DNN Hacking Tutorial

Let's Get Started:
Step 1: First you have to download This ASP Shell


Step 2: Now Open  http://www.google.com and enter this dork (This Dork is for Finding DNN vulnerable sites)



DNN Dorks:


inurl:/tabid/36/language/en-US/Default.aspx
OR
inurl:/Fck/fcklinkgallery.aspx

Using Google for Hacking

Things you can do with google

Find Botnets
Find People/Info/DoX
Find Vulnerable Sites
View Deleted Files/Sites
Finding things you're not supposed to
Obtaining things for free


Today I'm going to be showing you how to do all of these and more and how to protect yourself against them.


WHMCS 5.2.8 SQLI Vulnerability (0day)


Here again new 0day of WHMCS.
It's affect the Version 5.2.8 ( Current Version)

Again shit poor coding in new version of WHMCS .
Epicness not over . They make same mistake in

/includes/dbfunctions.php
We can manipulate the GET/POST variables and end up with something like $key = array('sqltype' => 'TABLEJOIN', 'value' = '[SQLI]');

By using this Vulnerability we can also change the /configuration.php to whatever we want.

John the Ripper


John the Ripper adalah program untuk mendekripsi password. Meskipun memiliki banyak
fungsi kita akan melihat menggunakannya sebagai decryper untuk file password
Anda miliki.
Kami akan melihat File Password yang Anda telah mengenakan Hard Disk Anda

PERSIAPAN

1. Download versi yang benar dari JTR, gunakan win32 untuk Win 95/98
2. Ekstrak file zip ke Direktori sebuah
3. Pastikan Anda memiliki File Password Anda dalam direktori yang sama

Exploit Shop737 File Upload Vulnerability

1. Cari web target
    Dork : intext:"Powered by Shop737"



    Dalam tutorial kali ini saya memilih website http://www.yungshe.com.


[ PLAYGROUND ]

Indonesian Coder || Codenesia || Exploit Database || Exploit ID || HN Community || devilzc0de || Packet Storm || cxsecurity