{"id":1954,"date":"2013-05-03T14:32:06","date_gmt":"2013-05-03T06:32:06","guid":{"rendered":"https:\/\/sdeno.com\/?p=1954"},"modified":"2013-05-03T14:32:06","modified_gmt":"2013-05-03T06:32:06","slug":"wordpress%e5%85%a5%e4%be%b5%e5%88%a9%e7%94%a8%e5%b7%a5%e5%85%b7","status":"publish","type":"post","link":"https:\/\/sdeno.com\/?p=1954","title":{"rendered":"wordpress\u5165\u4fb5\u5229\u7528\u5de5\u5177"},"content":{"rendered":"<p>wordpress\u7a0b\u5e8f\u5728\u5168\u7403\u4f7f\u7528\u7387\u5f88\u9ad8\u81ea\u7136\u5c11\u4e0d\u4e86\u9ed1\u5ba2\u4eec\u5165\u4fb5\u7684\u76ee\u6807\uff0c\u4e5f\u968f\u4e4b\u51fa\u73b0\u9488\u5bf9\u5165\u4fb5wordpress\u7684\u5229\u7528\u5de5\u5177\u3002<br \/>\n\u8fd9\u91cc\u4ecb\u7ecd\u4e00\u4e2a\u4e13\u95e8\u68c0\u6d4bwordpress\u6f0f\u6d1e\u7684\u5229\u7528\u5de5\u5177wpscan\u3002<br \/>\n\u4ee5\u4e0b\u662f\u4f7f\u7528\u7684\u6570\u636e\u8bb0\u5f55\uff1a<br \/>\n\u7ecf\u9a8c\u5fc3\u5f97\u5982\u4e0b\uff01<br \/>\n\u8fd9\u4e2a\u5de5\u5177\u65e0\u6cd5\u76f4\u63a5\u7528\u547d\u4ee4\uff0c\u9700\u8981\u8fdb\u5165\u5230usr\/bin\u6587\u4ef6\u5939\u4e2d\u8fd0\u884c\uff01<br \/>\n\u7b2c\u4e00\u6b65\uff0c\u6253\u5f00\u7ec8\u7aef<br \/>\n\u8f93\u5165cd \/usr\/bin<br \/>\n\u7b2c\u4e8c\u6b65\uff0c\u8fd0\u884cwpscan<br \/>\n\u5728usr\/bin \u7ec8\u7aef\u4e2d\u8f93\u5165\u547d\u4ee4\u3002 wpscan -h<br \/>\nHelp :<br \/>\nSome values are settable in conf\/browser.conf.json :<br \/>\nuser-agent, proxy, proxy-auth, threads, cache timeout and request timeout<br \/>\n\u2013update   Update to the latest revision<br \/>\n\u2013url   | -u <target url>  The WordPress URL\/domain to scan.<br \/>\n\u2013force | -f Forces WPScan to not check if the remote site is running WordPress.<br \/>\n\u2013enumerate | -e [option(s)]  Enumeration.<br \/>\noption :<br \/>\nu        usernames from id 1 to 10<br \/>\nu[10-20] usernames from id 10 to 20 (you must write [] chars)<br \/>\np        plugins<br \/>\nvp       only vulnerable plugins<br \/>\nap       all plugins (can take a long time)<br \/>\ntt       timthumbs<br \/>\nt        themes<br \/>\nvt       only vulnerable themes<br \/>\nat       all themes (can take a long time)<br \/>\nMultiple values are allowed : \u2018-e t,p\u2019 will enumerate timthumbs and plugins<br \/>\nIf no option is supplied, the default is \u2018vt,tt,u,vp\u2019<br \/>\n\u2013exclude-content-based \u2018<regexp or string>\u2019 Used with the enumeration option, will exclude all occurence based on the regexp or string supplied<br \/>\nYou do not need to provide the regexp delimiters, but you must write the quotes (simple or double)<br \/>\n\u2013config-file | -c <config file> Use the specified config file<br \/>\n\u2013follow-redirection  If the target url has a redirection, it will be followed without asking if you wanted to do so or not<br \/>\n\u2013wp-content-dir <wp content dir>  WPScan try to find the content directory (ie wp-content) by scanning the index page, however you can specified it. Subdirectories are allowed<br \/>\n\u2013wp-plugins-dir <wp plugins dir>  Same thing than \u2013wp-content-dir but for the plugins directory. If not supplied, WPScan will use wp-content-dir\/plugins. Subdirectories are allowed<br \/>\n\u2013proxy <[protocol:\/\/]host:port> Supply a proxy (will override the one from conf\/browser.conf.json).<br \/>\nHTTP, SOCKS4 SOCKS4A and SOCKS5 are supported. If no protocol is given (format host:port), HTTP will be used<br \/>\n\u2013proxy-auth <username:password>  Supply the proxy login credentials (will override the one from conf\/browser.conf.json).<br \/>\n\u2013basic-auth <username:password>  Set the HTTP Basic authentification<br \/>\n\u2013wordlist | -w <wordlist>  Supply a wordlist for the password bruter and do the brute.<br \/>\n\u2013threads  | -t <number of threads>  The number of threads to use when multi-threading requests. (will override the value from conf\/browser.conf.json)<br \/>\n\u2013username | -U <username>  Only brute force the supplied username.<br \/>\n\u2013help     | -h This help screen.<br \/>\n\u2013verbose  | -v Verbose output.<br \/>\nExamples :<br \/>\n-Further help \u2026<br \/>\nruby \/usr\/bin\/wpscan \u2013help<br \/>\n-Do \u2018non-intrusive\u2019 checks \u2026<br \/>\nruby \/usr\/bin\/wpscan \u2013url www.example.com<br \/>\n-Do wordlist password brute force on enumerated users using 50 threads \u2026<br \/>\nruby \/usr\/bin\/wpscan \u2013url www.example.com \u2013wordlist darkc0de.lst \u2013threads 50<br \/>\n-Do wordlist password brute force on the \u2018admin\u2019 username only \u2026<br \/>\nruby \/usr\/bin\/wpscan \u2013url www.example.com \u2013wordlist darkc0de.lst \u2013username admin<br \/>\n-Enumerate installed plugins \u2026<br \/>\nruby \/usr\/bin\/wpscan \u2013url www.example.com \u2013enumerate p<br \/>\n-Enumerate installed themes \u2026<br \/>\nruby \/usr\/bin\/wpscan \u2013url www.example.com \u2013enumerate t<br \/>\n-Enumerate users \u2026<br \/>\nruby \/usr\/bin\/wpscan \u2013url www.example.com \u2013enumerate u<br \/>\n-Enumerate installed timthumbs \u2026<br \/>\nruby \/usr\/bin\/wpscan \u2013url www.example.com \u2013enumerate tt<br \/>\n-Use a HTTP proxy \u2026<br \/>\nruby \/usr\/bin\/wpscan \u2013url www.example.com \u2013proxy 127.0.0.1:8118<br \/>\n-Use a SOCKS5 proxy \u2026 (cURL >= v7.21.7 needed)<br \/>\nruby \/usr\/bin\/wpscan \u2013url www.example.com \u2013proxy socks5:\/\/127.0.0.1:9000<br \/>\n-Use custom content directory \u2026<br \/>\nruby \/usr\/bin\/wpscan -u www.example.com \u2013wp-content-dir custom-content<br \/>\n-Use custom plugins directory \u2026<br \/>\nruby \/usr\/bin\/wpscan -u www.example.com \u2013wp-plugins-dir wp-content\/custom-plugins<br \/>\n-Update \u2026<br \/>\nruby \/usr\/bin\/wpscan \u2013update<br \/>\nSee README for further information.<br \/>\n\u9009\u9879\u8fc7\u591a\uff0c\u4e0d\u4e00\u4e00\u89e3\u91ca\u3002 \u6311\u9009\u51e0\u4e2a\u5e38\u7528\u7684\u547d\u4ee4<br \/>\nwpscan \u2013url http:\/\/testurl\/   \u68c0\u6d4b\u5e38\u7528\u63d2\u4ef6<br \/>\nwpscan \u2013url http:\/\/testurl\/ -e \u5168\u9762\u68c0\u6d4b<br \/>\nwpscan \u2013url http:\/\/testurl\/ -e u \u68c0\u6d4b\u7528\u6237<br \/>\nwpscan \u2013url http:\/\/testurl\/ \u2013wordlist \u5b57\u5178\uff08\u5982\u679c\u4e0b\u8f7d\u5230\u684c\u9762\uff0c\u5219\u662f\/root\/Desktop\/\u5b57\u5178.txt\uff09 \u2013username admin (\u8fd9\u91cc\u586b\u5199\u4e4b\u95f4\u68c0\u6d4b\u5230\u7684\u7528\u6237\uff09  \u66b4\u529bPJ\u5bc6\u7801\uff01<br \/>\n\u5168\u9762\u68c0\u6d4b\u4e2d\u4f1a\u68c0\u6d4b\u5230\u4e00\u4e9bXSS\u6216\u8005SQL\u6ce8\u5c04\u7c7b\u7684\u6f0f\u6d1e\uff0c\u4f1a\u7528\u7ea2\u8272\u7684\u5b57\u4f53\u663e\u793a\uff0c\u5e76\u6709\u6f0f\u6d1e\u8be6\u7ec6\u4fe1\u606f\u7684\u94fe\u63a5\uff01<br \/>\n\u5176\u4ed6\u7684\u529f\u80fd\u5927\u5bb6\u6162\u6162\u53d1\u89c9\uff01 \u641ewordpress \u975e\u5e38\u6709\u7528\u7684\u5de5\u5177\uff01<\/p>\n","protected":false},"excerpt":{"rendered":"<p>wordpress\u7a0b\u5e8f\u5728\u5168\u7403\u4f7f\u7528\u7387\u5f88\u9ad8\u81ea\u7136\u5c11\u4e0d\u4e86\u9ed1\u5ba2\u4eec\u5165\u4fb5\u7684\u76ee\u6807\uff0c\u4e5f\u968f\u4e4b\u51fa\u73b0\u9488\u5bf9\u5165\u4fb5wordpress\u7684\u5229\u7528\u5de5 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"close","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-1954","post","type-post","status-publish","format-standard","hentry","category-9"],"_links":{"self":[{"href":"https:\/\/sdeno.com\/index.php?rest_route=\/wp\/v2\/posts\/1954","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sdeno.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sdeno.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sdeno.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sdeno.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1954"}],"version-history":[{"count":0,"href":"https:\/\/sdeno.com\/index.php?rest_route=\/wp\/v2\/posts\/1954\/revisions"}],"wp:attachment":[{"href":"https:\/\/sdeno.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1954"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sdeno.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1954"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sdeno.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1954"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}