![]() |
|
Help hacking "new sites" - Sinister Mission - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: Help hacking "new sites" - Sinister Mission (/Thread-Help-hacking-new-sites-Sinister-Mission) |
Help hacking "new sites" - Sinister Mission - foxhound - 09-08-2013 Hello World! I have a target, and a dream....and my dream is to hack the hat out of my target xD So...I've spending the last weeks on learning how to hack using different tools (nmap, msfconsole, wpscan...etc) and methods (Sql injection, RFI, XSS) but....i can't hack my target =( so...what's the problem bro? I can't find the vulnerabilities! can't find anything, already have my target don't wanna change it , i need to take this one....so make a few nmap scans....they say ports 80 its open, version Apache httpd (that's all i get from this site) the server it suppose to run Linux 2.6.x also get some more info and the results are the next data: The information gathering: OS: Linux 2.6 Server: Apache (httpd) Country: United States WordPress and MetaGenerator: v3.5.1 Javascript library: JQueryv 1.8.3 i also find out that the site its running something called "All-in-one-SEO-pack" version 1.6.15.3 and that's " http://www.target.com/xmlrpc.php " exist.... SO.... also checked www.yougetsignal.com and try to find vulnerable sites to just get to the server but nothing....i can't find any sql hole or something like that, all sites are very clean to this beginner eyes =( its never something like " www.target.com/secrets.php?id=12 " ...its always just " www.target.com/secrets" or " www.target.com/secrets/super_secrets/the_deep_secrets " So please trow me a bone here i really want to accomplish my mission and own that site , I'm not going to break anything or make any damage to anybody =) want may be a little deface or just get the database to check it out , but first i need to get in, then o will think what to do xD Okey to finish this post i will share this video tutorial that's shows me web www.yougetsignal.com and make my think about to" really think out of the box" ...hope you like it I would like to say that BRUTE-FORCE its not working neither...this guy´s passwords isn't "password" or "123456" =S I am in fact brute forcing this target with Wpscan (since its running WordPress) and it doesn't have the "limit bad login " plugin...but after 20 hours of "rocking it" nothing happens and still have a lot of words but this method its not for me...may be a need another word lists, any effective shorter one? using rockyou.txt and darkOde.lst....run out of patience xD thanks for reading and sorry if misspell some words... my next missions will be about bot-nets if you have some interesting tut about please share =D have a nice hack Happy Hunting! RE: Help hacking "new sites" - Sinister Mission - Oni - 09-08-2013 Learning hacking tools? I don't even. RE: Help hacking "new sites" - Sinister Mission - Complibur - 09-08-2013 U wot m8? Lost here bro. H4xer tools is working pr3tty ub3r. RE: Help hacking "new sites" - Sinister Mission - Cyanide and Cynicism - 09-12-2013 First off, RFI is an outdated and horrible method. Did you mean LFI? If not, then learn it. Second, find out what other software the site has by looking around. Explore every single page and directory you can, get an account and learn the website from the inside out. Then you should be able to find a method. |