Attacking Common Applications Notes
???
Using EyeWitness
1. Wordlist Creation
- Objective: Create target list for Nmap.
- Filename:
scope_list
2. Nmap Discovery Scan
- Objective: Find open web ports and output XML.
- Command:
sudo nmap -p 80,443,8000,8080,8180,8888,10000 --open -oA web_discovery -iL scope_list
- Note:
-oAcreatesweb_discovery.xmlwhich EyeWitness needs.
3. EyeWitness Screenshotting
- Objective: Automatically screenshot and log the active websites.
- Command:
eyewitness --web -x web_discovery.xml -d inlanefreight_eyewitness
- Note:
-dcreates the output folder for the report.
WordPress Discovery and Enumeration
1. Identify Site Framework
- Objective: Discover if site is made in WordPress
- Steps: Checking the robots.txt or enumerating for common WordPress directories can give us an idea on what framework the site is. The presence of
/wp-adminor the likes are the ones we are looking for.
2. Manual Enumeration
- Objective: Look at the page source for additional information
- Steps: Looking for specific terms in the page source can give us an idea on what version we are working on and the presence of plugins. Common terms are
WordPress, themes, plugins
3. Automated Scanner
- Objective: Automatically scan for common vulnerabilities and features
- Command:
sudo wpscan --url http://blog.inlanefreight.local --enumerate --api-token dEOFB<SNIP>
- Note: setting the
--enumerateto--enumerate pand adding the--plugins-detection aggressiveflag brute forces known plugin paths - Note:
--api-tokenis a token from WPScan - Note: adding the
-t 100flag sets the thread to 100