Re: Introducing WPScan - WordPress Security Scanner

[email protected]
Newsgroups gmane.comp.security.websecurity,gmane.comp.security.web-applications
Message-ID <[email protected]>
Comparing the hashes of some js/css file is probably the most reliable
method, since lots of sites
hide their version from the generator and remove the readme file.

We wrote an article about it a while ago:
http://tools.sucuri.net/?page=docs&title=fingerprinting-web-apps

And we still use that on our scanner ( http://sitecheck.sucuri.net ) :)

Thanks,

On Mon, Jun 20, 2011 at 1:49 PM, Chris Weber <[email protected]> wrote:
> Ryan - I'm I correct that the two methods you use for identifying the WP
> version are:
>
> a) Parse the readme.html file for the version number
> b) Parse the meta tag generator content for the WP version number
>
> In the case where both of these failed, what do you do?  Does Seth's plan of
> comparing hashes of the js/css/other files sound like it would work?
>
> -Chris
>
>
> -----Original Message-----
> From: [email protected]
> [mailto:[email protected]] On Behalf Of seth
> Sent: Sunday, June 19, 2011 12:14 AM
> To: [email protected]
> Cc: [email protected]; [email protected]
> Subject: Re: [WEB SECURITY] Introducing WPScan - WordPress Security Scanner
>
> I have started a wp scanner but lost the files before finishing and never
> started again. It had three ways of identifying the version:
> Generator meta tag
> Readme file (you already download it, and the only valuable information i
> see is the version number. Why not showing it?) Downloading some javascript,
> css, images, etc. Then comparing the hashes of these files against an array
> that was like [file][hash]=>version Hope it's usefull
>
>
>
> _______________________________________________
> The Web Security Mailing List
>
> WebSecurity RSS Feed
> http://www.webappsec.org/rss/websecurity.rss
>
> Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA
>
> WASC on Twitter
> http://twitter.com/wascupdates
>
> [email protected]
> http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org
>

_______________________________________________
The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

[email protected]
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.