How to hack WordPress?

Поділитися
Вставка
  • Опубліковано 30 лип 2024
  • 🖥️ Check out the Wordfence Bug Bounty Program: bbre.dev/wf
    📧 Subscribe to BBRE Premium: bbre.dev/premium
    ✉️ Sign up for the mailing list: bbre.dev/nl
    📣 Follow me on Twitter: bbre.dev/tw
    In this video, I'm showing you how to start hacking Wordpress, how to analyse the source code of a WordPress plugin and what bugs to pay attention to to maximise your bounty.
    Wordfence Discord: / discord
    doker-compose.yaml: gist.github.com/Rhynorater/9c...
    Plugins in scope: ctbb.show/downloads/pluginData
    The credit for creating these goes to ‪@criticalthinkingpodcast‬
    Advanced Search in VS Code: members.bugbountyexplained.co...
    🖥 Get $100 in credits for Digital Ocean: bbre.dev/do
    Timestamps:
    00:00 Intro
    00:49 How to setup a local WordPress instance for testing?
    01:45 How to start analysing a WordPress plugin?
    09:24 Wordfence Bug Bounty Program
    11:30 How can a WordPress plugin create a new endpoint in another way?
    14:10 Walkthrough of a real vulnerability
  • Наука та технологія

КОМЕНТАРІ • 26

  • @BugBountyReportsExplained
    @BugBountyReportsExplained  6 місяців тому +2

    Thank you for watching the video and welcome to the comment section. You can check out the Wordfence Bug Bounty program here: bbre.dev/wf

    • @reed6514
      @reed6514 6 місяців тому

      It would have been nice to see a quick overview of how to submit the bug report to wordfence. I'm sure the link explains it fine, but it woulda been nice to see. Good video though.

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  6 місяців тому +1

      @@reed6514I think if you can find a valid bug in a plugin, you'll also deal with a simple form😉

    • @reed6514
      @reed6514 6 місяців тому

      ​@@BugBountyReportsExplainedlol very true

  • @newwindserver
    @newwindserver 6 місяців тому +13

    Can we get more videos showing real bugs that have already been patched, knowing there wil be a bug in the code we are looking over will make the video more engaging.

  • @xB-yg2iw
    @xB-yg2iw 6 місяців тому +3

    Love some php code review, so ill for sure try this!

  • @bissoghuri
    @bissoghuri 6 місяців тому +2

    Yoo amazing 🎉

  • @vuilachinh5252
    @vuilachinh5252 5 місяців тому

    very helpful video, thank man:)

  • @MarkFoudy
    @MarkFoudy 6 місяців тому +1

    Love this

  • @entertainment6655
    @entertainment6655 6 місяців тому +2

    Amazing

  • @OthmanAlikhan
    @OthmanAlikhan 4 місяці тому

    Thanks for the video =)

  • @ahmetsaric5364
    @ahmetsaric5364 5 місяців тому

    Hello and thank you.

  • @brandonsteve9702
    @brandonsteve9702 6 місяців тому

    whats the best online platform/group/channels for me to learn more about this topic??

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  6 місяців тому

      Wordfence Discord is the probably the best community for this. The link is in the description ;)

  • @visualmodo
    @visualmodo 6 місяців тому

    Really good content :)

  • @0xchilli
    @0xchilli 5 місяців тому

    I am convinced you are the pentesterlab dude

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  5 місяців тому

      I am not though

    • @0xchilli
      @0xchilli 5 місяців тому

      @@BugBountyReportsExplained Oh Wow I DID NOT EXPECT YOU WILL REPLY , I love your content thank you so much for your effort.

  • @jonathanma4814
    @jonathanma4814 5 місяців тому

    Vidno chto svoy)

    • @BlaowVEVO
      @BlaowVEVO 5 місяців тому

      Какой свой, он с германии или нидерландов. Точно не помню, но он точно не с снг.

  • @entertainment6655
    @entertainment6655 6 місяців тому +3

    First comment buddy

  • @user-zl9dy6hz2q
    @user-zl9dy6hz2q 6 місяців тому +1

    Sny bbrf discount available

  • @user-ic4hs1cc1h
    @user-ic4hs1cc1h 5 місяців тому

    is there a need to enable anything from settings of VS Code? There's no match found for '

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  5 місяців тому

      you need to enable the regex search which is in the search input field

    • @user-ic4hs1cc1h
      @user-ic4hs1cc1h 5 місяців тому

      hey, yeah I had figured that out, thanks for the reply and such an amazing video
      @@BugBountyReportsExplained
      any resource recommendations on sharping our source code analysis skills?