1.安装svn
sudo apt-get install subversion
2.通过svn安装wpscan
svn checkout http://wpscan.googlecode.com/svn/trunk/ ./wpscan
3.安装依赖包
cd wpscancat README
(根据提示安装,不同平台的安装是不同的。我这里是安装ubuntu的)
sudo apt-get install libcurl4-gnutls-dev libopenssl-rubysudo gem install typhoeus xml-simple
提示:sudo: gem: command not found
解决:
sudo apt-get install rubygems
sudo gem install typhoeus xml-simple
示例:
Do ‘non-intrusive’ checks…
ruby ./wpscan.rb –url www.example.com
Do wordlist password brute force on enumerated users using 50 threads…
ruby ./wpscan.rb –url www.example.com –wordlist darkc0de.lst –threads 50
Do wordlist password brute force on the ‘admin’ username only…
ruby ./wpscan.rb –url www.example.com –wordlist darkc0de.lst –username admin
Generate a new ‘most popular’ plugin list, up to 150 pages…
ruby ./wpscan.rb –generate_plugin_list 150
Enumerate instaled plugins…
ruby ./wpscan.rb –url www.example.com –enumerate p
截图: