搜索
查看: 543|回复: 0

WordPress系统暴力破解测试工具 – wpbf

[复制链接]

1839

主题

2255

帖子

1万

积分

管理员

Rank: 9Rank: 9Rank: 9

积分
11913
发表于 2014-6-21 16:10:15 | 显示全部楼层 |阅读模式
wpbf这款工具可以帮助渗透测试人员,针对WordPress博客后台进行爆破测试。
特性
用户名枚举和发现
  1. 多线程
  2. 自动使用博客内容中的关键字作为字典
  3. HTTP代理支持
  4. 基本的Wordpress指纹探测
  5. 高级指纹探测插件
复制代码

基本使用方法
  1. $ ./wpbf.py http://localhost/wordpress/
  2. 2012-02-26 14:26:18,793 - INFO - Target URL: http://localhost/wordpress/
  3. 2012-02-26 14:26:18,844 - INFO - Checking URL and username...
  4. 2012-02-26 14:26:18,845 - INFO - Enumerating users...
  5. 2012-02-26 14:26:52,027 - INFO - Usernames: admin, test, guest
  6. 2012-02-26 14:26:54,153 - INFO - 31 plugins will be tested
  7. 2012-02-26 14:26:55,311 - INFO - 215 passwords will be tested
  8. 2012-02-26 14:26:55,369 - INFO - Starting workers...
  9. 2012-02-26 14:26:56,685 - INFO - WordPress version: 3.0.1
  10. 2012-02-26 14:26:57,570 - INFO - WordPress path in server: /var/www/wordpress/
  11. 2012-02-26 14:27:08,624 - INFO - Plugin 'akismet' was found
  12. 2012-02-26 14:27:10,292 - INFO - Plugin 'akismet' version: 2.5.5 (more info @ http://localhost/wordpress/wp-content/plugins/akismet/readme.txt)
  13. 221 tasks left / 2.1 tasks per second / 1.76min left
  14. 199 tasks left / 2.2 tasks per second / 1.51min left
  15. 172 tasks left / 2.7 tasks per second / 1.06min left
  16. 21 tasks left / 1.6 tasks per second / 0.22min left
  17. 2012-02-26 14:57:23,245 - INFO - Password 'qawsed' found for username 'admin' on http://localhost/wordpress/wp-login.php
复制代码

用户名枚举
  1. $ ./wpbf.py -eu [url]http://www.mysite.com/blog/[/url]
复制代码

下载地址
https://github.com/atarantini/wpbf
过段时间可能会取消签到功能了
您需要登录后才可以回帖 登录 | Join BUC

本版积分规则

Powered by Discuz!

© 2012-2015 Baiker Union of China.

快速回复 返回顶部 返回列表