Top Banner
$ pwd /home/espreto $ mkdir conferences/nullbyte && cd $_ $ cat > title.txt ^C $ clear
21

Cabra Arretado Aperriando o WordPress

Jan 14, 2017

Download

Technology

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Cabra Arretado Aperriando o WordPress

$ pwd

/home/espreto

$ mkdir conferences/nullbyte && cd $_

$ cat > title.txt

^C

$ clear

Page 2: Cabra Arretado Aperriando o WordPress

$ whoami

espreto

$ cat me.txt

$ clear

Page 3: Cabra Arretado Aperriando o WordPress

$ cat talk.txt

$ clear

Page 4: Cabra Arretado Aperriando o WordPress

$ irb - -simple-prompt

>> def talk(data)

>> …snip…

>> talk(“wp_intro”)

Page 5: Cabra Arretado Aperriando o WordPress

>> talk(“plugins_the_dark_side”)

Page 6: Cabra Arretado Aperriando o WordPress

>> talk(“plugins_the_dark_side”)

Commons Vulnerabilities

Upload Vulnerability Mechanism.

Cross-Site Scripting vulnerability (XSS).

File Download Vulnerability.

Cross-Request-Forgery Vulnerability (CSRF).

SQL Injection Vulnerability (SQL Injection).

Page 7: Cabra Arretado Aperriando o WordPress

>> talk(“plugins_the_dark_side”)

https://wpvulndb.com/plugins

Page 8: Cabra Arretado Aperriando o WordPress

>> talk(“why_metasploit”)

Page 9: Cabra Arretado Aperriando o WordPress

>> talk(“exploits_auxiliaries”)

https://www.rapid7.com/db/search

Page 10: Cabra Arretado Aperriando o WordPress

>> talk(“http_msf_requests”)

net/http library

Msf::Exploit::Remote::HTTP::Wordpress

Page 11: Cabra Arretado Aperriando o WordPress

>> talk(“http_msf_requests”)

File Read (Traversal)

http://wordpress/wp-content/plugins/dukapress/lib/dp_image.php?src=../../../../../../etc/passwd

Page 12: Cabra Arretado Aperriando o WordPress

>> talk(“demo”)

Page 13: Cabra Arretado Aperriando o WordPress

>> talk(“http_msf_requests”)

WordPress Login

Check method

Page 14: Cabra Arretado Aperriando o WordPress

@espreto

>> talk(“http_msf_requests”)

Get nonce

Page 15: Cabra Arretado Aperriando o WordPress

>> talk(“wpsploit”)

By todb, Rapid7

Page 16: Cabra Arretado Aperriando o WordPress

>> talk(“wpsploit”)

Page 17: Cabra Arretado Aperriando o WordPress

>> talk(“wpsploit”)

https://github.com/espreto/wpsploit

Page 18: Cabra Arretado Aperriando o WordPress

>> talk(“demo”)

Page 19: Cabra Arretado Aperriando o WordPress

>> talk(“demo”)

Page 20: Cabra Arretado Aperriando o WordPress

>> talk(“questions”)

Page 21: Cabra Arretado Aperriando o WordPress

>> quit

$ cat contact.txt

$ shutdown –h now