Deface dengan OJS (Open Journals System) + Shell Finder OJS

Type : Uploader File Data
Dork : inurl:/files/journals/ (Kembangin lagi )
Vuln : /index.php/index/user/register ( Bisa registrasi )

1. Kamu harus mendaftar dulu disini > site,com/index.php/index/user/register
    - Centang "Author....."

   - Jangan Centang  "Send me a confirmation email....."




2. Setelah Registasi Klik "New Submission" / "New Article"



3. Selesaikan Step 1


4. Di Step 2, kamu dapat upload shell (format shell : a.phtml)


   - Choose File, lalu Upload / Download Server

Shell Path : /files/journals/1/articles/454/submission/original/454-879-1-SM.phtml

Penjelasan : 
Filename : 454-879-1-SM.phtml
454 = id user kamu

note : kalo ga ketemu bisa gunakan : http://pastebin.com/r4k1cPs8 (OJS shell Finder)


          kalo ga ketemu lg coba upload sc deface berformat html
          kalo ga bisa jg, MATI AJA :"""V



Live Target : http://ppct.caicyt.gov.ar/files/journals
Video :

thx: Java Intelegent Cyber

- Mr-Andraz404

Postingan terkait:

5 Tanggapan untuk "Deface dengan OJS (Open Journals System) + Shell Finder OJS"