WordPress Vulnerability Scanning With WPScan

Поділитися
Вставка
  • Опубліковано 22 гру 2024

КОМЕНТАРІ • 210

  • @usamaraees9979
    @usamaraees9979 2 роки тому +13

    For those people who are watching this video right now ... to type in the url the command is not -u now its -url so you will have to type in that when putting in the address

    • @NemoBlu
      @NemoBlu 6 місяців тому

      --url -e u vp --force -

  • @mzonerz
    @mzonerz 6 років тому +35

    The --wordlist was in the v2, use the --passwords option in the v3:

    • @b07x
      @b07x 3 роки тому +1

      wpscan --url example.com --username admin --password passwd.txt

    • @b07x
      @b07x 3 роки тому

      Idk if it works or not
      I didnt try

    • @pepejulianonziema1475
      @pepejulianonziema1475 3 роки тому

      @@b07x have you tried it yet?
      If not i will test it

    • @8080VB
      @8080VB 3 роки тому

      @@b07x no , its like this
      wpscan --url *********** --enumerate u -P //path.txt. . . . .

  • @alisawari0
    @alisawari0 6 років тому +4

    it has the most of the famous website's passwords like yahoo gmail
    6:58 wordlist.txt selected, 75 bytes

  • @hectorgarc3963
    @hectorgarc3963 6 років тому +7

    Very good video. Good video showing instructions and giving tips on working and practice pen-testing in your own lab.

    • @HackerSploit
      @HackerSploit  6 років тому +1

      +Hector Garcia Jr Thanks for the feedback and support

  • @supriyoguha9314
    @supriyoguha9314 3 роки тому +6

    Sir, share ur wordlist

  • @Dn0de
    @Dn0de Рік тому

    I'm wondering what was the relevance of the "File Manager" plugin?

  • @asklepoisaliasmirco9155
    @asklepoisaliasmirco9155 3 роки тому +1

    sorry, but my kali linux does not working, do you have any idea why it doesn't works well ?

  • @vineetpandey743
    @vineetpandey743 7 років тому +4

    As always you did it very well, thanks man

  • @atheena6804
    @atheena6804 7 років тому +5

    that's awesome keep up loading cool stuff like this

  • @Javedboqo1
    @Javedboqo1 3 роки тому

    does wpscan package is free to use for commercial ?@HackerSploit

  • @venkateshd6572
    @venkateshd6572 3 роки тому

    That ip that ur giving is ur virtual machine turnkey linux ip right

  • @merajrabbani
    @merajrabbani 3 роки тому

    would you mind sharing the wordlist used in this video for bruteforcing passwords

  • @webdev8042
    @webdev8042 5 років тому +3

    Thanks for your posting this video. But could you show me where can I get wordlist.text file?
    it doesn't work and I can get wordlist file.
    Thank you

    • @webdev8042
      @webdev8042 5 років тому

      @@jaxon496 I tried for long times, but couldn't find.

    • @ashleybishton742
      @ashleybishton742 4 роки тому

      download seclists off github then type in locate seclists then it cd into seclists passwords section then tar the file as rockyou.txt needs to be compressed as it is 14 million words long lol. but even with the wordlist if u are trying to do it with a real word press site your grand kids will 80 by the time the password is cracked they will still be sat there at 80 scratching their heads

    • @8080VB
      @8080VB 3 роки тому +1

      @@ashleybishton742 😂😂 true.

  • @aryachowkekar2769
    @aryachowkekar2769 3 місяці тому

    How Can I get this Virtual Lab ??

  • @deadpool-eh8oc
    @deadpool-eh8oc 3 роки тому

    what is the target machine is here

  • @josebernardo4699
    @josebernardo4699 6 років тому

    Where did u get the wordlist from?

  • @Radioteletelstar
    @Radioteletelstar 2 роки тому

    hi.thnx for your nvideo. where i can find the wordlist please?

  • @mmahfw
    @mmahfw 7 років тому +4

    really interesting videos thank you for all the effort you put in explaining your videos.
    And Please I would like to see more tutorials on exploiting web servers ect .
    .

    • @HackerSploit
      @HackerSploit  7 років тому +1

      Thank you for the support, I will continue making videos on web servers.

  • @richardkoiki4177
    @richardkoiki4177 2 роки тому

    How , and where do i download vulnerable Wpscan ....pls help

  • @velocity-_-9401
    @velocity-_-9401 6 років тому +4

    nicely explained as always :-)

  • @yt-dman
    @yt-dman 4 роки тому +2

    how do i find the password to content that is password protected, or can i do the same for that?

  • @williamchancey163
    @williamchancey163 5 років тому

    i am using pentestbox and keep getting error as my text isnot found where do i put the wordlist as i know it is in the directory but how do i find the directory of pentextbox

  • @tephlondandada156
    @tephlondandada156 5 років тому

    Can you use wpscan with virtual box?

  • @Gormlessostrich
    @Gormlessostrich 4 роки тому +1

    This was a fun one! Thanks!

  • @pepejulianonziema1475
    @pepejulianonziema1475 3 роки тому

    Best tutorial ever

  • @nyarkosamuel9728
    @nyarkosamuel9728 5 років тому

    How long does it take for password to finish bruteforcing?

  • @AncientAmulet
    @AncientAmulet 3 роки тому +1

    a blackhaat's first act is to make a new admin user for himself, delete the original admin so they cant recuperate per email, and relogin as the new admin. then and only then should one mess with 404 pages and small things like that. take control first before showing off. Still though, WPScan was well explained. Thanks

  • @patelsameer529
    @patelsameer529 5 років тому

    Do you know how to use kajack in kali?

  • @gigigigiotto1673
    @gigigigiotto1673 6 років тому +5

    it works only with --url example.com --enumerate u

  • @Johnello1
    @Johnello1 3 роки тому

    If I'm using Ubuntu 4.20 on my windows 10, how can I know what the path is of the file containing the passwords? can someone help me please so I know what path to use?

  • @dhaiwatmehta2323
    @dhaiwatmehta2323 7 років тому +11

    Can you share that wordlist ??

    • @nikolanojic6861
      @nikolanojic6861 5 років тому +1

      @peroh Suree like that isnt going to take 55 days to complete

    • @markusmeer7365
      @markusmeer7365 5 років тому

      It only has 12 passwords, thats the reason why its that fast

    • @nikolanojic6861
      @nikolanojic6861 5 років тому

      @peroh Like literally i puted a rockyou list and it showed that it will complete in 55days
      while doing that they would patch the brute forcing metod :/

    • @GOTHICforLIFE1
      @GOTHICforLIFE1 5 років тому

      @@nikolanojic6861 That sounds like a really slow PC :|

    • @nikolanojic6861
      @nikolanojic6861 5 років тому

      @@GOTHICforLIFE1
      FX 6300 (6 cores 4.3Ghz)
      8GB RAM
      R7 360 2GB

  • @8L4NK_
    @8L4NK_ 7 років тому +1

    Thanx for your continuous teachings. I have been able to relearn some of what I've forgot. Continue to pump out the vids. Your fans are watching and supporting.
    -Glitch00010001

  • @efecicikara8016
    @efecicikara8016 3 роки тому

    I get a dont get it "url" (403) error how ı fix it

  • @JaquetonEnigmon
    @JaquetonEnigmon Рік тому

    5:54 haha "immediately I have everything"

  • @rimengineers
    @rimengineers 6 років тому +1

    Great work !

  • @limalfred9956
    @limalfred9956 5 років тому +1

    i am totally new here. what required to do all of this, anything i need to download? im windows user. hope can help from u. and i ready to join your course after testing this. please help me. My friend.

    • @nikolanojic6861
      @nikolanojic6861 5 років тому

      lol

    • @MrLennonson
      @MrLennonson 5 років тому

      There's no real hacker in youtube. Find proper class to study about it

    • @nikolanojic6861
      @nikolanojic6861 5 років тому

      @@MrLennonson Of course there are , check "The Cyber Mentor"

  • @Me-xo8kc
    @Me-xo8kc 4 роки тому +2

    Can you give us download link for your wordlist please.

    • @sg-rf8xs
      @sg-rf8xs 3 роки тому

      yes I need the same

    • @8080VB
      @8080VB 3 роки тому

      @@sg-rf8xs got want?

    • @sg-rf8xs
      @sg-rf8xs 3 роки тому

      @@8080VB I didn't get that

  • @8080VB
    @8080VB 3 роки тому +2

    Guys in 2021 -u is changed to --url ( to specify a url address) n
    the scan should be
    wpscan --url 192.168.0.00 -e vp

    • @bulbulahmedrabbi4056
      @bulbulahmedrabbi4056 3 роки тому

      Hello Brother

    • @8080VB
      @8080VB 3 роки тому

      @@bulbulahmedrabbi4056 hi there

    • @bulbulahmedrabbi4056
      @bulbulahmedrabbi4056 3 роки тому

      @@8080VB I want to contact you personally.
      Would you give me your whatsapp number?

    • @8080VB
      @8080VB 2 роки тому

      @@bulbulahmedrabbi4056 discord?

  • @csyonslinkerhoden3134
    @csyonslinkerhoden3134 5 років тому +3

    can you give us a link to your wordlist ?

    • @8080VB
      @8080VB 3 роки тому

      @love spoofing worked for you?

    • @8080VB
      @8080VB 3 роки тому

      @love spoofing really?? You generated or using this file?

    • @8080VB
      @8080VB 3 роки тому

      @love spoofing ok lemme try

    • @8080VB
      @8080VB 3 роки тому

      @love spoofing na its not cracked. .

    • @8080VB
      @8080VB 3 роки тому

      @love spoofing hmm but not.

  • @avunit9538
    @avunit9538 7 років тому +13

    Wordlist doesn't always crack passwords. :/

    • @HackerSploit
      @HackerSploit  7 років тому +7

      Yes, but powerful ones do.

    • @avunit9538
      @avunit9538 7 років тому +2

      HackerSploit That last line of description tho 😃🇮🇳 💓 .
      Can you share any powerful one?

  • @bendover-mn3hs
    @bendover-mn3hs 5 років тому

    if your having issues because --wordlist is not a valid command try to run the following command replace yourtarget.com/ with your target url and the wordlist path on the end like so: wpscan --url --password-attack yourtarget.com/ /root/Desktop/wordlist.txt hope this helps

  • @mralasco3202
    @mralasco3202 5 років тому

    if i have 5 username and i want brute force 1 user what is the command i have try many command but always brute force all users

  • @bludauitservices2109
    @bludauitservices2109 7 років тому +1

    Nice work! Go on! :-)

  • @Mandaragat1969
    @Mandaragat1969 Рік тому

    can i get worldl;ist

  • @gadgetsreview5287
    @gadgetsreview5287 5 років тому

    Which ip entered

  • @_zerosecurity_
    @_zerosecurity_ Рік тому

    Bro love U from sudan ♥

  • @krisdouglas6536
    @krisdouglas6536 6 років тому +2

    Great informative video. Could you make a video following on from this gaining a backdoor please ?

  • @dankeyote5873
    @dankeyote5873 7 років тому +2

    can you make a video on creating a large wordlists in future?????

    • @HackerSploit
      @HackerSploit  7 років тому +4

      Yes.

    • @dankeyote5873
      @dankeyote5873 7 років тому +1

      yeah i already have that, but i want to make an word list that is alpha numeric and has 1-10 character strings,i already have tried that with crunch but every time i try that, crunch seems to show an error so i wanted to know if there is an alternative tool for this purpose

    • @payl04d23
      @payl04d23 6 років тому +1

      Use cupp. It is truly powerful, helped me crack a wifi pass. it was Uszoda2009.

    • @dankeyote5873
      @dankeyote5873 6 років тому

      oNerkzei (1v1er) thanks for respondin, actually the main problem I encounter is that when I create brute force word list the size is extremely big, so I can't really make a alpha-numeric woldlist which has more than 5 characters, so I'm looking for a more efficient way of creating compressed wordlists, and btw idk the compression options in cruch end up showing me an error

    • @payl04d23
      @payl04d23 6 років тому +1

      Inventor 707 if you want to crack passwords, use little wordlist, with a botnet. cracking from thousands of pcs is more effective than using a huge wlist

  • @SabharamM
    @SabharamM 5 років тому

    @HackerSploit Sir please let me know how to install wordpress in debian...??

  • @kurdi2959
    @kurdi2959 4 роки тому +1

    Well done

  • @zyltech4409
    @zyltech4409 4 роки тому

    Good job!

  • @lynxtouch
    @lynxtouch 6 років тому

    What would be the reason/s for wpscan not enumerating usernames?

  • @shashankranjan9564
    @shashankranjan9564 5 років тому

    Please share the wordlist

  • @alex-vq1yy
    @alex-vq1yy 3 роки тому +1

    Please Sir can you provide the password world list that u have 🙇

  • @imranthoufeeque
    @imranthoufeeque 7 років тому

    Second comment... Thank you alexis...

  • @ShahriarAIUniverse
    @ShahriarAIUniverse 3 роки тому +1

    Can you provide me a dedicated wordpress site url? , my aim is to academic purpose.

  • @XAVIERRUBILLOS
    @XAVIERRUBILLOS 4 роки тому

    what if the password is not on the wordlist?

  • @kapilgoyal7697
    @kapilgoyal7697 5 років тому

    wordlist option not found

    • @bendover-mn3hs
      @bendover-mn3hs 5 років тому

      run the following command replace yourtarget.com/ with your target url and the wordlist path on the end like so: wpscan --url --password-attack yourtarget.com/ /root/Desktop/wordlist.txt hope this helps

    • @devEns0
      @devEns0 5 років тому

      wpscan --url www.target.com/ -e u -U -P /root/Desktop/wordlist.txt

  • @sequelgrand5167
    @sequelgrand5167 3 роки тому

    very cool

  • @nmapmetasploit1972
    @nmapmetasploit1972 2 роки тому

    remember him blaming his laptop for being clumsy on the keyboard? 7 videos later, same struggle. The guy who 8 fingers but rather should use only point fingers

  • @Anonymous-jv8nt
    @Anonymous-jv8nt 7 років тому +1

    Thanks sir

  • @harshthakur7215
    @harshthakur7215 7 років тому +2

    Can you send links to get good wordlists? @hackersploit

    • @HackerSploit
      @HackerSploit  7 років тому +1

      I will make a video on wordlists

    • @bossysmaxx
      @bossysmaxx 5 років тому

      @@HackerSploit when

    • @joshdtbx
      @joshdtbx 5 років тому

      Google.com there u go

  • @schmickfurhrer8644
    @schmickfurhrer8644 7 років тому

    Thanks alot was just thinking about how to reverse shell a website.

  • @moazelsawaf2000
    @moazelsawaf2000 7 років тому

    Nice video ❤

  • @viralworld3395
    @viralworld3395 4 роки тому

    amazing

  • @code9developer284
    @code9developer284 4 роки тому

    Hai , can you guys help me hack, its for a rude client who denied me of cpanel access and wordpress website acess

  • @0xe338
    @0xe338 4 роки тому

    Wordlist??

  • @adwitiyarathore9247
    @adwitiyarathore9247 3 роки тому

    ERROR= " Scan Aborted: The remote website is up, but does not seem to be running WordPress."
    please help!!

  • @saklandking9303
    @saklandking9303 3 роки тому

    How to save the website after hacked

    • @8080VB
      @8080VB 3 роки тому +1

      Mean? Just save the username n pwd

  • @MultiWordss
    @MultiWordss 28 днів тому

    Bro how can i get someone’s wifi password? 😅 i really need it to learn about it cause i my daily data limit no sufficient for me 😢

  • @MrGFYne1337357
    @MrGFYne1337357 7 років тому

    Also i have a request. Easy but cool. Can you show us one tool piped | into another tool? peace.

  • @redrab5163
    @redrab5163 6 років тому

    hello sir,,, i want to need your wordlist download links...............please send and help us...........?

  • @shankarneela
    @shankarneela 7 років тому +4

    I need ur wordlist.txt package

  • @pratikmukherjee5914
    @pratikmukherjee5914 5 років тому

    Sir can you please share the source to download turnkey linux that you used in this video

  • @anashaouat2802
    @anashaouat2802 7 років тому

    Can you link the wordlist? Or share it with google drive or dropbox ... Great video .

    • @HackerSploit
      @HackerSploit  7 років тому

      I will make a video on wordlists

    • @sidowsidow
      @sidowsidow 7 років тому

      HackerSploit wordlist

  • @aaryan1143
    @aaryan1143 5 років тому

    I type in the command and it says:
    Detected By: Author Posts - Display Name (Passive Detection)
    | Confirmed By:
    | Rss Generator (Passive Detection)
    | Author Id Brute Forcing - Author Pattern (Aggressive Detection)
    | Login Error Messages (Aggressive Detection)
    What should I do now????????????????????????????????????

    • @Najumulsaqib
      @Najumulsaqib 5 років тому

      Yeah same issue

    • @aaryan1143
      @aaryan1143 Рік тому +1

      Lol I was literally a noob 4 years back, great to see where I've reached now!

  • @oulGamer
    @oulGamer 7 років тому +3

    Finally

  • @activetutorial
    @activetutorial 3 роки тому

    Likes and upload date is same ☺

  • @shayan4934
    @shayan4934 6 років тому

    good

  • @channeltimur4690
    @channeltimur4690 5 років тому

    Is this work on android?

  • @MrGFYne1337357
    @MrGFYne1337357 7 років тому

    All hail are hakr guru. Namaste Respect

  • @zanidd
    @zanidd 7 років тому +1

    i like your intro song

    • @pablogarcia4823
      @pablogarcia4823 7 років тому +1

      ZaniddTV What are u doing here zanidd?

    • @zanidd
      @zanidd 7 років тому

      p gu enjoying the intro song. obviously :P

    • @HackerSploit
      @HackerSploit  7 років тому

      Thanks.

  • @r3dcl0udzz20
    @r3dcl0udzz20 7 років тому

    Notification squad

  • @adnanahmed9215
    @adnanahmed9215 3 роки тому

    This man sounds like Mufti Menk lol

  • @8080VB
    @8080VB 3 роки тому +1

    lol hes cheating , he knw the password n he just only added the password with 16 words to the wordlist.txt

  • @russiansoldiersniper4183
    @russiansoldiersniper4183 7 років тому +1

    hi

  • @monsterhk7633
    @monsterhk7633 7 років тому

    Pliz bro 1 gmail account hack pliz reply

  • @thefazledyn
    @thefazledyn 3 роки тому

    lol, ur wordlist was only 54 bytes. you stored the exact password there

  • @AnuragsharanTG
    @AnuragsharanTG 7 років тому +1

    Don't install nulled themes and plugins.

  • @AliAhmad-dz1db
    @AliAhmad-dz1db 6 років тому

    Can you send me word list.

  • @skmajin2922
    @skmajin2922 7 років тому +1

    Make a tch hydra tutorial plz

  • @anounTT
    @anounTT Рік тому

    fsociety folder... lol

  • @ashleybishton742
    @ashleybishton742 3 роки тому

    chances on a real one are slim even with the 14 million rockyou wordlist. your grandkids would still be sat at the pc at age 80 and still wouldnt have cracked it. the password needs to be in the wordlist? what's the chances of that and how long will it take to find? hack the box and try hack me all the passwords are in the wordlists built in with kali so it might seem easy on one of them ones but on a real target out in the wild.....its going to take decades possibly the age of the universe depending on the complexity of password. if its not using a mix of uppercase, lowercase, number and special character then it will be easy. but we all use that sort of policy as most websites use that sort of thing if you don't put any in then you are not agreeing to the policy conditions/terms and wont be allowed to create an account so u need to stick with password policy and staff should all know what kind of password to use its just basic baby stuff lol no ones going to hold their hand if they cant set up a password lol. they going to get fire on the spot for that shit lol

    • @mk71618
      @mk71618 Рік тому +2

      I think you underestimate how clueless most regular people are about their online security, and how many extremely flimsy auth systems are still in use. And I'm not just talking about small companies/individuals.

  • @neonlight8154
    @neonlight8154 4 роки тому +2

    I want to hack a wordpress acc

  • @r3dcl0udzz20
    @r3dcl0udzz20 7 років тому

    4th

  • @Abdullah-po5er
    @Abdullah-po5er 4 роки тому +1

    Rip english

  • @pablosaenz161
    @pablosaenz161 6 років тому +1

    Why make this video use the wordlist and don't share it ? 👎👎

  • @رسطمالسيستانيالإرهابيلقلوقبنيص

    BROTHER SEND US THE LINK OF YOUR SPECIAL WORDLIST HAHAHAHAH;you can upload it on mediafire please brother and thanks a lot of

  • @MrGFYne1337357
    @MrGFYne1337357 7 років тому

    7th, dang

  • @رسطمالسيستانيالإرهابيلقلوقبنيص

    brother make a video aND TEACH US HOW TO BUILD SIMPLE WORPDRESS SITE AS BLOG than we can see comments and our repsonses on them. WITH EMAIL NOTIFICATION ON LOCALHOST THEN WE UPLOAD IT ON FREE HOSTING LIKE 000webhost pls..and thanks again