Need help for hack website
by flyshell - Saturday April 5, 2025 at 07:31 AM
#1
Hi,

This is a request for help to understand what else I can do without paying for your time, sorry
I would like to ask you to direct me, to suggest what next steps should be taken to achieve the goal = need a user info database from website

This info i already found:

# site_info:
CMS : WordPress ver.5.2.21
Blogs : WordPress
Database : MySQL
Programming Languages: PHP
JavaScript Graphics : Chart.js
JavaScript frameworks: Vue.js
Web servers: Nginx
Reverse Proxies: Nginx
Analytics: Google Analytics
Live chat : JivoChat
JavaScript Libraries: Selectize : Moment.js : jQuery
Different: Open Graph


# wp creds
wp_admin_username:yes
wp_admin_pwd:no
wp_admin_pwd_brute:tried_top9k_pwds:no_result


# zap:spider:active scan:Result:
High:
SQL Injection (139)
SQL Injection - Oracle - Time Based (8)
SQL Injection - SQLite (165)
Medium:
Absence of Anti-CSRF Tokens (5)
Content Security Policy (CSP) Header Not Set (284)
Missing Anti-clickjacking Header (226)
Vulnerable JS Library (4)
Low:
Cookie No HttpOnly Flag (5)
Cookie without SameSite Attribute (5)
Cross-Domain JavaScript Source File Inclusion (550)
Secure Pages Include Mixed Content
Server Leaks Version Information via "Server" HTTP Response Header Field (624)
Strict-Transport-Security Header Not Set (483)
X-Content-Type-Options Header Missing (325)


# ffuf -w raft-small-files-lowercase.txt
Have a this files:
license.txt
wp-login.php
favicon.ico
readme.html
robots.txt
wp-config.php
sitemap.xml
sitemap.html
wp-cron.php
wp-links-opml.php
sendmail.php
sitemap.xml.gz
wp-load.php
main.js
sitemap1.xml
sitemap2.html

But i don’t see anything interesting inside these files


# finalize target
need a user info database


All sql vuln url have a this 3 param: "count=3&sum=ZAP&term=ZAP"
i tried use sqlmap but my skill is not high and i didn’t get the desired result

Can someone tell me some other steps?

Thank you very much for your time!
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Need help to hack an instagram account azzenk 2 333 04-06-2025, 08:04 PM
Last Post: monalisa
  Where can i learn for 0 clicks hack for ios and android buffer overflow? Hackkkkkkk 6 1,105 04-03-2025, 04:53 PM
Last Post: rizee
  How to hack instagram account yvesdior 16 4,137 10-24-2024, 12:27 PM
Last Post: AdoumiBigBoy
  Need to carry out a cyberattack on the website robberto 2 513 07-09-2024, 01:15 PM
Last Post: Rusty
  Hacking Login Website Goverment Bwin27 0 1,656 10-27-2023, 01:34 PM
Last Post: Bwin27

Forum Jump:


 Users browsing this thread: 1 Guest(s)