Hello all

This Post is for EDUCATIONAL PURPOSE

It helps You to know  how hackers Upload shell in sites


This thread is for people who fail to upload shell onto websites ( Happens to me alot :P )


Try these methods below


---------------------------------------------------------------------------------
Method 1:
---------------------------------------------------------------------------------


we all know that uploading scripts accepts JPG or GIF or both etc..
so its possible some times to bypass it by
renaming the file to
" shell.jpg.php "


---------------------------------------------------------------------------------
Method 2:
---------------------------------------------------------------------------------


Sometimes we can upload PHP file by editing the parameters with tools such as
Tamper Data ( Firefox Addon )
Download Here:
Code:https://addons.mozilla.org/en-US/firefox/addon/tamper-data/
Change the


application/octet-stream
to
image/gif
or
image/jpg


Video tuorial:
Code:
http://www.youtube.com/watch?v=OB5iQI5SkTw
However, that works on some scripts...


---------------------------------------------------------------------------------
Method 3:
---------------------------------------------------------------------------------
We can also upload shell by adding
to the file name


%_00
shell.jpgphp


shell.jpg%.php


or


shell.jpg;php (works alot specially on Win box'z )


---------------------------------------------------------------------------------
Method 4:
---------------------------------------------------------------------------------
Another way is by tricking Apache
by adding PHP languages
For Example:
file.php.en
the Apache will read the file.php.en
as a normal php file
cause .en refers to English
another example:
file.php.ar
.ar refers to Arabic and so on....
that helps when we find an uploading center that
denies PHP extinsions and allows any other unknown extionsion.


Well that's pretty much it


Good luck!


~Regards
This Post is for EDUCATIONAL PURPOSE

It helps You to know  how hackers Crack Rdp/SSh

First You Need A Good Ip Scanner
Here is More Ip Scanner On Web
But Personally Speak I use K.PortScan Its Good

KPortScan:-3.0
311853f17ccff3205bcb083a377aed14.png

First You Download File And Extract the Folder on Desktop
DOWNLOAD FILE


Scan Report


Now U Need Ipblockcountry Ranges Here is One i share

c5909698439be3d8cd0dbd0fc8913eca.png

Now u Get your Ip Ranges like This Example Mexico

9ef145d29c839cd1cbfd94d1891f0203.png


Now Copy Your Ip ranges And Paste KPortScan
489744af04f4ef9432aaa8cbe9ecb6a6.png
And Filter your Good ip range Auto Save in KPortScan Folder in result txt File:-

NOTE:- Do Not Changes KPorScan Is All is Default Only paste Ip ranges And Start
More than 1 lakh IPs is Good For cracking
Now i told u How to Crack RDP/VPS After Got Good Ip Ranges
The Best RDP/VPS Cracking TOOL is DUBRUTE V2.2
Download here DUBRUTE V2.2


https://www.virustot...5ae7a/analysis/

Note:- DUBRUte is A hack Tool Have Some issues I suggest Don't Use Your PC Use Only VPS/RDP

835b48b652003f10201f57b1170fc6d1.png

3dcdd94df3ebe5987ae08e039b27bc93.png


After All Click make And clik ok

Now your DUBRUte V2.2 Is Ready To Cracking RDP/VPS
You Got Cracked VPS On Dubrute Folder in Good txt. File Example 114.22.45.30@Administrator;password1
Listen One Most Important Thing After you All set Don't Click Start Go To DUBRUte-->CONFIG
Here is u Select your Thread Its Depend On VPS RAM if your RAM is 2GB Choose 100 Thread Only And if RAM 4GB Choose Only 250 Thread As those

d3d53333ba5b07e9650249268fbdfd8e.png

After You choose your Threads Click Ok And Back Now START DUBRUte V2.2
Here i Share My Username And password List
NOTE:- Username Only use 7 or 8 General Login Like
Administrator
Admin
user
Server
test
server, etc
administrator

admin
admin1
user
user1
user2
test
test1
test2
remote
server
manager
root
support
scanner
scan
temp


Password List 


GoodLuck :)

NOTE:- Don't Change Password To Cracked Account Like Administrator If You Do Then VPS/RDP is DEAD
Better You Create your Own Account And use it

HOW To Create User Account On Server/VPS ?

Create user Account Window Server 2003


Create user Account Window Server 2008 or Window 7 Server/VPS