Deface PoC Computer Based Test with Csrf


Deface Computer Based Test with csrf
# Author : 0xGh05t
# Team : Syndicate Hacker Team 
# Date : 27/09/2020
# Tested On : Windows 10
# Google Dorks : inurl:panel/pages/login.php
                 inurl:/login.php intitle:ujian online
                 inurl:/cbt/login.php site:sch.id
                 inurl:/login.php intitle:cbt beesmart
                 inurl:/login.php inurl:/cbt
                 inurl:/login.php intitle:ujian sekolah
                 inurl:/login.php intitle:ujian sma
                 inurl:/login.php intitle:cbt pintersmart
                 inurl:/login.php intitle:ujian pintersmart
                 "Modified @2018 intext:cbt"
                 intitle:CBT BEESMART intext:cbt
                 "Modified @2017 by MBA" inurl:login.php
                 "BeeSMART-CBT : v3_Rev3" inurl:login.php
                 intext:Supported by BEESMART

# Exploit : /panel/pages/upload-file.php
            /panel/pages/upload_video.php                        /panel/pages/upload_audio.php
            /panel/pages/upload_gambar.php
            /panel/pages/upload-file.php
            /panel/pages/upload-fotosiswa.php
            /panel/pages/upload-banner.php
            /panel/pages/upload-logo.php
            /panel/pages/upload-user.php


# contact me : ncdream72@gmail.com / https://facebook.com/ananta.an.37

###################################################################

CSRF : https://blogpongo.com/csrf.php
Shell bypass forbidden : hhttps://pastebin.com/WAUXzQ1K

Shell Bypass 403 or 406 and LiteSpeed:https://raw.githubusercontent.com/dmzhari/Bypass-Shell-Litespeed/master/bypass-shell.php