#Date : 07-04-2017
#tested : Linux ( Backbox ) , Windows 7
dork :
intext:"by Faveo" "Submit a Ticket"
example :
http://helpdesk.intisolusindojaya.com/public/auth/register
step :
[-]register
[-]check ur email,and click link activation
[-]login
[-]go to profile ( http://helpdesk.intisolusindojaya.com/public/client-profile )
[-]upload ur pic ( real pic dont use backdoor extension jpg )
[-]change extension jpg to php and change that jpg language or what ever i not understand about that to ur uploader or ur backdoor script use burpsuite
[-]if done.. click right on ur profile picture and copy link location
result :
http://helpdesk.intisolusindojaya.com/public/lb-faveo/media/profilepic/default.php
####################
thnks for my teacher : pak haxor - KONSLET - lastc0de - Antonio HsH - Mr.DellatioNx196 - Nanas Sec7or
Greetz : sanjungan jiwa - defacer tersakiti - Strlen - Jje Incovers - ReC0ded - Panataran - ex-Sh1Ne - Malaikat_Galau
ViruzTomcat - AdrElite - Wonka - Isal dot ID - Sh0uT0u7 - l0c4lh34rtz
0 Response to "Faveo Helpdesk Exploit"
Post a Comment