WEBSITE HACKING USING FCKeditor VULNERABILITY - HACKING Begins

April 29, 2012

WEBSITE HACKING USING FCKeditor VULNERABILITY

Welcome again to "HACKING begins - An approach to introduce people with the truth of HACKING".
Today i teach you how to hack a website with FCKeditor Vulnerability. 

Lets Hack

Open Google

Search for DORK
Type: "inurl:/HTMLEditor/editor/filemanager/connectors/" without quotes

You see a webpage like that


 Ok now just replace things after “connectors/to “uploadtest.html”

Example :: http://www.victim.com/HTMLEditor/editor/filemanager/connectors/uploadtest.html 



Now select the file u want to upload
Browse the file and send it to server
You will get a POPUP to successfully file uploaded.

Viewing The File:

Just go to 

“http://www.website.com/Uploaded File URL:

  

If u get errors likes

Uploder Disabled & Content Forbidden

Try Another Website
 
*It is only for the Educational purposes,don't Misuse It.
  Moderator of this site is responsible for the misuse done by you.
 

Thanks and Regards  
Sahil Mahajan C|EH

 


 

6 comments:

  1. Hi that's is awesome,, Thanks to share with us

    ReplyDelete
  2. Because it allows them to be more precise and accurate when preparing our clients’ essays, have a glimpse at the site to find more!

    ReplyDelete
  3. Taking responsibility needs true grit but I think here you should write
    " Moderator of this site is NOT responsible for the misuse done by you."

    It may create lots of problems for you.



    ReplyDelete

I hope you got some great ideas in this post! Please feel free to share additional ideas or query.