Showing posts with label Shell. Show all posts
Showing posts with label Shell. Show all posts

Shell is a malicious piece of PHP code that can be uploaded to a site to gain access to files stored on that site. Once it is uploaded, the hacker can use it to edit, delete, or download any files on the site, or upload their own.

How to upload

Hackers usually take advantage of an upload panel designed for uploading images onto sites. This is usually found once the hacker has logged in as the admin of the site. Shells can also be uploaded via exploits or remote file inclusion.
 

Uses

Shells have many uses. They can be used to edit the webserver directory index page of site, and then hackers can leave their mark or "deface" for visitors to the site to see when they go to the homepage. Hackers may also use it to bruteforce FTP or cpanel, allowing them more access to the website. Shells can also be used to gain root access to the site. Some hackers may choose to host malware or spyware on the sites they have uploaded their shell to using various exploits.



Check this too:  What is Shell? 


Many of  Newbies asking & searching for the tutorial , which tells "How to Use Shells..? "How to Deface Website ?" Many of them asking to write a post about it , so now iam going to   tell How to use "Shell"
When you Upload a shell on a site Whats  Next ? What you Going to Do ?
Many thing you can do With Shell,Some times you can hack other websites on the same server using some methods, or you can root the server using that shell !!
okk , How to upload files & and deface pages on your shelled sites ?
Look@ this image

in this image you can see a shelled website , and  iam in wp-content directory(location) .
That means the directory location is  site.com/wp-content/  , if i upload any file , it will be on that location 
site.com/wp-content/file
you can see the location  which we on  on Below the directory's(file manager) option
like:    /home/user/public_html/wp-content/
 and Remember public html is the site address, that means "site.com" which you shelled
and the directory is site.com/wp-content/
now How to upload Files to the site via the Shell ?
Scroll down you can see a "Upload" Button& browse option (or press ctrl+F and search for "upload"
then brose ur deface page & press on upload
After upload go to the file, and the file will be in the directory like
site.com/directory/file.html
if you want to upload file in the main Directory ,go to the public_html (look at the first image)
& the file location will be site.com/file.html
Now How to Deface Home page or the main page of a site or the Index page ?
look for index file , it will be in the name  "index.htm" , or  "index.html" , or  "index.php"  on public_html
you can edit or delete it, and you can update  "index" page with yours

E -Edit 
R-Rename
D-Download
T-time
Permission:Controlling the permission of the page & files 
Now you can edit or  Upload Index page with your own Index(Deface page)



What is Shell ?

Posted by Unknown 1 comments

If you have to learn what is hacking, you must be know about the basic .
like admin panels,shells,vulnerability ,...............
What is Shell ? 

programmer use this thing
admin panel is just for managing text and images on the website
admin panel can be used by a person who dont know programming language
Shell provide facility to manage the website directory too
From admin panel we can upload images
so we upload the shell in place of image and open it
and we are in if everything goes right

{this post is for many people who new in hacking & learning hacking ;) }


Get access to all the readable directories on the server and their possible database.
Steps to get access.
Go to your shell
Upload this zip file "Jumping.zip"
Download it from here
After that just unzip our zip file by giving the following command
unzip jumping.zip
Once it done and unzip command is executed you will see like this
This show all the files included in our zip file
 Now go and open our jumping folder. if you have uploaded it in public_html 
then the link would be www.site.com/jumping and you would see the below image

 Now open barc0de mini.php its an shell. once you open it. it look like this


Enter pass hackers
Now open jump.php it will take some time to load as it scans for all readable sites on server.
Once it done it will come up will all readable sites on server like this

 All the above are directly readable. Now will run scanner.php
it will read for config file in those dir once done it shows us like this
Now lets take one of them and put it in our barc0de mini.php and see if it shows us the database
And boom we have the access to its database config
i have included two more files sql.php & domain.php. this will help you to get website name and get in to database..cracker.php tries to crack ftp+ cpanel...
Updated barc0de.php
This shell is the newer version of barc0de mini.php
it is all in one shell. it has jump, scanner, cracker, and checker included in one shell
Download it from here barc0de.php 

Being a hacker its Important to know the most of the methods which are require to hacking. Well my last post was E-mail related. Today I will tell you Advanced way to hack a website by using symlink bypassing. Now what is symlink bypassing ?
Symlink Bypassing:

Symlink is a method to reference other files and folder on Linux, in order to make linux work faster.  Symlink Bypassing is a hacking technique used to gain unauthorized access to folders on a server. Using this technique an hackers are able to hack multiple sites on a shared web hosting service.

Now lets get started
 

Require Tools
Symlink Files – Click here to download