13.gif

Search (advanced search)
Use this Search form before posting, asking or make a new thread.
Tips: Use Quotation mark to search words (eg. "How To Make Money Online")

07-12-2014, 01:46 AM
Post: #1
Please null http://vinewp.com/
hi people

can anyone please null this for me

http://vinewp.com/


i keep requesting but cant se any result so thought a post will help :D
12-22-2014, 05:45 AM
Post: #2
RE:
sure, I can null, where do I get the script? do you have it?
12-22-2014, 06:42 AM (This post was last modified: 12-22-2014 06:43 AM by oasisfleeting.)
Post: #3
RE: Please null http://vinewp.com/
(07-12-2014 01:46 AM)kiwizz Wrote:  hi people

can anyone please null this for me

http://vinewp.com/


i keep requesting but cant se any result so thought a post will help :D
Here you are. I want to become a VIP and get in on some of these group buys. How do I do it?

[hide]http://www22.zippyshare.com/v/48794932/file.html[/hide]
12-22-2014, 07:15 AM
Post: #4
RE: Please null http://vinewp.com/
(12-22-2014 06:42 AM)oasisfleeting Wrote:  
(07-12-2014 01:46 AM)kiwizz Wrote:  hi people

can anyone please null this for me

http://vinewp.com/


i keep requesting but cant se any result so thought a post will help :D
Here you are. I want to become a VIP and get in on some of these group buys. How do I do it?

[hide]http://www22.zippyshare.com/v/48794932/file.html[/hide]
that script is already nulled... and not same as the vinewp its a php script.. if anyone has this template post here pls
12-22-2014, 09:09 PM
Post: #5
RE:
Uhh, hey dude, if you just look at the source code you'll see what you think is some super special vine version of wordpress is just the netix theme combined with the script I posted.
http://netix-wp.webfactoryltd.com/ <--- does this look familiar?
74.gif
12-22-2014, 09:42 PM (This post was last modified: 12-22-2014 09:50 PM by oasisfleeting.)
Post: #6
RE:
okay, let's walk through this..
First, I registered here.
http://vinewp.com/vine/wp-login.php

Then I started examining source codes
I saw the plugins he was using. pretty much 90% of wordpress plugins are vulnerable.
First thing that caught my eye was the shop. jigo.
So I went here and downloaded the plugin.

https://wordpress.org/plugins/jigoshop/

Now I'm looking for local file inclusion bugs in the code.

jesus, wordpress developers are so clueless.
After downlading that shop plugin, I see a few files that i can use lfi on to find out the version he's using and my ultimate goal here is to find a download directory that isn't blocked by apache. I don't think that's going to happen though he appears to have indexing off and it's probably password protected.

http://vinewp.com/shop/wp-content/plugin...readme.txt
http://vinewp.com/shop/wp-content/plugin...oducts.xml <-- scrumptious




44.gif
Free counters!