WP-ATTACKER v.4

What's new ?

  1. Grab all wordpress websites on the server via Bing API
  2. Scan all the possible plugins/themes on each website from a list (provided by the user)
  3. Brute Force using the correct username and a passwords list via xmlrpc.php *NEW*
  4. Brute Force using the correct username and a passwords list via wp-login.php *MODIFIED*
  5. Scan all the possible plugins/themes on each website from security databases *MODIFIED*
  6. Change the appearance of the tool 


Plugins/themes List format:
Code:
XP:wp-content/plugins/XP/lib/exploit.php:Group-XP

XP = plugin/theme 's name

wp-content/plugins/XP/lib/exploit.php = plugin/theme 's path

Group-XP = Keyword (clue to double check if its there!)

NOTE: Keyword value is optional in this version Cool

the Tool uses two methods to check plugins and/or themes, which are:
  • Keyword.
  • Headers Respond.

Passwords list:

Code:
123456
password
admin
whateva


--------------

What's new ?

Brute Force using two methods:
  1. The usual way : wp-login.php
  2. The new way : xmlrpc.php


Checking plugins and/or themes using two methods:

  1. Keyword (provided by the user).
  2. Headers.


Any list could be used with a simple modification as an example:
HERE !


Pictures for Brute Forcing (Success!):
  • XMLRPC

  • WP-LOGIN


Disclaimer:
  • THIS TOOL WAS WRITTEN FOR EDUCATIONAL PURPOSES. ONLY USE THIS TOOL ON WEBSITES YOU ARE ALLOWED TO TEST
  • THE AUTHOR CANNOT AND WILL NOT IN ANY WAY LIABLE FOR ANY LOSS OR DAMAGE ARISING WITH THE USE OF THIS TOOL.
  • USE IT UNDER YOUR OWN RISK!
  • IF YOU DON'T AGREE WITH WHAT I SAID, PLEASE DON'T USE THIS TOOL.


Before downloading you must have a BING API Hash : HERE


Download from here: WP-ATTCKER


Any problem you could use this thread or GitHub 


Đăng nhận xét Blogger

 
Top