CMS attacks
Common application attacks
WordPress
Grabbing information from the site
$ curl -s http://blog.inlanefreight.local | grep WordPress # WP version
$ curl -s http://blog.inlanefreight.local/ | grep themes # active theme
$ curl -s http://blog.inlanefreight.local/ | grep plugins # installed pluginsWordPress /robots.txt
/robots.txt User-agent: *
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php
Disallow: /wp-content/uploads/wpforms/
Sitemap: https://<site>/wp-sitemap.xmlKey WordPress files
Key WordPress folders
Enumerating Users
Attacking accounts
Backdoors in WordPress Admin
Joomla
Joomla robots.txt
robots.txtGetting Joomla version
Enumerating with droopescan
droopescanBrute forcing with joomla-bruteforce
joomla-bruteforceBackdoors as Joomla Admin
Drupal
Enumerating with droopescan
droopescanRCE
Drupalgeddons
Last updated