Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 97 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Tutorialsarrow Targeting and Hacking a WordPress Site (Ninja-Sec.com - Infosec Resources )
EH-Net
May 26, 2012, 08:58:06 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Targeting and Hacking a WordPress Site (Ninja-Sec.com - Infosec Resources )  (Read 4261 times)
0 Members and 2 Guests are viewing this topic.
Ninja-Sec
Newbie
*
Offline Offline

Posts: 47


ninja-sec.com


View Profile WWW
« on: January 05, 2012, 02:47:18 PM »

hi

please read our new article

http://resources.infosecinstitute.com/hacking-a-wordpress-site/

Enjoy Smiley
« Last Edit: January 10, 2012, 09:39:08 PM by Ninja-Sec » Logged

http://ninja-sec.com - CODENAME: Samurai Skills Course
ChrisLaz
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #1 on: January 06, 2012, 03:11:58 AM »

Very interesting approach. Thank you for sharing.
Logged
j0rDy
Hero Member
*****
Offline Offline

Posts: 578


View Profile
« Reply #2 on: January 06, 2012, 03:58:08 AM »

nice hack! I always enjoy reading hacks like this, there fun and still very informative.
Logged

ISC2 Associate, CEH, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
vp75
Jr. Member
**
Offline Offline

Posts: 76


View Profile
« Reply #3 on: January 06, 2012, 06:00:03 AM »

Thanks for sharing, also reading some of the articles which interests me......
Logged
MrTuxracer
Newbie
*
Offline Offline

Posts: 18


View Profile WWW
« Reply #4 on: January 06, 2012, 08:34:41 AM »

That's the Hack-me "HackademicRTB1" provided by GhostInTheLab  Smiley I've posted a slightly different solution for it on my blog, but it works on this way too.

Thanks for sharing!
Logged

eCPPT, LPIC-1, VCP, WCSP
www.inshell.net
Seen
Jr. Member
**
Offline Offline

Posts: 96


View Profile
« Reply #5 on: January 06, 2012, 04:15:21 PM »

Interesting, I'll have to try this against my wordpress site, thanks.
Logged

Sec+, eCPPT
SephStorm
Sr. Member
****
Offline Offline

Posts: 416


View Profile WWW
« Reply #6 on: January 07, 2012, 01:03:35 PM »

Now I havent looked at the article yet, but my question is, what would be the approval for this? Would you need to contact WP or just have permission from the blog owner?
Logged

hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #7 on: January 07, 2012, 01:24:58 PM »

@ SephStorm - you can host your own Wordpress site, so pentesting an individual's site wouldn't require any permission from Wordpress, just the owner of the site and / or the server owner / provider, if the site is hosted.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
Jamie.R
Hero Member
*****
Offline Offline

Posts: 626



View Profile WWW
« Reply #8 on: January 08, 2012, 09:27:55 AM »

Yeah just download and maybe use WAMP kit
Logged

OSWP | eCPPT | HackingDojo Nidan
www.jamierougive.co.uk
MaXe
Hero Member
*****
Offline Offline

Posts: 507


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #9 on: January 08, 2012, 08:44:47 PM »

Some constructive feedback:  Grin
* Hacking other sites on the same server and / or the Registrar is illegal unless you have explicit permission to hack any of these.

* The: "nmap -O" command will only make a "best guess" on what the target is running, and this highly depends on 1) The NMAP version, 2) The open ports, 3) Services

* Example: scanme.nmap.org can be anything from Windows to Linux, depending on if you use NMAP or Xprobe2, and of course also which version of NMAP. (This is just an example out of context.)


* About the hash(es) that were cracked, here's some notes.

All of these three hashes, is "admin" in cleartext:
$P$BknpJUI2S.F6oD9bsAjRgZKBrQ2ct60
$P$BOOqZK9L94G3iXsjBlWLO5RbMSsLqW/
$P$Bc/LbIyetpQ1O21TcSJIq7zHr22Eiz.

(Note: Wordpress version 3.3.1)

These three hashes are also "admin" in cleartext:
$P$BBZNzh4ejzux/Q1XJeYa4bMoXVbE0o1
$P$BHbYY6iira4PZGTbnQGj52DPaqfn3t0
$P$BXqXvkYvNkAM1b.N3qZXY6K5Y/mkj90

(Note: Wordpress version 2.8.4)

In case you wonder, $P$ comes from class_phpass.php:
$output = '$P$'; in the function gensalt_private($input); function.


* When an attacker comes across a kernel version like this: 2.6.31.5-127.fc12.1686, the last number (127) is often the distribution specific patch number. (Meaning security patches could've been applied nullifying known vulnerabilities for 2.6.31.5)


No offense intended of course, there's just a few loose ends  Wink
Logged

I'm an InterN0T'er
SephStorm
Sr. Member
****
Offline Offline

Posts: 416


View Profile WWW
« Reply #10 on: January 09, 2012, 12:21:35 AM »

learning is occurring. Wait a minute... is ninja-sec affiliated with ISI? These guys are getting around...

OKAY, the answer is on the resources page:
"Mohamed Ramadan is a researcher for InfoSec Institute. He also teaches Penetration Testing at Ninja-Sec.com."
« Last Edit: January 09, 2012, 12:25:12 AM by SephStorm » Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.136 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.