Wednesday, July 27, 2016

Deface By Admin Login Bypass

Deface By Admin Login Bypass Technique With SQL Inject This time Team Undergroud would share a little technique deface Bypass Admin Login to SQL inject this technique we dapetkan of all blog garuda securit hacker.karena by Team Undergroud this technique is good then we also menshare immediately wrote to the scene. Ingredients 1. coffee 2. eat 3. Internet Connection 4. Script deface 5. Dork: inurl: /? Mnux = log "Powered by Sisfo Campus" Dork can develop themselves. tutorial: 1. Dorking first in google dork above 2. After emerging web results dorking select which do you think (vuln) 4. After opening the web you will be escorted to the login 5. If it is not directly on the spot you just add the login /? Mnux = log behind url Her web. example www.sitetarget.com/?mnux=login 6. Look to see where his login 7. Choose a login with the "Superuser" 8. Once in the menu login "Superuser" you enter inject '=' 'or' in the username and password. See the image and click login 9. After a successful entry to inject, you select the Master in the table above (see red marks) and then select the menu Students 10. Once selected, you edit its student profile (see picture) 11. Then click photo editing (see picture) 12. Then upload script that you deface extension .html 13. Once the upload is complete, to see the results of his defacean, you can right click on the image that is destroyed, then click view image (see picture) This is the result of deface

1 comment: