WPscan – Discovering the Vulnerabilities and Enumerating Users of WordPress Sites with Autotor for IP Spoofing
Keywords:
WPscan, WordPress,, vulnerability, AutoTor, IP Spoofing.Abstract
WPscan is an open source WordPress security
scanner. You can use it to scan your WordPress website for
known vulnerabilities in popular WordPress plugins and
themes. Since it is a black box scanner, it almost copies an
action of a real attacker. This means that for conducting the
tests, it does not depend on any access to your WordPress
dashboard or source code. To put it another way, if WPscan
can find a flaw in your WordPress website, an attacker can
too. An attacker trying to either guess or confirm that
something they are targeting exists on the target system is
commonly termed as Enumeration.
Some of the most commonly enumeration scans that WPscan
does during a scan are:
Detection of versions of WordPress core, plugins and
themes,
Looks for wp-config.php backups or other database
exports that are open to the public.
Counting the number of users and administrators