WPScan 1.1

      WPScan是一款使用ruby编写、基于白盒测试的WordPress安全扫描器,它会尝试查找WordPress安装版的一些已知的安全弱点。WPScan可以辅助专业安全人员或是WordPress管理员评估他们的WordPress安装版的安全状况。

WPScan更新至1.1版,新版主要改变:
Changelog v1.1
    * Detection for 750 more plugins.
    * Detection for 107 new plugin vulnerabilities.
    * Detection for 447 possible timthumb file locations.
    * Advanced version fingerprinting implemented.
    * Full Path Disclosure (FPD) checks.
    * Auto updates.
    * Progress indicators.
    * Improved custom 404 checking.
    * Improved plugin detection.
    * Improved error_log checking.
    * Lots of bugs fixed.
    * Lots of small tweaks.

Principal Features
    * Username enumeration (from author querystring and location header)
    * Weak password cracking (multithreaded)
    * Version enumeration (from generator meta tag and from client side files)
    * Vulnerability enumeration (based on version)
    * Plugin enumeration (2220 most popular by default)
    * Plugin vulnerability enumeration (based on plugin name)
    * Plugin enumeration list generation
    * Other misc WordPress checks (theme name, dir listing, …)


工具下载:http://code.google.com/p/wpscan

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值