Webdav Tutorial


Assalamualaikum and greetings, today i'm gonna teach you how to deface a website using WEBDAV. This is the most easy defacing method.

 



1- Extract the Webdav.zip that you have downloaded.

2-There will be 4 things inside the folder:
  1.  Webdav.exe
  2.  Up.php
  3.  Dorks
  4.  Example of vuln sites   
3-Run webdav.exe

4-Click on Webdav and choose asp shell maker

 

5- And you will see something like this,

    

6- Click on setting, and paste or load your defacement/shell code

7-Its up to you whether you want to use asp or php shell.

   

8- Click Add site and paste your vulnerable target or you also can load it from file

9- Once you're ready, click on Serang!!! to start uploading

10-If it says, "Not vulnerable dav", thats mean the site is not vulnerable or already patched.

11-Once the shell is uploaded successfully, it will say shell created

12-Copy the link given and open it in your browser and you will get your shell :)

DORKS:
 
intitle:”index.of” intext:”(Win32) DAV/2″ intext:”Apache”
intitle:”index.of” intext:”(Win32) DAV/2″ intext:”Apache” site:edu
intitle:”index.of” intext:”(Win32) DAV/2″ intext:”Apache” site:gov
intitle:”index.of” intext:”(Win32) DAV/2″ intext:”Apache”
inurl:webdav




That's all. Thanks

-K3RAMA7-