Skip to content
All writing

Attacking Common Applications Notes

???

Using EyeWitness

1. Wordlist Creation

  • Objective: Create target list for Nmap.
  • Filename: scope_list

2. Nmap Discovery Scan

  • Objective: Find open web ports and output XML.
  • Command:
sudo nmap -p 80,443,8000,8080,8180,8888,10000 --open -oA web_discovery -iL scope_list
  • Note: -oA creates web_discovery.xml which EyeWitness needs.

3. EyeWitness Screenshotting

  • Objective: Automatically screenshot and log the active websites.
  • Command:
eyewitness --web -x web_discovery.xml -d inlanefreight_eyewitness
  • Note: -d creates the output folder for the report.

WordPress Discovery and Enumeration

1. Identify Site Framework

  • Objective: Discover if site is made in WordPress
  • Steps: Checking the robots.txt or enumerating for common WordPress directories can give us an idea on what framework the site is. The presence of /wp-admin or the likes are the ones we are looking for.

2. Manual Enumeration

  • Objective: Look at the page source for additional information
  • Steps: Looking for specific terms in the page source can give us an idea on what version we are working on and the presence of plugins. Common terms are WordPress, themes, plugins

3. Automated Scanner

  • Objective: Automatically scan for common vulnerabilities and features
  • Command:
sudo wpscan --url http://blog.inlanefreight.local --enumerate --api-token dEOFB<SNIP>
  • Note: setting the --enumerate to --enumerate p and adding the --plugins-detection aggressive flag brute forces known plugin paths
  • Note: --api-token is a token from WPScan
  • Note: adding the -t 100 flag sets the thread to 100