Top 2000 Wordpress Plugins

The top 2000 Wordpress plugins by popularity. 2419 to be exact, all plugins with at least 5000+ active installs. List is accurate as of 20 Jan 2018. Interestingly, I could not find something similar online. The Wordpress plugins site does not allow sorting by popularity. Name Active Installs Last Updated ...

Smart Google Code Inserter < 3.5 - Auth Bypass/SQLi

Exploit Title: Smart Google Code Inserter < 3.5 - Auth Bypass/SQLi Google Dork: inurl:wp-content/plugins/smart-google-code-inserter/ Date: 26-Nov-17 Exploit Author: Benjamin Lim Vendor Homepage: http://oturia.com/ Software Link: https://wordpress.org/plugins/smart-google-code-inserter/ Version: 3.4 Tested on: Kali Linux 2.0 CVE : CVE-2018-3810 (Authentication Bypass with resultant ...

Designing an offline authentication system

I have recently got to know of the igloohome digital lock. It is completely offline and connects to the app via bluetooth only. No internet connection. One of the most puzzling features is that the owner can remotely generate a PIN code, valid for a certain duration, and have it ...

SANS SEC660 review

SEC660 I recently had the opportunity to attend the SANS SEC660 course held in Singapore in October 2017. The course was conducted by Tim Medin and covered advanced penetration testing and exploit writing. SEC660 started off introducing ARP spoofing, SSL striping and IPv6 router advertisements MITM attacks. It would have ...

Piwik - Possible XSS in RDNS lookup function

The possible XSS vulnerability can be found in version 3.1.1 of the Piwik software itself. The getHostname() function in piwik/vendor/piwik/network/src/IP.php does not sanitize the hostname before returning the value. This results in a possible XSS if Piwik itself or any plugins use ...

CVE-2017-14766 Simple Student Result < 1.6.4 - Auth Bypass

Exploit Title: Simple Student Result < 1.6.4 - Auth Bypass Google Dork: inurl:wp-content/plugins/simple-student-result Date: 21-Sep-17 Exploit Author: Benjamin Lim Vendor Homepage: https://ssr.saadamin.com/ Software Link: https://wordpress.org/plugins/simple-student-result/ Version: < 1.6.4 Tested on: Kali Linux 2.0 CVE : CVE-2017-14766 1. Product & Service ...