Re: Introducing WPScan - WordPress Security Scanner
"Chris Weber" <[email protected]>
| Newsgroups | gmane.comp.security.websecurity,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <[email protected]> |
dd, have you open sourced any parts of your production code, such as the fingerprinting data? Or do we each need to do that work independently? And have you detected any edge cases - for example a Web server that includes an extra newline character in the body? -Chris -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of [email protected] Sent: Monday, June 20, 2011 9:58 AM To: Chris Weber Cc: seth; [email protected]; [email protected]; [email protected] Subject: Re: [WEB SECURITY] Introducing WPScan - WordPress Security Scanner Comparing the hashes of some js/css file is probably the most reliable method, since lots of sites hide their version from the generator and remove the readme file. We wrote an article about it a while ago: http://tools.sucuri.net/?page=docs&title=fingerprinting-web-apps And we still use that on our scanner ( http://sitecheck.sucuri.net ) :) Thanks, _______________________________________________ The Web Security Mailing List WebSecurity RSS Feed http://www.webappsec.org/rss/websecurity.rss Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA WASC on Twitter http://twitter.com/wascupdates [email protected] http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org