[Tutorial] Hack WordPress site with SQL injection [Tuto]

M33

[ Verified Seller ]
Staff member
Trusted Seller
Joined
11 yrs. 8 mth. 23 days
Messages
5,010
Reaction score
11,818
Wallet
13,191$
lets begin.

First of all we need to find a vulnerable page.
We enter this in Google:


Code:
Please, Log in or Register to view codes content!


When you found your site you need to find admin email and username.
I will be using this site for example:


Code:
Please, Log in or Register to view codes content!

regiont.png


When i add ' text disappears so it is vulnerable.

regionzn.png


NOTE: I will not demonstrate how to SQL inject.

Now we need admin username and email.
We need to inject:

Code:
Please, Log in or Register to view codes content!

Now we have 2 users.

http
regionjhg.png


We pick one and copy his email.
Go to the login page of the site.
It is usually here:

Code:
Please, Log in or Register to view codes content!

And press "Lost your password?"

regionz.png


Now you enter either username or email.
We can enter both so it doesnt matter.
I entered email.

regionby.png

regionng.png


Now when you got:

"Check your e-mail for the confirmation link."

It means that reset key is successfully sent.
Now we need to get the activation key.

Go back to the syntax you used for extracting email and username and do this:

Code:
Please, Log in or Register to view codes content!

Code:
Please, Log in or Register to view codes content!

regiongn.png


Voila!
Now we just need to reset it.

go to:
Code:
Please, Log in or Register to view codes content!

NOTE: Replace key= & login=

So my link will be:

regionzi.png


Enter new password:

thefreenudecelebritysit.png


regiongv.png


Thanks for reading! :giggle:
 
Paid adv. expire in 2 months
CLICK to buy Advertisement !
westernunion carding Verified & Trusted WesternUnion | MoneyGram | Bank - Transferring [299$ BTC for 2000$ WU]
electronics carding Verified & Trusted Electronics Carding, Carding iPhone, Samsung Carding, MacBook Carding, Laptops Carding

Tornado

[ Final Boss ]
Staff member
Escrow
Moderator
Administrator
V.I.P
Joined
12 yrs. 10 mth. 19 days
Messages
8,339
Reaction score
27,858
Wallet
8,991$
good.. +1 rep
 

M33

[ Verified Seller ]
Staff member
Trusted Seller
Joined
11 yrs. 8 mth. 23 days
Messages
5,010
Reaction score
11,818
Wallet
13,191$
no problem brothers.
 

M33

[ Verified Seller ]
Staff member
Trusted Seller
Joined
11 yrs. 8 mth. 23 days
Messages
5,010
Reaction score
11,818
Wallet
13,191$
no problem guys!
 

Earl

Well-known member
Member
Joined
11 yrs. 6 mth. 7 days
Messages
2,634
Reaction score
8,001
Wallet
0$
Damn nice tutorial... thanks for that. Very indepth.
 
Top Bottom