Syahrul Akbar R
2 min readDec 28, 2018

How I Takeover Wordpress Admin fiiipay.my

Hello everyone, in this post im gonna show you how i takeover admin on cms wordpress and get bounty ๐Ÿ˜†.

  1. First of all is RECON, so i goto https://fiiipay.my and check what cms they use and i see they are using wordpress .
  2. Then i check admin page with adding โ€œ/wp-adminโ€ after home url
  3. i got redirected to โ€œ/setup-config.phpโ€
w00t ?

4. W00t?,, I click lets go and set new database configuration with remote my sql, https://www.freemysqlhosting.net/

5. After that i got redirect to โ€œ/wp-admin/install.phpโ€ and i set new user & password wordpress

6. Login to wordpress

After this, i reported this vulnerability to AntiHack,

  • Nov 20, 2018 โ€” Sent Report to AntiHack
  • Nov 20, 2018 โ€” AntiHack change status to New
  • Dec 13, 2018 โ€” AntiHack rewarded me $300 SGD
  • Dec 28, 2018 โ€” Bounty received
Syahrul Akbar R
Syahrul Akbar R

No responses yet