Jump to content
YOUR-AD-HERE
HOSTING
TOOLS
992Proxy

Locked Hacking Linux Webserver (With Wordpress)


sQuo

Recommended Posts

This is the hidden content, please

 

Description:

 

Webserver Content: WordPress default page.

 

Webserver on my LOCAL network!!! but works over the internet...

 

1, Detecting admin pages.

2, Scanning for open ports.

3, Scanning with WPScan for detecting WordPress version.

4, Enumerating users via WPScan.

5, Bruteforcing user with passwordfile.

6, Injecting Reverse Shell PHP (Thank's to pentestmonkey) to one of the plugins.

7, Starting netcat and executing Reverse Shell PHP.

8, Openning wp-config.php, because it is contain the SQL Database login info.

9, Lets try to login to PHPMyadmin

10, LOL the admin is use one password for all users.....

11, Try to connect to the SSH Server with my known PHPMyadmin login.

12, And finaly change the ROOT Password........

13, Connect to the server as ROOT....

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.