BF EX 0DAY EXPLOIT BRUTEFORCE GET WP LOGIN WORDPRESS AND AUTO UPLOAD SHELL
1. WordPress Detection - Automatically identifies if the target site runs WordPress by checking /wp-login.php and analyzing server responses.
2. Username Extraction - Extracts usernames using 3 methods: /?author=X enumeration, REST API (/wp-json/wp/v2/users), and URL pattern analysis.
3. Smart Credential Generation - Generates custom password lists based on the domain name and discovered usernames.
4. Fast Brute Force (Top 50) - Tests the 50 most likely username/password combinations first for maximum speed.
5. SQL Injection Exploit (0day) - (Blind SQL Injection) to create a new administrator account without any credentials.
6. Automatic Admin Verification - Verifies the SQLi-created admin account actually works by logging in and checking access to /wp-admin/index.php.
7. Deep Brute Force - If SQLi fails, continues testing ALL remaining credentials from the database.
8. Auto Shell Upload (4 Methods) - Automatically uploads a PHP shell using multiple techniques: Plugin Upload, Theme Upload, File Manager Exploit, and Theme Editor Injection.
9. Shell Verification - Tests the uploaded shell URL to confirm it's working and accessible.
10. Results Logging - Saves all successful logins to Successfully-login.txt and all shell URLs to BF_Shells.txt.
Telegram
༺ X7ROOT C S ༻
Привет - @Durov Этот канал не противоречит закону. И в нем нет порнографических и грубых постов. пожалуйста, обратите внимание! Наш официальный канал с гордостью @Telegram No Spam No Pornographi Владелец: @X7ROOT
🔒 Bu içeriği görmek için giriş yapın