RE: Found admin panel, now what? 10-12-2013, 03:24 AM
#5
Every answer I've seen in this thread is retarded, "WHMCS is vuln", yes publicly that depends on which version it is running, everything is vuln, the question is do you posess the exploit to take advantage of that vuln...And don't fucking say, HAVE YOU TRIED SQLI RFI LFI HURRR, you might as well ask him if he ran acunetix...And if he could perform a basic pentest then he should have already have tried those rudimentary techniques.
to OP, don't use any bullshit autohax programs, wpscan is useful for gaining some info, now that you know a majority of plugins it runs, try to audit the source of those plugins, then you can own the site...if you want to sitback and bruteforce the /wp-admin/ you are free to do so, but unless the admin is as stupid as you you aren't going to get him that way, wpscan has a bruteforce feature, you should really read the help docs before asking stupid questions
to OP, don't use any bullshit autohax programs, wpscan is useful for gaining some info, now that you know a majority of plugins it runs, try to audit the source of those plugins, then you can own the site...if you want to sitback and bruteforce the /wp-admin/ you are free to do so, but unless the admin is as stupid as you you aren't going to get him that way, wpscan has a bruteforce feature, you should really read the help docs before asking stupid questions

![[+]](https://sinister.li/images/modern/collapse_collapsed.png)