Tuesday, 6 November 2012

Hack a website through IIS



 First you need to find a vulnerable website.you can find it from google dork....
to know how to search google dork just see my post on google hacking

For Windows xp:


In IIS Exploit we can upload the Defaced page on the Vulnerable Server without any Login. It is most Easiest  way to Hack any site.

STEP 1: Click on Start button and open "RUN".

http://1.bp.blogspot.com/-Jp6FInbqAzg/Td8-yvFWs8I/AAAAAAAAAFY/2qPyMhG9o20/s1600/IIS+exploit1.JPG
STEP 2: Now Type  this in RUN
%WINDIR%\EXPLORER.EXE ,::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{BDEADF00-C265-11d0-BCED-00A0C90AB50F}


Now A Folder named "Web Folders" will open.


STEP 3: Now "Right-Click" in the folder and Goto "New" and then "Web Folder".


STEP 4: Now type the name of the Vulnerable site in this. e.g." http://autoqingdao.com/ " and click "Next".

STEP 5: Now Click on "Finish"

STEP 6: Now the folder will appear. You can open it and put any deface page or anything.

STEP 7: I put  text file in that folder. Named "securityalert.txt" (you can put a shell or HTML file also). If the file appear in the folder then the Hack is successful but if it don't then the site is not Vulnerable.


.
Now to view the uploaded site i will go to "http://autoqingdao.com/securityalert.txt"
In your case it will be " www.[sitename].com/[file name that you uploaded] "



 IIS Exploit website Hacking in Windows Seven 7 Step By Step Explained with Images

Step 1-
(Go to My Computer, Do Right Cilck and Select Add a network Location)


Step 2- (click on Next)

Step 3- (click on Next) 

Step 4- (now enther The URL of vuln website and Click on Next, For example tka this site http://www.myxixia.com/)

Step 5-(click on next button) 

Step 6- (Now click on Finish)

Step 7- (see Network Location Option And click on website folder)

Step 8- Now Download the Shell  http://www.ziddu.com/download/16498227/shell.zip.html 

Step 9-(After Downloading do right click on file and click on Extract here)

Step 10- (Now copy the Power.asp;.jpg file and open the web folder of vuln website)

Step 11- (now paste the power.asp;.jpg file in web folder)

Step 12- (Paste Complete)

Step 13 - (Now open Your Browser and enter The site addres and put Power.asp;.jpg after url for example http://www.myxixia.com/power.asp;.jpg)

Step 14- ( Now click on edit file index.asp)

Step 15- (open your deface html file. do right click and select open with notepad)

Step 16- (Copy all code)

Step 17-(paste the all code in that popup which yu got after clicking edit index.asp and click on save)

Step 18- (now you wil got a page tike this)

Step 18 -You've done :) now when you will open that website you will got your deface page on home :)

I hope you like this tutorial :)

Kindly Bookmark this Post using your favorite Bookmarking service:
Technorati Digg This Stumble Stumble Facebook Twitter
YOUR ADSENSE CODE GOES HERE

0 comments:

Post a Comment

Blog Archive

 

| Computer Hacks and Tricks © 2012. All Rights Reserved | Template Style by TP's Hack World | Design by Tushar Patel | Back To Top |