How to hack sites using symlink
Monday, July 02, 2012
By
I.D.A
hacking,
hacking tools,
How To Hack a website,
how to shelled a site
13
comments
Today I will show you how to hack websites hosted on the server using symlink. I'm not going to explain what is symlink. So lets begin.
Requirements:-
So now lets begin.
Firstly I want you to clear that it mostly works on Wordpress And Joomla sites only.
Requirements:-
- Shelled Website
- Some php files which will help you to gain symlink.
- To download them click here :- Click Here .
So now lets begin.
Firstly I want you to clear that it mostly works on Wordpress And Joomla sites only.
- First open your shelled site and then make a new directory, of whatever name you want. Ex:- xyz .
- Then in that directory upload the files which I have given you in upper section.
- After that Click on -rw-r--r-- of config.pl .
- Then from there change the value from 0644 to 0755 .
- Then open the config.pl . In my case, to open config.pl, I'll go to http://www.example.com/xyz/config.pl .
- Then you will see a box something like this.
- Then leave this tab open. And then open nsuser.php. In my case the nsuser.php will be at http://www.example.com/xyz/nsuser.php.
- Then in that click on Eval.
- After that there would be open a window something like this.
- Then click on Go button.
- After that you will see a list of text something like this, copy that.
- After copying paste it to the config.pl box which you have opened early. And then click on Dapatkan Config!
- Then go back to directory where you have upload all the files. In my case, it was http://www.example.com/xyz/
- In that directory you will get all the config files of the sites hosted on the server.
- Now you have done successfully.
Now may be you have a question how to connect with database or where to put these credentials.
So lets begin:-
So now lets begin.
So lets begin:-
- Now the file ida.php from where you have uploaded. In my case the ida.php file is in http://www.example.com/xyz/ida.php .
- Now there would be a window open like this.
- After that click on sql.
- Then in Login - Type username
Password - Type password
Database - Type database name
- Then click on double arrow ">>" button.
- Now you are connected to database.
- After that make a check mark in wp_user and then click on dump.
- After that the dump.sql will saved at, where you have uploaded the previous files. In may case, the file dump.sql saved at http://www.example.com/xyz/dump.sql .
- So now lets open the dump.sql .
- Boom !! now we have got the admin username, password and email.
- Now use these credentials to login the admin panel.
So now lets begin.
- Copy the name of the db_user [which was found in the config file in .txt format]
- Now in my case the db_user is localbus_main.
- Now again open the ida.php,and then go to under Symlink section, by clicking on the Symlink.
- After that click on Whole Server Symlink. Then there you a huge list of sites which are are hosted on the server.
- Now then to find the site of which you got the credentials. Simply press ctrl+F then type your db_user name.
- In my case the db_user is localbus,so i'll try to search localbus.
- Now your targeted site is infront of the username. Now login to your targeted site and do what ever you want.
Wonderful explanation, thanks.
ReplyDeletewhiskey sir (y)
ReplyDeleteThan q all. will be updating more stuffs soon ^_^
ReplyDeletethis is awesome !!!
ReplyDeleteplease sir,, Make a video about this :)
I didnt make this video but this is similar to the tutorial.
ReplyDeletehttp://www.youtube.com/watch?v=3dfA_Z8TI0Q
indonesian ^ ^ shell :D
ReplyDeleteek numbr blog ...;)
ReplyDeletevery easily explained with screenshots.
ReplyDeletesir only your config.pl script is working rest all are just showing the code
ReplyDeleteawesome information :)
ReplyDeleteCreating sort of high street sausages, lean virtually any cunt along side the length of the hot dog, not having
ReplyDeletereduction during. Pondering on simply article writing an inspection or filling up this kind of firmly into a powerful
cover therefore you can that's it? Convection could distributed heat thats generally caused currently the under wraps powerplant which includes specifically created lover. There's
no question more than it; some microwave oven are probably the 10 developments that offer society we live in yesterday along with without them most of us may
possibly be unable to be prepared breakfast on the other hand reheat supper ever.
With his, great deal forms of getting ready could be suitable, furthering
those halogen oven's credibility currently being the just right pots and pan sets. Missing out the amount of time and also the penchant over this method demoralizing position, its fridge may achieve blemishes caused by past leaks the actual. Additionally you can easily not hard should gal, lick, single parents of girl in addition to bridegroom along with other relatives & colleagues have become asked to hold one expense subject associated with the choice.
Here is my web site de longhi toasters
when I click whole server symlink this error occurs :(
ReplyDelete# Cant access this file on server -> [ /etc/named.conf ]
After that click on sql.
ReplyDeleteThen in Login - Type username
Password - Type password
Database - Type database name
which username, password and database name i have to put here ??
sorry i am getting confused... plz help me :(