WordPress Vulnerabilities
Key Takeaways
The video 'WordPress Vulnerabilities' by The Cyber Mentor demonstrates how to exploit WordPress vulnerabilities, including enumeration, vulnerability scanning, and Brute Force attacks, using tools like WP Scan, ffuf, and XML-RPC.
Full Transcript
WordPress is a free and open-source content management system or CMS that uses PHP and MySQL its flexibility is likely due to its extensible plug-in architecture and templating system as well as being able to administer basically everything through a web interface you'll see WordPress running blogs company websites and e-commerce stores today we're going to spin up a WordPress instance using Docker and Docker compos for testing then take a look at the structure and some key elements of Wordpress do some manual enumeration some automated enumeration with WP scan and then attack the administrator accounts in part two we'll dive more into how to exploit plugins and misc configurations as always if you enjoy the video don't forget to like And subscribe and let's dive in so for installation I'm actually here on my Debian machine and of course you can use Cali to run your WordPress instance if you want to follow along but I like to keep some separation between the web apps that I'm hosting and my Cali VM which I used to carry out attacks just a personal preference really now if you don't have Docker and Docker compos installed already you can do this with pseudo appinstall docker.io and then same again pseudo appinstall docker-compose and just so you can see the versions that I'm running so if I just do Docker D- version I've got Docker 20.10 and then Docker compose Das Das version I think this is 1.25 and I do have version two as well uh in my Ops folder Docker compos 2-- version but 1.25 will do us for today so first up what I'm going to do is I'm going to come over to this gist that I have and this has the docker compose yaml file the link to this will be in the description below so all I'm going to do is Click raw crl a contrl c come back to my terminal and just pseudo Vim Docker compose do yaml insert paste and you can see we're pulling down MySQL and also the WordPress latest which I think is 6.2 so I'm just going to save this and then we should be good to go so pseudo Docker compose up you can use DD to run this in the background but I like to have it running in the terminal so that when I'm working I can see the messages and the traffic and we'll give this a minute to boot up all right looks like it's up and running so I'm just going to come over to my browser come to Local Host and here we have the installation so I'm just going to change this to English UK click continue and the site title can be tasu and the username Alex and I'm going to set a weak password because we're going to demo a Brute Force attack so I'm just going to set this it's quite nice that WordPress now has the confirm use of weak password hopefully that will discourage some users from using week passwords when they're doing their initial setup and then we have an email address so I'm just going to do ASD asd.com and then install WordPress so here we are we can log in Alex and Alex and we're logged in and good to go now there is a one more configuration change that we need to make because you see here we're running on Local Host when I try to access this from my other VM even though I can find the website using the IP address of this machine all of the internal links will be things like Local Host SL whatever whatever so I won't be able to navigate to the sites without having to manually change that each time so all I'm going to do is come down into settings and you can see we have the WordPress address and the site URL and then I'm just going to come back here grab my IP address which is 1010100 146 paste this in here and then click save changes and then we need to relog back in but as you can see we're at 1010100 146 instead of Local Host now so now I'm going to go ahead and create some content so obviously when we're attacking this we need a little bit of content on the website to have things to actually interact with so if we just come into Pages We'll add new and verasu is the best and then this is some content and then I'm just going to hit publish that looks like it's worked we'll come back to here and then I don't think we need to change the theme we can just keep the 2020 theme and then plugins I'm just going to activate these plugins here so I just click activate I'm not going to put the email address in activate that one let's add one from the library so let's just install buddy press once this is installed we'll just click activate and then when we're running our enumeration scripts against WordPress hopefully we'll be able to find these plugins now one last thing before we jump into enumeration and start attacking our site I want to show you some of the key files and directories so if I just come back over to my terminal and we do p sudo do ps- a and here we have the container ID of our WordPress latest and I'm just going to copy this and then pseudo Docker exac dasit bash and we're going to drop into a shell on this container and as you can see it's dropped us into VD HTML so I'm just going to lsla and here you can see our WordPress installation one key file that I want to start with is the WPC config.php so if you can read files on a server through some exploit often there are hard-coded credentials in here now I suspect because we're running Docker it's just going to use the environment variables but let's take a quick look so we'll just cat WPC config.php and you can see the keys and the salts for our installation and here we have the database settings so here we have the DB name obviously it's using the environment variables but often you'll see hardcoded usernames and passwords in here so this is always a good file to Target if you can read files on the server or you get something like file inclusion use filters to read the PHP file instead of executing it so next up we have the folder WP includes so let's just take a look in there and in here is all of the core components and things used to run WordPress so we'll come back out of this and WP content is also important so if we CD into WP content which is just here here we can see things like plugins and uploads and this is also an important directory to be aware of for the rest I recommend you come in and just take a quick look around maybe skim over the documentation because understanding some of the core files and structures of Wordpress is going to help you later on when you have vulnerabilities like file uploads or file inclusion or carrying out eneration so gaining a basic understanding of what's Happening under the hood is really helpful but for now let's move on to some basic enumeration I'm just going to head over to my Cali machine log myself in let's open up a terminal and also Firefox as well and if I recall we're running on 1010 100 146 and here we are so the first thing we want to do is get the WordPress version and unless the site's using a plug-in that strips this out of the HTML we can just have a look at the source code I'll zoom in a little bit and just search for WordPress and usually you'll get this WordPress 6.2.2 you can also check the CSS files so I think style. min. CSS here we are and we also have version 6.2.2 as well so this is probably the easiest and quickest way to get the version and obviously you can do a very quick search exploit for 6.2 too so next up we want to enumerate the plugins so on older versions or misconfigured versions of Wordpress we can go to DWP content which is a folder that we just looked at a minute ago and then we can go to SL plugins and as you can see we don't actually get any information back so there's no directory listing which is a good thing so that means that this is well configured but of course if we come back to our machine and we come into plugins there is actually some content in there so buddy press that we installed and some other things as well so there are a couple of ways to enumerate plugins even though we can't access this directory directly so I'm just going to come back and first up we'll just use FFF so ffuf and I'll grab this Das and then we'll fuzz and the word list can be user share word lists DB and we'll just do common for now and we'll do- e. PHP since we there are some PHP files in there and we can leave this running and I suspect what will happen is it will give us a bunch of 301 so some redirect so if we see activity for example and we copy this and then we go to here what word press is actually doing is it's saying hey you're trying to access this but your path looks like it's a little bit wrong and so it's actually going to forward us to this page but in a different location so if you're using fuff you might have to go ahead and filter out 301s and then continue your scan but for now I'm just going to stop this and then what we're going to do is we're going to take a look at WP scan which is obviously designed more for WordPress so WP scan D- URL and hopefully what this will do is it will give us the version and all of the plugins so 101046 hit enter and notice we're not using the API token yet because we don't need it we're not actually looking for vulnerabilities we're just trying to enumerate information that was pretty quick obviously this is running locally so it's going to be a little bit faster than attacking something that's online and let's verify some of this information so we've got interesting entry so the Apache version and we've got the PHP version we've got the WordPress version here so WordPress version 6.2.2 identified and then the theme in use 2023 and it found buddy press as well gives us a version tells us that it's up to date which is also useful to know and that's about it now here it says yeah no API token was given so if we wanted to give an API token we just do-- API token and we insert our token here if you want a token then you just go to WP scan.com sign up a free account and I think you get 25 scans a day with the free token in part two we'll do a little bit more of that since we'll be attacking plugins and the WordPress installation itself but for today we don't actually need the API so next what I want to do is I want to find some users so that we can attack them so I'm going to come to the website and usually part of my enumeration will be clicking around making sure I know what content's available and harvesting information from the site especially if you're doing a CTF you'll often find comments or pages that you know reveal some information or Clues but in the real world what we're interested in is usernames so we can just go to this post and you can see we get this posted on 12th of June 2023 in uncategorized by Alex so let's go to wp-admin and here we are at the login form and all I'm going to do is I'm going to paste Alex and just put in a random password and here we get an error the password you entered for the username Alex is incorrect and by default WordPress has this kind of weakness that is not best prac practice where you type in a username wrong it will tell you and it'll say hey the username admin is not registered so if the default configuration hasn't changed and there's no Brute Force protection we can easily enumerate usernames and I'm pretty surprised WordPress hasn't changed this by now this is kind of a common weakness that it's not really acceptable for modern web applications so let's try and Brute Force this account and what we're going to do is we're going to keep our scan syntax the same except we're going to add dasu Alex DP user share word list rock you and this is a very long word list this probably take days to complete even locally but I'm just going to run it for demo purposes anyway we'll just hit enter and then it'll do the same enumeration as before we give it a second to run and then here we are so performing password attack on XML RPC against one user so if we just open up a new terminal what we can do is we just cat user share word list rock you and let's just grab for Alex although we wants an exact match so let's do FX and then let's find the line number okay so we know the password is Alex so for demo purposes and we know that it's on 403 in rock Q so let's see how long this is going to take we're already at 2,600 so it shouldn't take too much longer into until we manage to crack it so let's see if this is successful and here we are so it's found valid combinations and username Alex password Alex so we can verify this we can just come in here and do Alex and Alex and here we are on the dashboard so that's it for this video in part two we'll take a look at how we can exploit plugins and misconfigured versions of Wordpress as well as how to get a shell from the admin Das board as always if you enjoyed the video don't forget to like And subscribe it really helps us out and I'll catch you in part two
Original Description
Alex dives into WordPress vulnerabilities into this video, providing detailed walkthroughs of the exploit process. There's also a second part to this series, which you can watch here: https://youtu.be/8AZKloj28pE
If you want to see more of this kind of content, be sure to subscribe to see the latest from our team! Alex usually livestreams every Wednesday 12 PM ET to do some hacking, so come by and say hi the next time we're live.
#wordpress #cybersecurity #hacking101 #vulnerabilities
00:00 Intro
00:47 Setup WordPress
05:00 Core files primer
07:17 Enumerating WordPress
08:40 Scanning for plugins
09:42 Scanning with wpscan
11:20 Attacking users
13:50 Outro
Link to repo: https://gist.github.com/AppSecExplained/8bbf5366c6279ffc44beec16e6c39855
Pentests & Security Consulting: https://tcm-sec.com
Get Trained: https://academy.tcm-sec.com
Get Certified: https://certifications.tcm-sec.com
Merch: https://merch.tcm-sec.com
Sponsorship Inquiries: info@thecybermentor.com
📱Social Media📱
___________________________________________
Twitter: https://twitter.com/thecybermentor
Twitch: https://www.twitch.tv/thecybermentor
Instagram: https://instagram.com/thecybermentor
LinkedIn: https://www.linkedin.com/in/heathadams
TikTok: https://tiktok.com/@thecybermentor
Discord: https://discord.gg/tcm
💸Donate💸
___________________________________________
Like the channel? Please consider supporting me on Patreon:
https://www.patreon.com/thecybermentor
Support the stream (one-time): https://streamlabs.com/thecybermentor
Hacker Books:
Penetration Testing: A Hands-On Introduction to Hacking: https://amzn.to/31GN7iX
The Hacker Playbook 3: https://amzn.to/34XkIY2
Hacking: The Art of Exploitation: https://amzn.to/2VchDyL
The Web Application Hacker's Handbook: https://amzn.to/30Fj21S
Real-World Bug Hunting: A Field Guide to Web Hacking: https://amzn.to/2V9srOe
Social Engineering: The Science of Human Hacking: https://amzn.to/31HAmVx
Linux Basics for Hackers: https://amzn.to/34WvcXP
Pytho
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from The Cyber Mentor · The Cyber Mentor · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Buffer Overflows Made Easy - Part 1: Introduction
The Cyber Mentor
Buffer Overflows Made Easy - Part 2: Spiking
The Cyber Mentor
Buffer Overflows Made Easy - Part 3: Fuzzing
The Cyber Mentor
Buffer Overflows Made Easy - Part 4: Finding the Offset
The Cyber Mentor
Buffer Overflows Made Easy - Part 5: Overwriting the EIP
The Cyber Mentor
Buffer Overflows Made Easy - Part 6: Finding Bad Characters
The Cyber Mentor
Buffer Overflows Made Easy - Part 7: Finding the Right Module
The Cyber Mentor
Buffer Overflows Made Easy - Part 8: Generating Shellcode and Gaining Shells
The Cyber Mentor
HackTheBox - Sunday Walkthrough (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - TCP, UDP, and the Three-Way Handshake (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - Network Subnetting (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - Network Subnetting Part 2: The Challenge (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - Building A Basic Network with Cisco Packet Tracer (Re-Up)
The Cyber Mentor
HackTheBox - Fighter Walkthrough (Re-Up)
The Cyber Mentor
Beginner Linux for Ethical Hackers - Navigating the File System
The Cyber Mentor
Beginner Linux for Ethical Hackers - Users and Privileges
The Cyber Mentor
Beginner Linux for Ethical Hackers - Common Network Commands
The Cyber Mentor
Beginner Linux for Ethical Hackers - Viewing, Creating, and Editing Files
The Cyber Mentor
Beginner Linux for Ethical Hackers - Controlling Kali Services
The Cyber Mentor
Beginner Linux for Ethical Hackers - Scripting with Bash
The Cyber Mentor
Beginner Linux for Ethical Hackers - Installing and Updating Tools
The Cyber Mentor
Cracking Linux Password Hashes with Hashcat
The Cyber Mentor
Reminder: Twitch Hacking Live Stream Tonight! 2/26/19 at 8PM EST
The Cyber Mentor
Hacking Live Stream: Episode 1 - Kioptrix Level 1, HackTheBox Jerry, and Career Q&A / AMA
The Cyber Mentor
Hacking Live Stream: Episode 2 - HackTheBox Active, Vulnserver Buffer Overflow, and Career Q&A / AMA
The Cyber Mentor
Hacking Live Stream: Episode 3 - Hack The Box Blue, Devel, and Career Q&A / AMA
The Cyber Mentor
New Zero to Hero Pentest Course, New Website, and 2K Subs?!
The Cyber Mentor
Zero to Hero Pentesting: Episode 1 - Course Introduction, Notekeeping, Introductory Linux, and AMA
The Cyber Mentor
Zero to Hero Pentesting: Episode 2 - Python 101
The Cyber Mentor
Zero to Hero Pentesting: Episode 3 - Python 102, Building a Terrible Port Scanner, and a Giveaway
The Cyber Mentor
Zero to Hero Pentesting: Episode 4 - Five Phases of Hacking + Passive OSINT
The Cyber Mentor
Zero to Hero Pentesting: Episode 5 - Scanning Tools (Nmap, Nessus, BurpSuite, etc.) & Tactics
The Cyber Mentor
Zero to Hero Pentesting: Episode 6 - Enumeration (Kioptrix & Hack The Box)
The Cyber Mentor
Zero to Hero Pentesting: Episode 7 - Exploitation, Shells, and Some Credential Stuffing
The Cyber Mentor
Installing Windows Server 2016 on VMWare in 5 Minutes
The Cyber Mentor
Zero to Hero: Week 8 - Building an AD Lab, LLMNR Poisoning, and NTLMv2 Cracking with Hashcat
The Cyber Mentor
A Day in the Life of an Ethical Hacker / Penetration Tester
The Cyber Mentor
Active Directory Exploitation - LLMNR/NBT-NS Poisoning
The Cyber Mentor
Zero to Hero: Week 9 - NTLM Relay, Token Impersonation, Pass the Hash, PsExec, and more
The Cyber Mentor
Zero to Hero: Episode 10 - MS17-010/EternalBlue, GPP/cPasswords, and Kerberoasting
The Cyber Mentor
Writing a Pentest Report
The Cyber Mentor
Zero to Hero: Week 11 - File Transfers, Pivoting, and Reporting Writing
The Cyber Mentor
The Complete Linux for Ethical Hackers Course for 2019
The Cyber Mentor
Full Ethical Hacking Course - Beginner Network Penetration Testing (2019)
The Cyber Mentor
Popping a Shell with SMB Relay and Empire
The Cyber Mentor
Pentesting for n00bs: Episode 1 - Legacy (hackthebox)
The Cyber Mentor
Pentesting for n00bs: Episode 2 - Lame
The Cyber Mentor
Pentesting for n00bs: Episode 3 - Blue
The Cyber Mentor
Web App Testing: Episode 1 - Enumeration
The Cyber Mentor
Pentesting for n00bs: Episode 4 - Devel
The Cyber Mentor
Pentesting for n00bs: Episode 5 - Jerry
The Cyber Mentor
Web App Testing: Episode 2 - Enumeration, XSS, and UI Bypassing
The Cyber Mentor
Pentesting for n00bs: Episode 6 - Nibbles
The Cyber Mentor
Web App Testing: Episode 3 - XSS, SQL Injection, and Broken Access Control
The Cyber Mentor
How NOT to Approach a Cybersecurity Mentor
The Cyber Mentor
Web App Testing: Episode 4 - XXE, Input Validation, Broken Access Control, and More XSS
The Cyber Mentor
Pentesting for n00bs: Episode 7 - Optimum (hackthebox)
The Cyber Mentor
Pentesting for n00bs: Episode 8 - Bashed (hackthebox)
The Cyber Mentor
Pentesting for n00bs: Episode 9 - Grandpa
The Cyber Mentor
Top 5 Internal Pentesting Methods
The Cyber Mentor
More on: Security Basics
View skill →Related Reads
📰
📰
📰
📰
That Voice on the Phone Sounds Exactly Like Your Boss. It Takes 5 Minutes to Fake.
Dev.to AI
E-Wallet Kamu Itu Sasaran Empuk: Cara Aman Pakai QRIS dan GoPay
Medium · Cybersecurity
Orisenc Technologies | Enterprise IT, Cloud & Cybersecurity Solutions
Medium · Cybersecurity
AWS Launches Amazon GuardDuty Investigation Agent to Automate Threat Triage
InfoQ AI/ML
Chapters (8)
Intro
0:47
Setup WordPress
5:00
Core files primer
7:17
Enumerating WordPress
8:40
Scanning for plugins
9:42
Scanning with wpscan
11:20
Attacking users
13:50
Outro
🎓
Tutor Explanation
DeepCamp AI