mass exploitation on edu site

fizakhan1

Supreme Member
Joined
Apr 10, 2018
Messages
1,297
Reaction score
822
i got some big list of indonasian sites, they are using edu and gov site to upload their content in it
anyone have a clue that how are they doing???
 
I seen that, I think they used to find the vulnerable sites which mistakenly provide folder permission for public access. Those are not recommended way and look total spam as they upload their html file in Edu websites which iframe their sites.
 
I seen that, I think they used to find the vulnerable sites which mistakenly provide folder permission for public access. Those are not recommended way and look total spam as they upload their html file in Edu websites which iframe their sites.
exactly. but why can't we find the way? how they found?
 
exactly. but why can't we find the way? how they found?
Google dork mostly.

e.g.

Code:
intitle:Index.Of inurl:pdf

The one above will only give you the publicly available folders though. I am not gonna expand on how to actually upload, because that would be considered hacking, and I don't want to get an infraction.
 
Google dork mostly.

e.g.

Code:
intitle:Index.Of inurl:pdf

The one above will only give you the publicly available folders though. I am not gonna expand on how to actually upload, because that would be considered hacking, and I don't want to get an infraction.
not pdf have a look at this http://tffc.usc.edu/judi-bola-resmi/
 
Yeah so (s)he uploaded a html file instead of pdf. Nothing revolutionary. If you want to learn more, google "RFI attack". We can't discuss such stuffs here.
ohh sure.
 
Congratulation you just exposed their method they're using to sell Seo gigs on fiverr lol.
 
Congratulation you just exposed their method they're using to sell Seo gigs on fiverr lol.
Honestly, I don't feel bad exposing these "scammers". This is not the real way, specially if someone is selling these links. All you are doing is hurting another web master. This is not fair...
 
yeah, i also wonder how they done it, try to imagine searching web 1 by 1 just to see any opening.
 
Back
Top