Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 80 guests online
 
Advertisement

You are here:
EH-Net
May 20, 2013, 04:00:24 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Targeting and Hacking a WordPress Site (Ninja-Sec.com - Infosec Resources )  (Read 14316 times)
0 Members and 1 Guest are viewing this topic.
Attack-Secure
Jr. Member
**
Offline Offline

Posts: 54


attack-secure.com


View Profile WWW
« on: January 05, 2012, 02:47:18 PM »

hi

please read our new article

http://resources.infosecinstitute.com/hacking-a-wordpress-site/

Enjoy Smiley
« Last Edit: January 10, 2012, 09:39:08 PM by Ninja-Sec » Logged

http://attack-secure.com - CODENAME: Samurai Skills Course
ChrisLaz
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #1 on: January 06, 2012, 03:11:58 AM »

Very interesting approach. Thank you for sharing.
Logged
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #2 on: January 06, 2012, 03:58:08 AM »

nice hack! I always enjoy reading hacks like this, there fun and still very informative.
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
vp75
Jr. Member
**
Offline Offline

Posts: 78


View Profile
« Reply #3 on: January 06, 2012, 06:00:03 AM »

Thanks for sharing, also reading some of the articles which interests me......
Logged

eCPPT
MrTuxracer
Newbie
*
Offline Offline

Posts: 43


View Profile WWW
« Reply #4 on: January 06, 2012, 08:34:41 AM »

That's the Hack-me "HackademicRTB1" provided by GhostInTheLab  Smiley I've posted a slightly different solution for it on my blog, but it works on this way too.

Thanks for sharing!
Logged

eCPPT, HP ASE (Networking), LPIC-1, OSCP, WCSP
www.inshell.net
Seen
Full Member
***
Offline Offline

Posts: 134


View Profile
« Reply #5 on: January 06, 2012, 04:15:21 PM »

Interesting, I'll have to try this against my wordpress site, thanks.
Logged

Sec+, eCPPT
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #6 on: January 07, 2012, 01:03:35 PM »

Now I havent looked at the article yet, but my question is, what would be the approval for this? Would you need to contact WP or just have permission from the blog owner?
Logged

hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #7 on: January 07, 2012, 01:24:58 PM »

@ SephStorm - you can host your own Wordpress site, so pentesting an individual's site wouldn't require any permission from Wordpress, just the owner of the site and / or the server owner / provider, if the site is hosted.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
millwalll
Guest
« Reply #8 on: January 08, 2012, 09:27:55 AM »

Yeah just download and maybe use WAMP kit
Logged
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #9 on: January 08, 2012, 08:44:47 PM »

Some constructive feedback:  Grin
* Hacking other sites on the same server and / or the Registrar is illegal unless you have explicit permission to hack any of these.

* The: "nmap -O" command will only make a "best guess" on what the target is running, and this highly depends on 1) The NMAP version, 2) The open ports, 3) Services

* Example: scanme.nmap.org can be anything from Windows to Linux, depending on if you use NMAP or Xprobe2, and of course also which version of NMAP. (This is just an example out of context.)


* About the hash(es) that were cracked, here's some notes.

All of these three hashes, is "admin" in cleartext:
$P$BknpJUI2S.F6oD9bsAjRgZKBrQ2ct60
$P$BOOqZK9L94G3iXsjBlWLO5RbMSsLqW/
$P$Bc/LbIyetpQ1O21TcSJIq7zHr22Eiz.

(Note: Wordpress version 3.3.1)

These three hashes are also "admin" in cleartext:
$P$BBZNzh4ejzux/Q1XJeYa4bMoXVbE0o1
$P$BHbYY6iira4PZGTbnQGj52DPaqfn3t0
$P$BXqXvkYvNkAM1b.N3qZXY6K5Y/mkj90

(Note: Wordpress version 2.8.4)

In case you wonder, $P$ comes from class_phpass.php:
$output = '$P$'; in the function gensalt_private($input); function.


* When an attacker comes across a kernel version like this: 2.6.31.5-127.fc12.1686, the last number (127) is often the distribution specific patch number. (Meaning security patches could've been applied nullifying known vulnerabilities for 2.6.31.5)


No offense intended of course, there's just a few loose ends  Wink
Logged

I'm an InterN0T'er
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #10 on: January 09, 2012, 12:21:35 AM »

learning is occurring. Wait a minute... is ninja-sec affiliated with ISI? These guys are getting around...

OKAY, the answer is on the resources page:
"Mohamed Ramadan is a researcher for InfoSec Institute. He also teaches Penetration Testing at Ninja-Sec.com."
« Last Edit: January 09, 2012, 12:25:12 AM by SephStorm » Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.075 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.