Ikuti kami di Google News. Follow

Deface dengan KCFINDER Shell upload With CSRF

di artikel kali ini saya akan share Deface dengan KCFINDER Shell upload With CSRF.
yups ini adalah sebuah bug di kcfinder.

Bahan:
Dork:kcfinder/browse.php site:domain
Exploit:kcfinder/upload.php
vendor: http://artus.md/kcfinder/upload.php
CSRF: http://nobsec.net/csrf.txt

pertama-tama kalian dorking dulu menggunakan dork di atas(kembangkan lgi), atau kalian bisa gunakan live target yang udah saya sediakan http://artus.md/kcfinder/upload.php

apa bila vuln maka akana akan keluar pesan alert "Unknown error".


oke untuk tutorialnya kalian bisa tonton video saya berikut ini:






mungkin sekian artikel kali ini sampai bertemu di artikel berikutnya!

Cookie Consent
We serve cookies on this site to analyze traffic, remember your preferences, and optimize your experience.
Oops!
It seems there is something wrong with your internet connection. Please connect to the internet and start browsing again.
AdBlock Detected!
We have detected that you are using adblocking plugin in your browser.
The revenue we earn by the advertisements is used to manage this website, we request you to whitelist our website in your adblocking plugin.
Site is Blocked
Sorry! This site is not available in your country.