Targeting websites via searching and finding compressed files 04-25-2020, 11:38 AM
#1
Hello world,
Today I'll share with you how to targeting websites via searching and finding compressed files that help you to get access
Sometimes many admins when install new script (webapp) on his website and forget to remove the compressed file
For example:
vBulletin, Wordpress, Joomla, Drupal, SMF, etc ...
# What I need?
DirBuster, Havij, Acunetix WVS, Linkrot, etc ...
Also you can use this online website
http://www.file2hd.com/
# The Method
You can use your mind to search for the files on the website, for example:
wordpress.zip, word.zip, wp.zip, vb.zip, forum.zip, www.zip, public_html.zip, joomla.zip, smf.zip, etc ...
Or you can use any tool we have mentioned above
DirBuster, Havij, Acunetix WVS, Linkrot, etc ...
# Tricks
After finding the compressed file and download it to your PC and extracting it
You should look to the script's configuration file
- If we find the (HostName), (DB_Host) are not on "localhost"
Then we can try to connecting to the database remotely
- Trying the password on script's admin panel (every script has a diffrent CP)
- Trying the password on website/server admin panel (cPanel, Plesk, DirectAdmin)
- Trying the password on admin's email
- Trying social engineering with the root server or the technical support
# Tutorial
Now let's see the video
I hope you like this tutorial
Regards,
elsyad/.
Today I'll share with you how to targeting websites via searching and finding compressed files that help you to get access
Sometimes many admins when install new script (webapp) on his website and forget to remove the compressed file
For example:
vBulletin, Wordpress, Joomla, Drupal, SMF, etc ...
# What I need?
DirBuster, Havij, Acunetix WVS, Linkrot, etc ...
Also you can use this online website
http://www.file2hd.com/
# The Method
You can use your mind to search for the files on the website, for example:
wordpress.zip, word.zip, wp.zip, vb.zip, forum.zip, www.zip, public_html.zip, joomla.zip, smf.zip, etc ...
Or you can use any tool we have mentioned above
DirBuster, Havij, Acunetix WVS, Linkrot, etc ...
# Tricks
After finding the compressed file and download it to your PC and extracting it
You should look to the script's configuration file
- If we find the (HostName), (DB_Host) are not on "localhost"
Then we can try to connecting to the database remotely
- Trying the password on script's admin panel (every script has a diffrent CP)
- Trying the password on website/server admin panel (cPanel, Plesk, DirectAdmin)
- Trying the password on admin's email
- Trying social engineering with the root server or the technical support
# Tutorial
Now let's see the video
I hope you like this tutorial
Regards,
elsyad/.
The Best Revenge Ever Is Success !
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)
















![[Image: p_237m2jx1.png]](http://c.top4top.net/p_237m2jx1.png)