wpscan
Differences
This shows you the differences between two versions of the page.
Next revision | Previous revision | ||
wpscan [2019/09/02 06:29] – created hacktheplanet | wpscan [2025/03/18 18:25] (current) – hacktheplanet | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | =====Man File===== | + | =====Help File===== |
< | < | ||
root@kali: | root@kali: | ||
Line 114: | Line 114: | ||
See README for further information. | See README for further information. | ||
</ | </ | ||
+ | |||
+ | |||
+ | =====Man File===== | ||
+ | < | ||
+ | WPSCAN(1) | ||
+ | |||
+ | NAME | ||
+ | | ||
+ | |||
+ | SYNOPSIS | ||
+ | | ||
+ | |||
+ | DESCRIPTION | ||
+ | | ||
+ | |||
+ | Sponsored by Sucuri - https:// | ||
+ | |||
+ | @_WPScan_, @ethicalhack3r, | ||
+ | |||
+ | OPTIONS | ||
+ | --url URL | ||
+ | The URL of the blog to scan Allowed Protocols: http, https Default Pro‐ | ||
+ | tocol if none provided: http This option is mandatory unless update | ||
+ | help or hh or version is/are supplied | ||
+ | |||
+ | -h, --help | ||
+ | Display the simple help and exit | ||
+ | |||
+ | | ||
+ | |||
+ | | ||
+ | Display the version and exit | ||
+ | |||
+ | -v, --verbose | ||
+ | Verbose mode | ||
+ | |||
+ | | ||
+ | Whether or not to display the banner Default: true | ||
+ | |||
+ | -o, --output FILE | ||
+ | Output to FILE | ||
+ | |||
+ | -f, --format FORMAT | ||
+ | Output results in the format supplied Available choices: cli-no-colour, | ||
+ | cli-no-color, | ||
+ | |||
+ | | ||
+ | Default: mixed Available choices: mixed, passive, aggressive | ||
+ | |||
+ | | ||
+ | |||
+ | | ||
+ | Use a random user-agent for each scan | ||
+ | |||
+ | | ||
+ | |||
+ | -t, --max-threads VALUE | ||
+ | The max threads to use Default: 5 | ||
+ | |||
+ | | ||
+ | Milliseconds to wait before doing another web request. If used, the max | ||
+ | threads will be set to 1. | ||
+ | |||
+ | | ||
+ | The request timeout in seconds Default: 60 | ||
+ | |||
+ | | ||
+ | The connection timeout in seconds Default: 30 | ||
+ | |||
+ | | ||
+ | Disables SSL/TLS certificate verification | ||
+ | |||
+ | | ||
+ | Supported protocols depend on the cURL installed | ||
+ | |||
+ | | ||
+ | |||
+ | | ||
+ | Cookie | ||
+ | cookie2=value2] | ||
+ | |||
+ | | ||
+ | File to read and write cookies Default: / | ||
+ | |||
+ | | ||
+ | Do not check if the target is running WordPress | ||
+ | |||
+ | | ||
+ | Whether or not to update the Database | ||
+ | |||
+ | | ||
+ | |||
+ | | ||
+ | |||
+ | -e, --enumerate [OPTS] | ||
+ | Enumeration Process Available Choices: | ||
+ | |||
+ | vp Vulnerable plugins | ||
+ | |||
+ | ap All plugins | ||
+ | |||
+ | p Plugins | ||
+ | |||
+ | vt Vulnerable themes | ||
+ | |||
+ | at All themes | ||
+ | |||
+ | t Themes | ||
+ | |||
+ | tt Timthumbs | ||
+ | |||
+ | cb Config backups | ||
+ | |||
+ | dbe Db exports | ||
+ | |||
+ | u User IDs range. e.g: u1-5 Range separator to use: ' | ||
+ | gument supplied: 1-10 | ||
+ | |||
+ | m Media IDs range. | ||
+ | " | ||
+ | no argument supplied: 1-100 | ||
+ | |||
+ | Separator | ||
+ | Backups Value if no argument supplied: vp, | ||
+ | choices (only one of each group/s can be used): | ||
+ | |||
+ | - vp, ap, p - vt, at, t | ||
+ | |||
+ | | ||
+ | Exclude | ||
+ | parts of the enumeration. | ||
+ | exp delimiters are not required. | ||
+ | |||
+ | | ||
+ | Use the supplied | ||
+ | (--detection-mode) mode. Default: passive | ||
+ | passive, aggressive | ||
+ | |||
+ | | ||
+ | Use the supplied mode to check plugins versions instead of the --detec‐ | ||
+ | tion-mode | ||
+ | choices: mixed, passive, aggressive | ||
+ | |||
+ | -P, --passwords FILE-PATH | ||
+ | List of passwords | ||
+ | name/s option supplied, user enumeration will be run. | ||
+ | |||
+ | -U, --usernames LIST | ||
+ | List of usernames to use during the password attack. | ||
+ | ' | ||
+ | |||
+ | | ||
+ | Maximum | ||
+ | Default: 500 | ||
+ | |||
+ | | ||
+ | Force the supplied attack to be used rather than automatically | ||
+ | mining one. Available choices: wp-login, xmlrpc, xmlrpc-multicall | ||
+ | |||
+ | | ||
+ | Alias for --random-user-agent --detection-mode passive --plugins-ver‐ | ||
+ | sion-detection passive | ||
+ | |||
+ | To see full list of options use --hh. | ||
+ | |||
+ | wpscan | ||
+ | </ | ||
+ | |||
+ |
wpscan.1567405798.txt.gz · Last modified: 2024/09/04 18:20 (external edit)