BIG thank you to Hack The Box for making this video happen. Check them out below and start HACKING! 👇 Learn to hack with HackTheBox Academy ▶ www.certbros.com/HTBAcademy Start the Bug Bount Hunter Training ▶ www.certbros.com/HTB_CBBH Put your skills to the test with HackTheBox ▶ www.certbros.com/HackTheBox
@huangzeyong2 жыл бұрын
haha,dhcp. dns
@KEEN29992 жыл бұрын
Do you have a case if the site does not support wordpress
@femijude6129 Жыл бұрын
Can you do a tutorial on how to hack Gmail password
@JacobBilson Жыл бұрын
I want to start learning how to hack from today can you help me with any app that can help me get hacker's sense like you
@SumanRoy.official2 жыл бұрын
Please Note : A situation where a 0-day is discovered wpscan won't upload the documentation for it, because they like to give the vendor some time to mitigate the issue. Timeframe is usually 30 days. By that time it gets patched, making the vulnerability useless to exploit and hackers won't be able detect it via wpscan because it won't get reported in your scans until that patch window expires. Only the sites which did not patch it because the users are unaware of it can then be exploited.
@Dear_LotterySambad2 жыл бұрын
tomar Instagram id pete pari?
@SumanRoy.official2 жыл бұрын
@@Dear_LotterySambad i don't do insta, nor facebook
@superstrongninja11 ай бұрын
@@SumanRoy.official tele?
@hnp-tv2 жыл бұрын
Show me 1 Website, what you hacked with a Wordlist? Before you speak about 455 Million Websites. This Video is not realistic. It will not works.
@Louis_H_ Жыл бұрын
455 million websites meaning they run on WordPress and it has a lot of vulnerabilities, of course you can't hack all of them and probably a lot of them don't contain that interesting of info, but a lot of them probably have sub par security because they're based on Wordpress
@siavash_id Жыл бұрын
maybe you can't by using a word list , but the governments or people with lots of power and money can easily brute force it by big GPUs ... I'm just kidding! you can hack it yourself by using a cloud GPU with a hundred times more power than a desktop GPU like 4090 and just 3/Hour is the bill you have to pay...
@Mike-xm1hl Жыл бұрын
WordPress is be exploited daily. Trust me. Easy money for hackers
@thiyamsuresh4918 Жыл бұрын
@@siavash_idwhat if the password are not in the word list?
@Idkfornowlol Жыл бұрын
@@thiyamsuresh4918bruteforce then
@Free.Education786 Жыл бұрын
Please, if possible, cover these advanced topics like How to bypass Drupal CMS or other secured CMS? How to bypass HARD WAF protection that stops HTML, SQL, and XSS injection payloads? Payload single-double-triple encoding using Cyber-Chef? How to find the real origin IP of secured websites behind Cloudflare, Akamai, ModSecurity, AWS CDN, etc.,? How to bypass Hard WAF using SQLMAP or Burpsuite? How to find hidden vulnerable parameters and endpoints inside the .js and .jason files? How to find hidden admin pages, cPanel pages, and WHM pages ? Please cover these important topics. Thanks
@zadekeys21946 ай бұрын
Do you know that you can ask Google or most Ai tools these questions and start learning for yourself? :) Learn nMap, Burp Suite , Wazuh.
@SabbirHossain-vu4ic15 күн бұрын
Bro, unfortunately, no one will cover these topics. You have to learn these all yourself.
@Free.Education78615 күн бұрын
@ Bro 😎 AlhamdulilAllah. I am master now. I learned everything from AI bots 🤖 and master myself. These were past talks. Now I can hack any website regardless of their server os programming languages waf cms. Actually no one talks or share real stuff. Bro study http request response system and start exploiting the vulnerabilities using it. I hope 🤞 you understand what I’m talking now ✅🚀🔐🔥🤖❤️🎩📞🎉🎈😎✌️✈️🤴🗳️💰
@paulvargas74062 жыл бұрын
Exactly what I was looking for. Cheers!
@jasgarcha47832 жыл бұрын
Great share for those interested in Hacking - ethically, of course 😊. Thank you.
@Certbros2 жыл бұрын
Thank you Jas!
@KEEN29992 жыл бұрын
Do you have a case if the site does not support wordpress
@nervall_revolt2 жыл бұрын
2:03 Ah, yes… My favourite CMS, *WordPess* xd Great video btw!
@lisansarkar79492 жыл бұрын
Most underrated content
@conmcdon2 жыл бұрын
Excellent video!! Thanks so much for this. I was wondering if you would consider a follow-up that goes into the details of RCE via the theme editor. It's also in the Hack the Box lesson, but the instructions on how to utilize a web shell aren't very clear. For example, how does one utilize a web shell to access specific files on the server?
@conmcdon2 жыл бұрын
I've just figured it out, actually. If anyone finds this comment in the future and is wondering how to solve that exercise: You need to set the command parameter equal cat with the location of whatever file you want to read. Because you can't have spaces in a URL, however, you have to append %20 to cat, just before the location. It'll look like this: cat%20/home/wp-user/flag.txt
@jinminetics599 Жыл бұрын
Instead of replacing spaces with %20, just url-encode the payload/command. There would be other characters aside space you would have to handle. So encoding the payload is the best way to do it not manual replacements.
@mahdidelavaran10992 жыл бұрын
hi your ccna course was very good would you consider creating a security plus course
@Certbros2 жыл бұрын
Thank you Mahdi! Great to hear you enjoyed the course. Yes absolutely! I would love to do a Security+ course. It's next on my list of courses
@KEEN29992 жыл бұрын
Do you have a case if the site does not support wordpress
@KEEN29992 жыл бұрын
@@Certbros Do you have a case if the site does not support wordpress
@MarkoKozlica4 ай бұрын
Hack the Box is a bit expensive and I would like to learn more about hacking Wordpress sites, any suggestions? thx
@LennyMiller7393 ай бұрын
Vulnhub has some stuff you can play with. Hard to figure out which one to do though as it's not curated
@powerseostrategy Жыл бұрын
Now there's 810 Million Wordpress sites.
@PenAce2 жыл бұрын
This will be covered in greater detail on my page!
@KEEN29992 жыл бұрын
Do you have a case if the site does not support wordpress
@PenAce2 жыл бұрын
@@KEEN2999 There is always a way where there is an administrator. I'll be posting soon!
@KEEN29992 жыл бұрын
@@PenAce What happened with you
@PenAce2 жыл бұрын
@@KEEN2999 What exactly do you mean?
@danielruzicka38582 жыл бұрын
You look like that guy who played Edward Snowden in Snowden movie
@mohamedizhag98322 жыл бұрын
You are right, there is a great similarities.
@mohamedizhag98322 жыл бұрын
I have seen the movie and it is inspiring and wonderful.
@bharathnaidu1072 жыл бұрын
Learned so much about wpscan tool.Tha nk you ❤️
@Certbros2 жыл бұрын
Great to hear it! Thank you
@KEEN29992 жыл бұрын
Do you have a case if the site does not support wordpress
@KEEN29992 жыл бұрын
@@Certbros Do you have a case if the site does not support wordpress
@MSLTV-je6bn7 ай бұрын
mean which place I put these prompt ?please tell me about it
@qompete65372 жыл бұрын
Location for your rockyoutext says does not exists or is not a file ???
@viktorsalamaha12192 жыл бұрын
Most wordpress sites use random passwords, where can I get sheets with these passwords? I think nowhere)
@kSITHerland Жыл бұрын
it would stand to reason that these passwords would be inculded inwhole or in part buy some of the bigger lists published of such breaches , which ones they are though i wouldnt begin to know
@Wavy6729 ай бұрын
wpscan detected 0 vulnerabilities (sorry if i misspelled it) 0 vulnerable plugins etc., what should i do?
@Bakekun9 ай бұрын
Nothing, If the website has no vulnerabilities then you cant use wpscan to hack it
@zadekeys21946 ай бұрын
Scan with more tools.... Don't assume 1 tool can scan for all vulnerabilities OR that it didn't make a mistake...
@nikosdimou72915 ай бұрын
you dont need bf if is lfi attack you can call the ssh file and take the rsa key
@ancour8 ай бұрын
Instead of parrot, will these functions in other kali os
@whysoserious4832 жыл бұрын
Celebrate the day who teach us to SWEAT MORE Happy Teacher's Day ❤️ man
@Certbros2 жыл бұрын
Thank you very much! I really appreciate that 🙏 😀
@MSLTV-je6bn7 ай бұрын
hi sir where i put it in cmd?
@visualmodo2 жыл бұрын
Very good video!
@Certbros2 жыл бұрын
Thank you!
@juniorferreira9635 Жыл бұрын
took me a while due to mistake, but it works thanks
@braimahchannel3639 Жыл бұрын
I love the hacking teaching, I wish you can teach me
@agnesanu.v8862 жыл бұрын
Sir.... could you please help me to hack a website
@3livesleft5772 жыл бұрын
Can this be used unethically? I have never used word press, but doesn't this encourage people to attempt to find credit card info or personal addresses? (I am new to this whole world of information technology)
@Certbros2 жыл бұрын
The purpose of this video is to show people how WordPress can be targeted and the methods that can be used in legal pentests or bug bounties. Of course, I would never condone any malicious use.
@huangzeyong2 жыл бұрын
what is going on? i am using VPN ,
@SunilKumar-wp7st Жыл бұрын
Om Pls help hack site..& help us recover our initial booked usdt
@timecop1983Two10 ай бұрын
Now 810 Million
@kman4658 Жыл бұрын
Hehehe 2:06 Word Pess
@MSLTV-je6bn7 ай бұрын
any one can help me?
@domingosdias5988 Жыл бұрын
Ganhou um novo inscrito de Angola!
@full_automation Жыл бұрын
Thank you❤️
@donga6713 Жыл бұрын
Weak informations but useful
@thelasteffort6785 Жыл бұрын
hacker wont show his face...😂😂😂
@omodesigner Жыл бұрын
Ahahaha Ahahaha like it
@-.-ahmed---ahmed-.- Жыл бұрын
FROM algeria pro the. s is 👾👾
@yassirdubad13862 жыл бұрын
i'm too early damn!!!!!!!
@Certbros2 жыл бұрын
You're right on time!
@KEEN29992 жыл бұрын
@@Certbros Do you have a case if the site does not support wordpress
@KEEN29992 жыл бұрын
Do you have a case if the site does not support wordpress
@РЕТСОАй бұрын
Thx
@JoseAbreuu2 жыл бұрын
could I use dirb instead of wpscan?
@gniewko1234562 жыл бұрын
sure
@mason-zi5yz Жыл бұрын
next time you should say that you have to pay for it