Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Wpscan usage tutorial

Shulou Source: shulou.com Published: 2022-06-01 06:12:33 10月04日 Update

First, a brief introduction:

Test system: kalilinux

Wpscan can detect the version, theme, plug-in and so on of wordpres, and can guess the background user name and burst password.

Scan vulnerability plug-in, support multi-threading, proxy and other functions.

Second: use method

1: probe basic information

Wpscan--urlwww.xxx.com

2: comprehensive testing

Wpscan--urlwww.xxx.com-e

3: scan plug-in

Wpscan--urlwwww.xxx.com-enumeratep

Scan only plug-ins that are vulnerable to *

Wpscan--urlwwww.xxx.com-enumeratevp

Scan all plug-ins

Wpscan--urlwwww.xxx.com-enumerateap

4: guess the user

Wpscan--urlwww.xx.com-eu or

Wpscan--urlwww.xxx.com-enumerateu

5: explode admin user password

Wpscan--urlwww.xxx.com-- dictionary .txt-- useruanmeadmin

Add a multithreading to speed up.

Wpscan--urlwww.xxx.com-- dictionary .txt-- useruanmeadmin--threads30

6: agent

Wpscan--urlwww.xxx.com-proxy127.0.0.1:8080

The agent can be used to grab the scan information of wpscan in combination with burpsuit.

Function base other functions wpscan-h take a look

Tags: Plug-ins functions users agents information dictionaries passwords threads detection explosions themes usage background methods test systems vulnerabilities versions user names systems probes Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Linux Apple MySQL Shulou Tech Info Docker