wpscan
Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| wpscan [2019/09/02 06:29] – created hacktheplanet | wpscan [2025/12/02 07:23] (current) – external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | =====Man File===== | + | =====Help File===== |
| < | < | ||
| root@kali: | root@kali: | ||
| Line 114: | Line 114: | ||
| See README for further information. | See README for further information. | ||
| </ | </ | ||
| + | |||
| + | |||
| + | =====Man File===== | ||
| + | < | ||
| + | WPSCAN(1) | ||
| + | |||
| + | NAME | ||
| + | | ||
| + | |||
| + | SYNOPSIS | ||
| + | | ||
| + | |||
| + | DESCRIPTION | ||
| + | | ||
| + | |||
| + | Sponsored by Sucuri - https:// | ||
| + | |||
| + | @_WPScan_, @ethicalhack3r, | ||
| + | |||
| + | OPTIONS | ||
| + | --url URL | ||
| + | The URL of the blog to scan Allowed Protocols: http, https Default Pro‐ | ||
| + | tocol if none provided: http This option is mandatory unless update | ||
| + | help or hh or version is/are supplied | ||
| + | |||
| + | -h, --help | ||
| + | Display the simple help and exit | ||
| + | |||
| + | | ||
| + | |||
| + | | ||
| + | Display the version and exit | ||
| + | |||
| + | -v, --verbose | ||
| + | Verbose mode | ||
| + | |||
| + | | ||
| + | Whether or not to display the banner Default: true | ||
| + | |||
| + | -o, --output FILE | ||
| + | Output to FILE | ||
| + | |||
| + | -f, --format FORMAT | ||
| + | Output results in the format supplied Available choices: cli-no-colour, | ||
| + | cli-no-color, | ||
| + | |||
| + | | ||
| + | Default: mixed Available choices: mixed, passive, aggressive | ||
| + | |||
| + | | ||
| + | |||
| + | | ||
| + | Use a random user-agent for each scan | ||
| + | |||
| + | | ||
| + | |||
| + | -t, --max-threads VALUE | ||
| + | The max threads to use Default: 5 | ||
| + | |||
| + | | ||
| + | Milliseconds to wait before doing another web request. If used, the max | ||
| + | threads will be set to 1. | ||
| + | |||
| + | | ||
| + | The request timeout in seconds Default: 60 | ||
| + | |||
| + | | ||
| + | The connection timeout in seconds Default: 30 | ||
| + | |||
| + | | ||
| + | Disables SSL/TLS certificate verification | ||
| + | |||
| + | | ||
| + | Supported protocols depend on the cURL installed | ||
| + | |||
| + | | ||
| + | |||
| + | | ||
| + | Cookie | ||
| + | cookie2=value2] | ||
| + | |||
| + | | ||
| + | File to read and write cookies Default: / | ||
| + | |||
| + | | ||
| + | Do not check if the target is running WordPress | ||
| + | |||
| + | | ||
| + | Whether or not to update the Database | ||
| + | |||
| + | | ||
| + | |||
| + | | ||
| + | |||
| + | -e, --enumerate [OPTS] | ||
| + | Enumeration Process Available Choices: | ||
| + | |||
| + | vp Vulnerable plugins | ||
| + | |||
| + | ap All plugins | ||
| + | |||
| + | p Plugins | ||
| + | |||
| + | vt Vulnerable themes | ||
| + | |||
| + | at All themes | ||
| + | |||
| + | t Themes | ||
| + | |||
| + | tt Timthumbs | ||
| + | |||
| + | cb Config backups | ||
| + | |||
| + | dbe Db exports | ||
| + | |||
| + | u User IDs range. e.g: u1-5 Range separator to use: ' | ||
| + | gument supplied: 1-10 | ||
| + | |||
| + | m Media IDs range. | ||
| + | " | ||
| + | no argument supplied: 1-100 | ||
| + | |||
| + | Separator | ||
| + | Backups Value if no argument supplied: vp, | ||
| + | choices (only one of each group/s can be used): | ||
| + | |||
| + | - vp, ap, p - vt, at, t | ||
| + | |||
| + | | ||
| + | Exclude | ||
| + | parts of the enumeration. | ||
| + | exp delimiters are not required. | ||
| + | |||
| + | | ||
| + | Use the supplied | ||
| + | (--detection-mode) mode. Default: passive | ||
| + | passive, aggressive | ||
| + | |||
| + | | ||
| + | Use the supplied mode to check plugins versions instead of the --detec‐ | ||
| + | tion-mode | ||
| + | choices: mixed, passive, aggressive | ||
| + | |||
| + | -P, --passwords FILE-PATH | ||
| + | List of passwords | ||
| + | name/s option supplied, user enumeration will be run. | ||
| + | |||
| + | -U, --usernames LIST | ||
| + | List of usernames to use during the password attack. | ||
| + | ' | ||
| + | |||
| + | | ||
| + | Maximum | ||
| + | Default: 500 | ||
| + | |||
| + | | ||
| + | Force the supplied attack to be used rather than automatically | ||
| + | mining one. Available choices: wp-login, xmlrpc, xmlrpc-multicall | ||
| + | |||
| + | | ||
| + | Alias for --random-user-agent --detection-mode passive --plugins-ver‐ | ||
| + | sion-detection passive | ||
| + | |||
| + | To see full list of options use --hh. | ||
| + | |||
| + | wpscan | ||
| + | </ | ||
| + | |||
| + | |||
wpscan.1567405798.txt.gz · Last modified: (external edit)
