Bahan- Bahan :
1. Dork :/index.php/index/user/register"
(baca juga Dork Open Journal System)
2. Imajinasi vokepers kalian buat kembangin dork.
3. Shell berekstensi .phtml
Step by Step :
1. Dorking (biasa aja dorking nya)
2. Kalo udah pilih target, mending cek dlu vuln apa ngga nya, kalo ane cara ngecek publik files nya cuma nambahin /Files/Journals
di belakang url target, Contoh : www.site.com/files/journals
( klo vuln nanti keluar public files nya , kalo Not Found atatu forbidden ga vuln )
di belakang url target, Contoh : www.site.com/files/journals
( klo vuln nanti keluar public files nya , kalo Not Found atatu forbidden ga vuln )
3. kalo target vuln pas di public files , kalian balik lagi ke halaman register.
4. Register deh, asalan juga gpp.
![]() |
| Note : Di bagian siu ceklis kotak Author : blablabla |
5. Setelah selesai daftar, calon pemudik, klik New Submission (kalo target ane bahasanya ane)
![]() |
| Biasanya letak nya di situ |
6. Ikutin dah apa yang di suruh.. nanti pas Step ke2 baru bisa upload shell
7. Kalo sukses, hasil nya akan, (cantik, mulus, bohay)
| Sukses |
8. Akses shell adalah hal paling ribet, klo kalian kaga cepet paham.
kita pergi ke Public Files , www.site.com/files/journals ( nanti oprek2 sendiri ,cari file mu di situ ) atau biasanya
kita pergi ke Public Files , www.site.com/files/journals ( nanti oprek2 sendiri ,cari file mu di situ ) atau biasanya
www.sitetarget.co.li/files/journals/1/articles/[iduser]/submission/original/[nama file].phtml
238 adalah id user dan 238-22-1-SM.phtml adalah file nya.
Sumber : GarudaSecHacker
238 adalah id user dan 238-22-1-SM.phtml adalah file nya.
Sumber : GarudaSecHacker

![Deface Dengan Open Journals System Arbitrary File Upload [Edisi Lebaran] Deface Dengan Open Journals System Arbitrary File Upload [Edisi Lebaran]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSPxXnfSkEJlO2m3MX30rE7GhvlY204_PbL4D1-5ywLiN72daOAuQkmKsmPaNOc9odClJpUzpdeK9IPzzcYc21d0B6yHuCmZCOv3mmp3loqMTo6bNuYqZSW5rcKefni5o4IEzyBLwMnG5j/s640/Screenshot+%2528144%2529.png)
![Deface Dengan Open Journals System Arbitrary File Upload [Edisi Lebaran] Deface Dengan Open Journals System Arbitrary File Upload [Edisi Lebaran]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNNXYkxYfffOIPD-P4DBGolGelJXO4NHxke5MxCA-eyWf8HMOjHQgXM8YZopkiMombE_k9op6lBZf5tUTahiOKYex1O-2uIikHQLHoyI7Vxaykb930hIC9gzD0KcRWp6T3-ORj_9orzBQA/s640/Screenshot+%2528145%2529.png)
![Deface Dengan Open Journals System Arbitrary File Upload [Edisi Lebaran] Deface Dengan Open Journals System Arbitrary File Upload [Edisi Lebaran]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvq12vCF7u0qEeZ8uMdAXGQZcXiSeYI6mewYaI33lH3sYtHGwR5gTgdOrHTnuxzSPcixQof7nLRDlDaiN9DTA8nmyRtVhedrZR8KqqPxgKume1dT7_jLc_Ba2TOP4qUyfCT_F1dVqwDL3O/s640/Screenshot+%2528147%2529.png)
0 Response to "Deface Dengan Open Journals System Arbitrary File Upload"
Post a Comment