Exploit WP-Store Upload Vulnerability

by Nue Bhandell - 03-12-2016 at 02:17 PM
Staff
Moderators
Posts:
45
Joined:
Mar 2016
Likes:
0
Reputation:
0
2 Year Of Member
#1
OP
Posted: 03-12-2016, 02:17 PM
xixixhi malam Gengs, ciee malam minggu yak ? awkawkaw kok gak ngapel x_O? malah sibuknyari exploit dimari awkwka.
*nyari Bug mulu, nyari pacarnya kapan* xD
iseng2 share exploit lama, kali aja masih crotz awkakw.

yg dh master minggir dlu beb :heart:

Play with Me , Baby :P

Dork :
inurl:/wp-content/themes/WPstore/

WPStore
eShop
KidzStore
Emporium
Store
eCommerce
framework
frameworkold
Theme bisa diganti *ganti pada bagian belakangnya itu lho*

Exploit: /wp-content/themes/WPStore/upload/


Ciri2 Vuln x_O ?
Muncul tempat Uploader Omz

[Image: pIv5zjH.png]


langsung ae Upload Shell Lo Gengs..

Shell Akses: target.co.li/wp-content/uploads/products_img/namashell.php

[Image: 3sgz1d0.png]

Done x_O


Baca juga thread gue sebelumnya gengs: http://www.backboxindonesia.or.id/thread-26.html
Kunjungin Blog saya plis  :D : TKJ Cyber Art



semoga bermanfaat Gengs, maap kalo post cupu  [Image: smile.png] 
waktunya Nue dan tim Katakan Putus cabut dulu gengs, karna mau Ngapel dolo  :cool:
Bye



SUMUR
Reply
Find Posts
Junior Member
Posts:
33
Joined:
Mar 2016
Likes:
0
Reputation:
0
2 Year Of Member
#2
Posted: 03-12-2016, 02:41 PM (This post was last modified: 03-12-2016, 03:07 PM by anongep.)
ok om, dicoba om ^_^ / , kemungkinan ada uploader 1000:1 :3
Reply
Find Posts
Security Analyze
Super Moderators
Posts:
35
Joined:
Mar 2016
Likes:
1
Reputation:
0
2 Year Of Member
#3
Posted: 03-12-2016, 02:44 PM
(03-12-2016, 02:17 PM)Nue Bhandell Wrote: xixixhi malam Gengs, ciee malam minggu yak ? awkawkaw kok gak ngapel x_O? malah sibuknyari exploit dimari awkwka.
*nyari Bug mulu, nyari pacarnya kapan* xD
iseng2 share exploit lama, kali aja masih crotz awkakw.

yg dh master minggir dlu beb :heart:

Play with Me , Baby :P

Dork :
inurl:/wp-content/themes/WPstore/

WPStore
eShop
KidzStore
Emporium
Store
eCommerce
framework
frameworkold
Theme bisa diganti *ganti pada bagian belakangnya itu lho*

Exploit: /wp-content/themes/WPStore/upload/


Ciri2 Vuln x_O ?
Muncul tempat Uploader Omz

[Image: pIv5zjH.png]


langsung ae Upload Shell Lo Gengs..

Shell Akses: target.co.li/wp-content/uploads/products_img/namashell.php

[Image: 3sgz1d0.png]

Done x_O


Baca juga thread gue sebelumnya gengs: http://www.backboxindonesia.or.id/thread-26.html
Kunjungin Blog saya plis  :D : TKJ Cyber Art



semoga bermanfaat Gengs, maap kalo post cupu  [Image: smile.png] 
waktunya Nue dan tim Katakan Putus cabut dulu gengs, karna mau Ngapel dolo  :cool:
Bye



SUMUR

kangen bet ama method ginian >_<
Zero-Security.id | BackBox Jakarta Team
Reply
Find Posts
Staff
Moderators
Posts:
45
Joined:
Mar 2016
Likes:
0
Reputation:
0
2 Year Of Member
#4
OP
Posted: 03-12-2016, 03:11 PM (This post was last modified: 03-12-2016, 03:14 PM by Nue Bhandell.)
(03-12-2016, 02:41 PM)anongep Wrote: ok om, dicoba om ^_^ / , kemungkinan ada uploader 1000:1 :3

iya bang , ini exploit lama bgt..
keknya cuma otak2 bokepers doang yg imajinasinya tinggi bisa oprek dork biar dpt yg perawan wkwkw  :cool:

(03-12-2016, 02:44 PM)kcnewbie Wrote:
(03-12-2016, 02:17 PM)Nue Bhandell Wrote: xixixhi malam Gengs, ciee malam minggu yak ? awkawkaw kok gak ngapel x_O? malah sibuknyari exploit dimari awkwka.
*nyari Bug mulu, nyari pacarnya kapan* xD
iseng2 share exploit lama, kali aja masih crotz awkakw.

yg dh master minggir dlu beb :heart:

Play with Me , Baby :P

Dork :
inurl:/wp-content/themes/WPstore/

WPStore
eShop
KidzStore
Emporium
Store
eCommerce
framework
frameworkold
Theme bisa diganti *ganti pada bagian belakangnya itu lho*

Exploit: /wp-content/themes/WPStore/upload/


Ciri2 Vuln x_O ?
Muncul tempat Uploader Omz

[Image: pIv5zjH.png]


langsung ae Upload Shell Lo Gengs..

Shell Akses: target.co.li/wp-content/uploads/products_img/namashell.php

[Image: 3sgz1d0.png]

Done x_O


Baca juga thread gue sebelumnya gengs: http://www.backboxindonesia.or.id/thread-26.html
Kunjungin Blog saya plis  :D : TKJ Cyber Art



semoga bermanfaat Gengs, maap kalo post cupu  [Image: smile.png] 
waktunya Nue dan tim Katakan Putus cabut dulu gengs, karna mau Ngapel dolo  :cool:
Bye



SUMUR

kangen bet ama method ginian >_<
akwakkwa ciee pemaen lama nih wkwkw  :D 
hehehe iya bang,, dulu mah exploit seumuran kek exploit diatas ,  rasanya kek ada manis2nya gimana gitu wkwkw   

btw bang kangenin gua aja  :heart:  xixixhi
Reply
Find Posts
Junior Member
Posts:
17
Joined:
Mar 2016
Likes:
0
Reputation:
1
2 Year Of Member
#5
Posted: 03-12-2016, 04:27 PM
nice share bang.
dlu ane sempet bkin exploiternya.
langsung ke akarnya di /upload/upload.php
Reply
Find Posts
Staff
Moderators
Posts:
45
Joined:
Mar 2016
Likes:
0
Reputation:
0
2 Year Of Member
#6
OP
Posted: 03-13-2016, 11:08 AM
(03-12-2016, 04:27 PM)Tu5b0l3d Wrote: nice share bang.
dlu ane sempet bkin exploiternya.
langsung ke akarnya di /upload/upload.php

xixihi iya2 bang ilham :D
aku kan setia trus ama tutor2 di indoXploit :)
Reply
Find Posts
Register an account or login to reply
Create an account
Create a free account today and start posting right away. It only takes a few seconds.
Login
Log into an existing account.