1 step Pwn - from Google to pwning - Stupid WordPress users..


Sooo .. I was googling a totally unrelated search term and found what I thought was a relevant link ...

... except the user replaced his wordpress installation with a default one - UNCONFIGURED.

Which means when I went to the site, I got this:


Sooo, I can now simply configure Wordpress, access the database and the server by using a couple of WordPress plugins to install any PHP I desire on the server.

I am sending an e-mail to the website owner to inform him of his unconfigured setup.. but if I would have my black hat on (do caps count, or is it only fedoras?) I would simply take over this hosting account.

What would you do when you see this in the wild?

Configure it to secure it, then report it to the owner?

Leave it as is?


Definitely don't make any changes on it, doing that breaks laws in most places that have computer laws.

Reporting it back to the owner is good if you can find their details, if you can't then report to the hosting company who may or may not be interested.

