Webdav Tutorial
Assalamualaikum and greetings, today i'm gonna teach you how to deface a website using WEBDAV. This is the most easy defacing method.
1- Extract the Webdav.zip that you have downloaded.
2-There will be 4 things inside the folder:
- Webdav.exe
- Up.php
- Dorks
- Example of vuln sites
4-Click on Webdav and choose asp shell maker
5- And you will see something like this,
6- Click on setting, and paste or load your defacement/shell code
7-Its up to you whether you want to use asp or php shell.
8- Click Add site and paste your vulnerable target or you also can load it from file
9- Once you're ready, click on Serang!!! to start uploading
10-If it says, "Not vulnerable dav", thats mean the site is not vulnerable or already patched.
11-Once the shell is uploaded successfully, it will say shell created
12-Copy the link given and open it in your browser and you will get your shell :)
DORKS:
intitle:”index.of” intext:”(Win32) DAV/2″ intext:”Apache”
intitle:”index.of” intext:”(Win32) DAV/2″ intext:”Apache” site:edu
intitle:”index.of” intext:”(Win32) DAV/2″ intext:”Apache” site:gov
intitle:”index.of” intext:”(Win32) DAV/2″ intext:”Apache”
inurl:webdav
That's all. Thanks
-K3RAMA7-