Re: Introducing WPScan - WordPress Security Scanner
| Newsgroups | gmane.comp.security.websecurity,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <[email protected]> |
Comparing the hashes of some js/css file is probably the most reliable method, since lots of sites hide their version from the generator and remove the readme file. We wrote an article about it a while ago: http://tools.sucuri.net/?page=docs&title=fingerprinting-web-apps And we still use that on our scanner ( http://sitecheck.sucuri.net ) :) Thanks, On Mon, Jun 20, 2011 at 1:49 PM, Chris Weber <[email protected]> wrote: > Ryan - I'm I correct that the two methods you use for identifying the WP > version are: > > a) Parse the readme.html file for the version number > b) Parse the meta tag generator content for the WP version number > > In the case where both of these failed, what do you do? Does Seth's plan of > comparing hashes of the js/css/other files sound like it would work? > > -Chris > > > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of seth > Sent: Sunday, June 19, 2011 12:14 AM > To: [email protected] > Cc: [email protected]; [email protected] > Subject: Re: [WEB SECURITY] Introducing WPScan - WordPress Security Scanner > > I have started a wp scanner but lost the files before finishing and never > started again. It had three ways of identifying the version: > Generator meta tag > Readme file (you already download it, and the only valuable information i > see is the version number. Why not showing it?) Downloading some javascript, > css, images, etc. Then comparing the hashes of these files against an array > that was like [file][hash]=>version Hope it's usefull > > > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > [email protected] > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org > _______________________________________________ The Web Security Mailing List WebSecurity RSS Feed http://www.webappsec.org/rss/websecurity.rss Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA WASC on Twitter http://twitter.com/wascupdates [email protected] http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org