搜索
查看: 4770|回复: 0

wordpress渗透测试系列(一)

[复制链接]

330

主题

177

回帖

1071

积分

vip用户

积分
1071

注册会员活跃会员热心会员

QQ
发表于 2018-4-26 19:37:38 | 显示全部楼层 |阅读模式
初步的信息收集
命令:
  1. wpscan --url http://192.168.3.234:8081
复制代码
渗透结果
  1. [+] robots.txt available under: 'http://192.168.3.234:8081/robots.txt'
  2. [!] The WordPress 'http://192.168.3.234:8081/readme.html' file exists exposing a version number
  3. [!] Full Path Disclosure (FPD) in 'http://192.168.3.234:8081/wp-includes/rss-functions.php':
  4. [+] Interesting header: LINK: <http://127.0.0.1:8081/index.php/wp-json/>; rel="https://api.w.org/"
  5. [+] Interesting header: SERVER: Apache/2.4.18 (Win32) OpenSSL/1.0.2e PHP/5.5.30
  6. [+] Interesting header: X-POWERED-BY: PHP/5.5.30
  7. [+] XML-RPC Interface available under: http://192.168.3.234:8081/xmlrpc.php

  8. [+] WordPress version 4.9.5

  9. [+] WordPress theme in use: twentyseventeen - v1.5

  10. [+] Name: twentyseventeen - v1.5
  11. |  Latest version: 1.3 (up to date)
  12. |  Last updated: 2017-06-08T00:00:00.000Z
  13. |  Location: http://192.168.3.234:8081/wp-content/themes/twentyseventeen/
  14. |  Readme: http://192.168.3.234:8081/wp-content/themes/twentyseventeen/readme.txt
  15. |  Style URL: http://192.168.3.234:8081/wp-content/themes/twentyseventeen/style.css
  16. |  Referenced style.css: http://127.0.0.1:8081/wp-content/themes/twentyseventeen/style.css
  17. |  Theme Name: Twenty Seventeen
  18. |  Theme URI: https://wordpress.org/themes/twentyseventeen/
  19. |  Description: Twenty Seventeen brings your site to life with header video and immersive featured images. With a...
  20. |  Author: the WordPress team
  21. |  Author URI: https://wordpress.org/

  22. [+] Enumerating plugins from passive detection ...
  23. [+] No plugins found

  24. [+] Finished: Thu Apr 26 19:33:00 2018
  25. [+] Requests Done: 68
  26. [+] Memory used: 16.43 MB
  27. [+] Elapsed time: 00:00:37
复制代码


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?注册

×
有没有参加CTF比赛的,一起组队啊!
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

快速回复 返回顶部 返回列表