919 lines
36 KiB
HTML
919 lines
36 KiB
HTML
<!DOCTYPE html>
|
|
|
|
<html>
|
|
<head>
|
|
<meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
|
|
|
|
<title>class WpTarget - RDoc Documentation</title>
|
|
|
|
<link type="text/css" media="screen" href="./rdoc.css" rel="stylesheet">
|
|
|
|
<script type="text/javascript">
|
|
var rdoc_rel_prefix = "./";
|
|
</script>
|
|
|
|
<script type="text/javascript" charset="utf-8" src="./js/jquery.js"></script>
|
|
<script type="text/javascript" charset="utf-8" src="./js/navigation.js"></script>
|
|
<script type="text/javascript" charset="utf-8" src="./js/search_index.js"></script>
|
|
<script type="text/javascript" charset="utf-8" src="./js/search.js"></script>
|
|
<script type="text/javascript" charset="utf-8" src="./js/searcher.js"></script>
|
|
<script type="text/javascript" charset="utf-8" src="./js/darkfish.js"></script>
|
|
|
|
|
|
<body id="top" class="class">
|
|
<nav id="metadata">
|
|
<nav id="home-section" class="section">
|
|
<h3 class="section-header">
|
|
<a href="./index.html">Home</a>
|
|
<a href="./table_of_contents.html#classes">Classes</a>
|
|
<a href="./table_of_contents.html#methods">Methods</a>
|
|
</h3>
|
|
</nav>
|
|
|
|
|
|
<nav id="search-section" class="section project-section" class="initially-hidden">
|
|
<form action="#" method="get" accept-charset="utf-8">
|
|
<h3 class="section-header">
|
|
<input type="text" name="search" placeholder="Search" id="search-field"
|
|
title="Type to search, Up and Down to navigate, Enter to load">
|
|
</h3>
|
|
</form>
|
|
|
|
<ul id="search-results" class="initially-hidden"></ul>
|
|
</nav>
|
|
|
|
|
|
<div id="file-metadata">
|
|
<nav id="file-list-section" class="section">
|
|
<h3 class="section-header">Defined In</h3>
|
|
<ul>
|
|
<li>lib/wpscan/wp_target.rb
|
|
</ul>
|
|
</nav>
|
|
|
|
|
|
</div>
|
|
|
|
<div id="class-metadata">
|
|
|
|
<nav id="parent-class-section" class="section">
|
|
<h3 class="section-header">Parent</h3>
|
|
|
|
<p class="link"><a href="Object.html">Object</a>
|
|
|
|
</nav>
|
|
|
|
<!-- Included Modules -->
|
|
<nav id="includes-section" class="section">
|
|
<h3 class="section-header">Included Modules</h3>
|
|
|
|
<ul class="link-list">
|
|
|
|
|
|
<li><a class="include" href="WebSite.html">WebSite</a>
|
|
|
|
|
|
|
|
<li><a class="include" href="WpReadme.html">WpReadme</a>
|
|
|
|
|
|
|
|
<li><a class="include" href="WpFullPathDisclosure.html">WpFullPathDisclosure</a>
|
|
|
|
|
|
|
|
<li><a class="include" href="WpConfigBackup.html">WpConfigBackup</a>
|
|
|
|
|
|
|
|
<li><a class="include" href="WpLoginProtection.html">WpLoginProtection</a>
|
|
|
|
|
|
|
|
<li><a class="include" href="Malwares.html">Malwares</a>
|
|
|
|
|
|
|
|
<li><a class="include" href="WpUsernames.html">WpUsernames</a>
|
|
|
|
|
|
|
|
<li><a class="include" href="WpTimthumbs.html">WpTimthumbs</a>
|
|
|
|
|
|
|
|
<li><a class="include" href="WpPlugins.html">WpPlugins</a>
|
|
|
|
|
|
|
|
<li><a class="include" href="WpThemes.html">WpThemes</a>
|
|
|
|
|
|
|
|
<li><a class="include" href="BruteForce.html">BruteForce</a>
|
|
|
|
|
|
</ul>
|
|
</nav>
|
|
|
|
<!-- Method Quickref -->
|
|
<nav id="method-list-section" class="section">
|
|
<h3 class="section-header">Methods</h3>
|
|
|
|
<ul class="link-list">
|
|
|
|
<li><a href="#method-c-new">::new</a>
|
|
|
|
<li><a href="#method-c-valid_response_codes">::valid_response_codes</a>
|
|
|
|
<li><a href="#method-i-debug_log_url">#debug_log_url</a>
|
|
|
|
<li><a href="#method-i-error_404_hash">#error_404_hash</a>
|
|
|
|
<li><a href="#method-i-has_debug_log-3F">#has_debug_log?</a>
|
|
|
|
<li><a href="#method-i-is_multisite-3F">#is_multisite?</a>
|
|
|
|
<li><a href="#method-i-login_url">#login_url</a>
|
|
|
|
<li><a href="#method-i-registration_enabled-3F">#registration_enabled?</a>
|
|
|
|
<li><a href="#method-i-registration_url">#registration_url</a>
|
|
|
|
<li><a href="#method-i-search_replace_db_2_exists-3F">#search_replace_db_2_exists?</a>
|
|
|
|
<li><a href="#method-i-search_replace_db_2_url">#search_replace_db_2_url</a>
|
|
|
|
<li><a href="#method-i-theme">#theme</a>
|
|
|
|
<li><a href="#method-i-url">#url</a>
|
|
|
|
<li><a href="#method-i-version">#version</a>
|
|
|
|
<li><a href="#method-i-wp_content_dir">#wp_content_dir</a>
|
|
|
|
<li><a href="#method-i-wp_plugins_dir">#wp_plugins_dir</a>
|
|
|
|
<li><a href="#method-i-wp_plugins_dir_exists-3F">#wp_plugins_dir_exists?</a>
|
|
|
|
</ul>
|
|
</nav>
|
|
|
|
</div>
|
|
|
|
<div id="project-metadata">
|
|
<nav id="fileindex-section" class="section project-section">
|
|
<h3 class="section-header">Pages</h3>
|
|
|
|
<ul>
|
|
|
|
<li class="file"><a href="./CREDITS.html">CREDITS</a>
|
|
|
|
<li class="file"><a href="./Gemfile.html">Gemfile</a>
|
|
|
|
<li class="file"><a href="./README.html">README</a>
|
|
|
|
</ul>
|
|
</nav>
|
|
|
|
<nav id="classindex-section" class="section project-section">
|
|
<h3 class="section-header">Class and Module Index</h3>
|
|
|
|
<ul class="link-list">
|
|
|
|
<li><a href="./Array.html">Array</a>
|
|
|
|
<li><a href="./Browser.html">Browser</a>
|
|
|
|
<li><a href="./BruteForce.html">BruteForce</a>
|
|
|
|
<li><a href="./CacheFileStore.html">CacheFileStore</a>
|
|
|
|
<li><a href="./Exploit.html">Exploit</a>
|
|
|
|
<li><a href="./Generate_List.html">Generate_List</a>
|
|
|
|
<li><a href="./GitUpdater.html">GitUpdater</a>
|
|
|
|
<li><a href="./Malwares.html">Malwares</a>
|
|
|
|
<li><a href="./Object.html">Object</a>
|
|
|
|
<li><a href="./RpcClient.html">RpcClient</a>
|
|
|
|
<li><a href="./SvnUpdater.html">SvnUpdater</a>
|
|
|
|
<li><a href="./Svn_Parser.html">Svn_Parser</a>
|
|
|
|
<li><a href="./URI.html">URI</a>
|
|
|
|
<li><a href="./Updater.html">Updater</a>
|
|
|
|
<li><a href="./UpdaterFactory.html">UpdaterFactory</a>
|
|
|
|
<li><a href="./Vulnerable.html">Vulnerable</a>
|
|
|
|
<li><a href="./WebSite.html">WebSite</a>
|
|
|
|
<li><a href="./WpConfigBackup.html">WpConfigBackup</a>
|
|
|
|
<li><a href="./WpDetector.html">WpDetector</a>
|
|
|
|
<li><a href="./WpEnumerator.html">WpEnumerator</a>
|
|
|
|
<li><a href="./WpFullPathDisclosure.html">WpFullPathDisclosure</a>
|
|
|
|
<li><a href="./WpItem.html">WpItem</a>
|
|
|
|
<li><a href="./WpLoginProtection.html">WpLoginProtection</a>
|
|
|
|
<li><a href="./WpOptions.html">WpOptions</a>
|
|
|
|
<li><a href="./WpPlugin.html">WpPlugin</a>
|
|
|
|
<li><a href="./WpPlugins.html">WpPlugins</a>
|
|
|
|
<li><a href="./WpReadme.html">WpReadme</a>
|
|
|
|
<li><a href="./WpTarget.html">WpTarget</a>
|
|
|
|
<li><a href="./WpTheme.html">WpTheme</a>
|
|
|
|
<li><a href="./WpThemes.html">WpThemes</a>
|
|
|
|
<li><a href="./WpTimthumbs.html">WpTimthumbs</a>
|
|
|
|
<li><a href="./WpUser.html">WpUser</a>
|
|
|
|
<li><a href="./WpUsernames.html">WpUsernames</a>
|
|
|
|
<li><a href="./WpVersion.html">WpVersion</a>
|
|
|
|
<li><a href="./WpVulnerability.html">WpVulnerability</a>
|
|
|
|
<li><a href="./WpscanOptions.html">WpscanOptions</a>
|
|
|
|
</ul>
|
|
</nav>
|
|
|
|
</div>
|
|
</nav>
|
|
|
|
<div id="documentation">
|
|
<h1 class="class">class WpTarget</h1>
|
|
|
|
<div id="description" class="description">
|
|
|
|
</div><!-- description -->
|
|
|
|
|
|
|
|
|
|
<section id="5Buntitled-5D" class="documentation-section">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<!-- Attributes -->
|
|
<section id="attribute-method-details" class="method-section section">
|
|
<h3 class="section-header">Attributes</h3>
|
|
|
|
|
|
<div id="attribute-i-uri" class="method-detail">
|
|
<div class="method-heading attribute-method-heading">
|
|
<span class="method-name">uri</span><span
|
|
class="attribute-access-type">[R]</span>
|
|
</div>
|
|
|
|
<div class="method-description">
|
|
|
|
|
|
|
|
</div>
|
|
</div>
|
|
|
|
<div id="attribute-i-verbose" class="method-detail">
|
|
<div class="method-heading attribute-method-heading">
|
|
<span class="method-name">verbose</span><span
|
|
class="attribute-access-type">[R]</span>
|
|
</div>
|
|
|
|
<div class="method-description">
|
|
|
|
|
|
|
|
</div>
|
|
</div>
|
|
|
|
</section><!-- attribute-method-details -->
|
|
|
|
|
|
<!-- Methods -->
|
|
|
|
<section id="public-class-5Buntitled-5D-method-details" class="method-section section">
|
|
<h3 class="section-header">Public Class Methods</h3>
|
|
|
|
|
|
<div id="method-c-new" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">new</span><span
|
|
class="method-args">(target_url, options = {})</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
|
|
|
|
|
|
|
|
<div class="method-source-code" id="new-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 36</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">initialize</span>(<span class="ruby-identifier">target_url</span>, <span class="ruby-identifier">options</span> = {})
|
|
<span class="ruby-ivar">@uri</span> = <span class="ruby-constant">URI</span>.<span class="ruby-identifier">parse</span>(<span class="ruby-identifier">add_trailing_slash</span>(<span class="ruby-identifier">add_http_protocol</span>(<span class="ruby-identifier">target_url</span>)))
|
|
<span class="ruby-ivar">@verbose</span> = <span class="ruby-identifier">options</span>[<span class="ruby-value">:verbose</span>]
|
|
<span class="ruby-ivar">@wp_content_dir</span> = <span class="ruby-identifier">options</span>[<span class="ruby-value">:wp_content_dir</span>]
|
|
<span class="ruby-ivar">@wp_plugins_dir</span> = <span class="ruby-identifier">options</span>[<span class="ruby-value">:wp_plugins_dir</span>]
|
|
<span class="ruby-ivar">@multisite</span> = <span class="ruby-keyword">nil</span>
|
|
|
|
<span class="ruby-constant">Browser</span>.<span class="ruby-identifier">instance</span>(<span class="ruby-identifier">options</span>.<span class="ruby-identifier">merge</span>(<span class="ruby-value">:max_threads</span> =<span class="ruby-operator">></span> <span class="ruby-identifier">options</span>[<span class="ruby-value">:threads</span>]))
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- new-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- new-method -->
|
|
|
|
|
|
<div id="method-c-valid_response_codes" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">valid_response_codes</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
<p>Valid HTTP return codes</p>
|
|
|
|
|
|
|
|
<div class="method-source-code" id="valid_response_codes-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 77</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-keyword">self</span>.<span class="ruby-identifier">valid_response_codes</span>
|
|
[<span class="ruby-value">200</span>, <span class="ruby-value">403</span>, <span class="ruby-value">301</span>, <span class="ruby-value">302</span>, <span class="ruby-value">500</span>]
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- valid_response_codes-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- valid_response_codes-method -->
|
|
|
|
|
|
</section><!-- public-class-method-details -->
|
|
|
|
<section id="public-instance-5Buntitled-5D-method-details" class="method-section section">
|
|
<h3 class="section-header">Public Instance Methods</h3>
|
|
|
|
|
|
<div id="method-i-debug_log_url" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">debug_log_url</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
|
|
|
|
|
|
|
|
<div class="method-source-code" id="debug_log_url-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 123</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">debug_log_url</span>
|
|
<span class="ruby-ivar">@uri</span>.<span class="ruby-identifier">merge</span>(<span class="ruby-node">"#{wp_content_dir()}/debug.log"</span>).<span class="ruby-identifier">to_s</span>
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- debug_log_url-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- debug_log_url-method -->
|
|
|
|
|
|
<div id="method-i-error_404_hash" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">error_404_hash</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
<p>Return the MD5 hash of a 404 page</p>
|
|
|
|
|
|
|
|
<div class="method-source-code" id="error_404_hash-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 64</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">error_404_hash</span>
|
|
<span class="ruby-keyword">unless</span> <span class="ruby-ivar">@error_404_hash</span>
|
|
<span class="ruby-identifier">non_existant_page</span> = <span class="ruby-constant">Digest</span><span class="ruby-operator">::</span><span class="ruby-constant">MD5</span>.<span class="ruby-identifier">hexdigest</span>(<span class="ruby-identifier">rand</span>(<span class="ruby-value">9999999999</span>).<span class="ruby-identifier">to_s</span>) <span class="ruby-operator">+</span> <span class="ruby-string">".html"</span>
|
|
|
|
<span class="ruby-identifier">response</span> = <span class="ruby-constant">Browser</span>.<span class="ruby-identifier">instance</span>.<span class="ruby-identifier">get</span>(<span class="ruby-ivar">@uri</span>.<span class="ruby-identifier">merge</span>(<span class="ruby-identifier">non_existant_page</span>).<span class="ruby-identifier">to_s</span>)
|
|
|
|
<span class="ruby-ivar">@error_404_hash</span> = <span class="ruby-constant">Digest</span><span class="ruby-operator">::</span><span class="ruby-constant">MD5</span>.<span class="ruby-identifier">hexdigest</span>(<span class="ruby-identifier">response</span>.<span class="ruby-identifier">body</span>)
|
|
<span class="ruby-keyword">end</span>
|
|
|
|
<span class="ruby-ivar">@error_404_hash</span>
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- error_404_hash-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- error_404_hash-method -->
|
|
|
|
|
|
<div id="method-i-has_debug_log-3F" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">has_debug_log?</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
|
|
|
|
|
|
|
|
<div class="method-source-code" id="has_debug_log-3F-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 117</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">has_debug_log?</span>
|
|
<span class="ruby-comment"># We only get the first 700 bytes of the file to avoid loading huge file (like 2Go)</span>
|
|
<span class="ruby-identifier">response_body</span> = <span class="ruby-constant">Browser</span>.<span class="ruby-identifier">instance</span>.<span class="ruby-identifier">get</span>(<span class="ruby-identifier">debug_log_url</span>(), <span class="ruby-value">:headers</span> =<span class="ruby-operator">></span> {<span class="ruby-string">"range"</span> =<span class="ruby-operator">></span> <span class="ruby-string">"bytes=0-700"</span>}).<span class="ruby-identifier">body</span>
|
|
<span class="ruby-identifier">response_body</span>[<span class="ruby-regexp">%r{\[[^\]]+\] PHP (?:Warning|Error|Notice):}</span>] <span class="ruby-operator">?</span> <span class="ruby-keyword">true</span> <span class="ruby-operator">:</span> <span class="ruby-keyword">false</span>
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- has_debug_log-3F-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- has_debug_log-3F-method -->
|
|
|
|
|
|
<div id="method-i-is_multisite-3F" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">is_multisite?</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
|
|
|
|
|
|
|
|
<div class="method-source-code" id="is_multisite-3F-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 162</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">is_multisite?</span>
|
|
<span class="ruby-keyword">unless</span> <span class="ruby-ivar">@multisite</span>
|
|
<span class="ruby-comment"># when multi site, there is no redirection or a redirect to the site itself</span>
|
|
<span class="ruby-comment"># otherwise redirect to wp-login.php</span>
|
|
<span class="ruby-identifier">url</span> = <span class="ruby-ivar">@uri</span>.<span class="ruby-identifier">merge</span>(<span class="ruby-string">"wp-signup.php"</span>)
|
|
<span class="ruby-identifier">resp</span> = <span class="ruby-constant">Browser</span>.<span class="ruby-identifier">instance</span>.<span class="ruby-identifier">get</span>(<span class="ruby-identifier">url</span>)
|
|
<span class="ruby-keyword">if</span> <span class="ruby-identifier">resp</span>.<span class="ruby-identifier">code</span> <span class="ruby-operator">==</span> <span class="ruby-value">302</span> <span class="ruby-keyword">and</span> <span class="ruby-identifier">resp</span>.<span class="ruby-identifier">headers_hash</span>[<span class="ruby-string">"location"</span>] <span class="ruby-operator">=~</span> <span class="ruby-regexp">%rwp-login\.php\?action=register/</span>
|
|
<span class="ruby-ivar">@multisite</span> = <span class="ruby-keyword">false</span>
|
|
<span class="ruby-keyword">elsif</span> <span class="ruby-identifier">resp</span>.<span class="ruby-identifier">code</span> <span class="ruby-operator">==</span> <span class="ruby-value">302</span> <span class="ruby-keyword">and</span> <span class="ruby-identifier">resp</span>.<span class="ruby-identifier">headers_hash</span>[<span class="ruby-string">"location"</span>] <span class="ruby-operator">=~</span> <span class="ruby-regexp">%rwp-signup\.php/</span>
|
|
<span class="ruby-ivar">@multisite</span> = <span class="ruby-keyword">true</span>
|
|
<span class="ruby-keyword">elsif</span> <span class="ruby-identifier">resp</span>.<span class="ruby-identifier">code</span> <span class="ruby-operator">==</span> <span class="ruby-value">200</span>
|
|
<span class="ruby-ivar">@multisite</span> = <span class="ruby-keyword">true</span>
|
|
<span class="ruby-keyword">else</span>
|
|
<span class="ruby-ivar">@multisite</span> = <span class="ruby-keyword">false</span>
|
|
<span class="ruby-keyword">end</span>
|
|
<span class="ruby-keyword">end</span>
|
|
<span class="ruby-ivar">@multisite</span>
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- is_multisite-3F-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- is_multisite-3F-method -->
|
|
|
|
|
|
<div id="method-i-login_url" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">login_url</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
|
|
|
|
|
|
|
|
<div class="method-source-code" id="login_url-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 51</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">login_url</span>
|
|
<span class="ruby-identifier">url</span> = <span class="ruby-ivar">@uri</span>.<span class="ruby-identifier">merge</span>(<span class="ruby-string">"wp-login.php"</span>).<span class="ruby-identifier">to_s</span>
|
|
|
|
<span class="ruby-comment"># Let's check if the login url is redirected (to https url for example)</span>
|
|
<span class="ruby-identifier">redirection</span> = <span class="ruby-identifier">redirection</span>(<span class="ruby-identifier">url</span>)
|
|
<span class="ruby-keyword">if</span> <span class="ruby-identifier">redirection</span>
|
|
<span class="ruby-identifier">url</span> = <span class="ruby-identifier">redirection</span>
|
|
<span class="ruby-keyword">end</span>
|
|
|
|
<span class="ruby-identifier">url</span>
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- login_url-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- login_url-method -->
|
|
|
|
|
|
<div id="method-i-registration_enabled-3F" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">registration_enabled?</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
<p>Should check wp-login.php if registration is enabled or not</p>
|
|
|
|
|
|
|
|
<div class="method-source-code" id="registration_enabled-3F-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 140</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">registration_enabled?</span>
|
|
<span class="ruby-identifier">resp</span> = <span class="ruby-constant">Browser</span>.<span class="ruby-identifier">instance</span>.<span class="ruby-identifier">get</span>(<span class="ruby-identifier">registration_url</span>)
|
|
<span class="ruby-comment"># redirect only on non multi sites</span>
|
|
<span class="ruby-keyword">if</span> <span class="ruby-identifier">resp</span>.<span class="ruby-identifier">code</span> <span class="ruby-operator">==</span> <span class="ruby-value">302</span> <span class="ruby-keyword">and</span> <span class="ruby-identifier">resp</span>.<span class="ruby-identifier">headers_hash</span>[<span class="ruby-string">"location"</span>] <span class="ruby-operator">=~</span> <span class="ruby-regexp">%rwp-login\.php\?registration=disabled/</span>
|
|
<span class="ruby-identifier">enabled</span> = <span class="ruby-keyword">false</span>
|
|
<span class="ruby-comment"># multi site registration form</span>
|
|
<span class="ruby-keyword">elsif</span> <span class="ruby-identifier">resp</span>.<span class="ruby-identifier">code</span> <span class="ruby-operator">==</span> <span class="ruby-value">200</span> <span class="ruby-keyword">and</span> <span class="ruby-identifier">resp</span>.<span class="ruby-identifier">body</span> <span class="ruby-operator">=~</span> <span class="ruby-regexp">%r<form id="setupform" method="post" action="[^"]*wp-signup\.php[^"]*">/</span>
|
|
<span class="ruby-identifier">enabled</span> = <span class="ruby-keyword">true</span>
|
|
<span class="ruby-comment"># normal registration form</span>
|
|
<span class="ruby-keyword">elsif</span> <span class="ruby-identifier">resp</span>.<span class="ruby-identifier">code</span> <span class="ruby-operator">==</span> <span class="ruby-value">200</span> <span class="ruby-keyword">and</span> <span class="ruby-identifier">resp</span>.<span class="ruby-identifier">body</span> <span class="ruby-operator">=~</span> <span class="ruby-regexp">%r<form name="registerform" id="registerform" action="[^"]*wp-login\.php[^"]*"/</span>
|
|
<span class="ruby-identifier">enabled</span> = <span class="ruby-keyword">true</span>
|
|
<span class="ruby-comment"># registration disabled</span>
|
|
<span class="ruby-keyword">else</span>
|
|
<span class="ruby-identifier">enabled</span> = <span class="ruby-keyword">false</span>
|
|
<span class="ruby-keyword">end</span>
|
|
<span class="ruby-identifier">enabled</span>
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- registration_enabled-3F-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- registration_enabled-3F-method -->
|
|
|
|
|
|
<div id="method-i-registration_url" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">registration_url</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
|
|
|
|
|
|
|
|
<div class="method-source-code" id="registration_url-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 158</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">registration_url</span>
|
|
<span class="ruby-identifier">is_multisite?</span> <span class="ruby-operator">?</span> <span class="ruby-ivar">@uri</span>.<span class="ruby-identifier">merge</span>(<span class="ruby-string">"wp-signup.php"</span>) <span class="ruby-operator">:</span> <span class="ruby-ivar">@uri</span>.<span class="ruby-identifier">merge</span>(<span class="ruby-string">"wp-login.php?action=register"</span>)
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- registration_url-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- registration_url-method -->
|
|
|
|
|
|
<div id="method-i-search_replace_db_2_exists-3F" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">search_replace_db_2_exists?</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
|
|
|
|
|
|
|
|
<div class="method-source-code" id="search_replace_db_2_exists-3F-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 134</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">search_replace_db_2_exists?</span>
|
|
<span class="ruby-identifier">resp</span> = <span class="ruby-constant">Browser</span>.<span class="ruby-identifier">instance</span>.<span class="ruby-identifier">get</span>(<span class="ruby-identifier">search_replace_db_2_url</span>)
|
|
<span class="ruby-identifier">resp</span>.<span class="ruby-identifier">code</span> <span class="ruby-operator">==</span> <span class="ruby-value">200</span> <span class="ruby-operator">&&</span> <span class="ruby-identifier">resp</span>.<span class="ruby-identifier">body</span>[<span class="ruby-regexp">%r{by interconnect}</span>]
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- search_replace_db_2_exists-3F-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- search_replace_db_2_exists-3F-method -->
|
|
|
|
|
|
<div id="method-i-search_replace_db_2_url" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">search_replace_db_2_url</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
<p>Script for replacing strings in wordpress databases reveals databse
|
|
credentials after hitting submit <a
|
|
href="http://interconnectit.com/124/search-and-replace-for-wordpress-databases/">interconnectit.com/124/search-and-replace-for-wordpress-databases/</a></p>
|
|
|
|
|
|
|
|
<div class="method-source-code" id="search_replace_db_2_url-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 130</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">search_replace_db_2_url</span>
|
|
<span class="ruby-ivar">@uri</span>.<span class="ruby-identifier">merge</span>(<span class="ruby-string">"searchreplacedb2.php"</span>).<span class="ruby-identifier">to_s</span>
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- search_replace_db_2_url-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- search_replace_db_2_url-method -->
|
|
|
|
|
|
<div id="method-i-theme" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">theme</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
<p>return <a href="WpTheme.html">WpTheme</a></p>
|
|
|
|
|
|
|
|
<div class="method-source-code" id="theme-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 82</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">theme</span>
|
|
<span class="ruby-constant">WpTheme</span>.<span class="ruby-identifier">find</span>(<span class="ruby-ivar">@uri</span>)
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- theme-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- theme-method -->
|
|
|
|
|
|
<div id="method-i-url" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">url</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
<p>Alias of @uri.to_s</p>
|
|
|
|
|
|
|
|
<div class="method-source-code" id="url-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 47</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">url</span>
|
|
<span class="ruby-ivar">@uri</span>.<span class="ruby-identifier">to_s</span>
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- url-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- url-method -->
|
|
|
|
|
|
<div id="method-i-version" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">version</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
<p>return <a href="WpVersion.html">WpVersion</a></p>
|
|
|
|
|
|
|
|
<div class="method-source-code" id="version-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 87</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">version</span>
|
|
<span class="ruby-constant">WpVersion</span>.<span class="ruby-identifier">find</span>(<span class="ruby-ivar">@uri</span>, <span class="ruby-identifier">wp_content_dir</span>)
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- version-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- version-method -->
|
|
|
|
|
|
<div id="method-i-wp_content_dir" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">wp_content_dir</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
|
|
|
|
|
|
|
|
<div class="method-source-code" id="wp_content_dir-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 91</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">wp_content_dir</span>
|
|
<span class="ruby-keyword">unless</span> <span class="ruby-ivar">@wp_content_dir</span>
|
|
<span class="ruby-identifier">index_body</span> = <span class="ruby-constant">Browser</span>.<span class="ruby-identifier">instance</span>.<span class="ruby-identifier">get</span>(<span class="ruby-ivar">@uri</span>.<span class="ruby-identifier">to_s</span>).<span class="ruby-identifier">body</span>
|
|
<span class="ruby-comment"># Only use the path because domain can be text or an ip</span>
|
|
<span class="ruby-identifier">uri_path</span> = <span class="ruby-ivar">@uri</span>.<span class="ruby-identifier">path</span>
|
|
|
|
<span class="ruby-keyword">if</span> <span class="ruby-identifier">index_body</span>[<span class="ruby-regexp">%r\/wp-content\/(?:themes|plugins)\//</span>]
|
|
<span class="ruby-ivar">@wp_content_dir</span> = <span class="ruby-string">"wp-content"</span>
|
|
<span class="ruby-keyword">else</span>
|
|
<span class="ruby-ivar">@wp_content_dir</span> = <span class="ruby-identifier">index_body</span>[<span class="ruby-node">%r(?:href|src)\s*=\s*(?:"|').+#{Regexp.escape(uri_path)}([^"']+)\/(?:themes|plugins)\/.*(?:"|')/</span>, <span class="ruby-value">1</span>]
|
|
<span class="ruby-keyword">end</span>
|
|
<span class="ruby-keyword">end</span>
|
|
<span class="ruby-ivar">@wp_content_dir</span>
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- wp_content_dir-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- wp_content_dir-method -->
|
|
|
|
|
|
<div id="method-i-wp_plugins_dir" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">wp_plugins_dir</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
|
|
|
|
|
|
|
|
<div class="method-source-code" id="wp_plugins_dir-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 106</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">wp_plugins_dir</span>
|
|
<span class="ruby-keyword">unless</span> <span class="ruby-ivar">@wp_plugins_dir</span>
|
|
<span class="ruby-ivar">@wp_plugins_dir</span> = <span class="ruby-node">"#{wp_content_dir}/plugins"</span>
|
|
<span class="ruby-keyword">end</span>
|
|
<span class="ruby-ivar">@wp_plugins_dir</span>
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- wp_plugins_dir-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- wp_plugins_dir-method -->
|
|
|
|
|
|
<div id="method-i-wp_plugins_dir_exists-3F" class="method-detail ">
|
|
|
|
<div class="method-heading">
|
|
<span class="method-name">wp_plugins_dir_exists?</span><span
|
|
class="method-args">()</span>
|
|
<span class="method-click-advice">click to toggle source</span>
|
|
</div>
|
|
|
|
|
|
<div class="method-description">
|
|
|
|
|
|
|
|
|
|
|
|
<div class="method-source-code" id="wp_plugins_dir_exists-3F-source">
|
|
<pre><span class="ruby-comment"># File lib/wpscan/wp_target.rb, line 113</span>
|
|
<span class="ruby-keyword">def</span> <span class="ruby-identifier">wp_plugins_dir_exists?</span>
|
|
<span class="ruby-constant">Browser</span>.<span class="ruby-identifier">instance</span>.<span class="ruby-identifier">get</span>(<span class="ruby-ivar">@uri</span>.<span class="ruby-identifier">merge</span>(<span class="ruby-identifier">wp_plugins_dir</span>)).<span class="ruby-identifier">code</span> <span class="ruby-operator">!=</span> <span class="ruby-value">404</span>
|
|
<span class="ruby-keyword">end</span></pre>
|
|
</div><!-- wp_plugins_dir_exists-3F-source -->
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
</div><!-- wp_plugins_dir_exists-3F-method -->
|
|
|
|
|
|
</section><!-- public-instance-method-details -->
|
|
|
|
</section><!-- 5Buntitled-5D -->
|
|
|
|
</div><!-- documentation -->
|
|
|
|
|
|
<footer id="validator-badges">
|
|
<p><a href="http://validator.w3.org/check/referer">[Validate]</a>
|
|
<p>Generated by <a href="https://github.com/rdoc/rdoc">RDoc</a> 3.12.
|
|
<p>Generated with the <a href="http://deveiate.org/projects/Darkfish-Rdoc/">Darkfish Rdoc Generator</a> 3.
|
|
</footer>
|
|
|