Skip to content

Instantly share code, notes, and snippets.

@vivekpatil94
Created August 22, 2022 22:36
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save vivekpatil94/560b753c29b40e4b3b148d944f6d7066 to your computer and use it in GitHub Desktop.
Save vivekpatil94/560b753c29b40e4b3b148d944f6d7066 to your computer and use it in GitHub Desktop.
[+] URL: https://piticmkt.com/ [2a02:4780:b:848:0:621:69d0:1]
[+] Started: Tue Aug 23 04:02:46 2022
Interesting Finding(s):
[+] Headers
| Interesting Entries:
| - x-powered-by: PHP/7.3.33
| - server: LiteSpeed
| - content-security-policy: upgrade-insecure-requests
| Found By: Headers (Passive Detection)
| Confidence: 100%
[+] robots.txt found: https://piticmkt.com/robots.txt
| Interesting Entries:
| - /wp-admin/
| - /wp-admin/admin-ajax.php
| Found By: Robots Txt (Aggressive Detection)
| Confidence: 100%
[+] XML-RPC seems to be enabled: https://piticmkt.com/xmlrpc.php
| Found By: Direct Access (Aggressive Detection)
| Confidence: 100%
| References:
| - http://codex.wordpress.org/XML-RPC_Pingback_API
| - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner/
| - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos/
| - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login/
| - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access/
[+] WordPress readme found: https://piticmkt.com/readme.html
| Found By: Direct Access (Aggressive Detection)
| Confidence: 100%
[+] The external WP-Cron seems to be enabled: https://piticmkt.com/wp-cron.php
| Found By: Direct Access (Aggressive Detection)
| Confidence: 60%
| References:
| - https://www.iplocation.net/defend-wordpress-from-ddos
| - https://github.com/wpscanteam/wpscan/issues/1299
[+] WordPress version 5.4.10 identified (Latest, released on 2022-03-11).
| Found By: Rss Generator (Passive Detection)
| - https://piticmkt.com/feed/, <generator>https://wordpress.org/?v=5.4.10</generator>
| - https://piticmkt.com/comments/feed/, <generator>https://wordpress.org/?v=5.4.10</generator>
[+] WordPress theme in use: engage
| Location: https://piticmkt.com/wp-content/themes/engage/
| Readme: https://piticmkt.com/wp-content/themes/engage/readme.txt
| Style URL: https://piticmkt.com/wp-content/themes/engage/style.css?ver=1.0.63
| Style Name: Engage
| Style URI: https://themeforest.net/item/engage-creative-multipurpose-wp-theme/19199913
| Description: WordPress reimagined for creating websites....
| Author: Veented
| Author URI: http://themeforest.net/user/Veented
|
| Found By: Css Style In Homepage (Passive Detection)
| Confirmed By: Css Style In 404 Page (Passive Detection)
|
| Version: 2.9.0 (80% confidence)
| Found By: Style (Passive Detection)
| - https://piticmkt.com/wp-content/themes/engage/style.css?ver=1.0.63, Match: 'Version: 2.9.0'
[+] Enumerating Users (via Passive and Aggressive Methods)
Brute Forcing Author IDs - Time: 00:00:04 <==================================================================> (10 / 10) 100.00% Time: 00:00:04
[i] User(s) Identified:
[+] piticmkt
| Found By: Author Posts - Author Pattern (Passive Detection)
| Confirmed By:
| Rss Generator (Passive Detection)
| Wp Json Api (Aggressive Detection)
| - https://piticmkt.com/wp-json/wp/v2/users/?per_page=100&page=1
| Oembed API - Author URL (Aggressive Detection)
| - https://piticmkt.com/wp-json/oembed/1.0/embed?url=https://piticmkt.com/&format=json
| Rss Generator (Aggressive Detection)
| Author Id Brute Forcing - Author Pattern (Aggressive Detection)
[+] WPScan DB API OK
| Plan: free
| Requests Done (during the scan): 0
| Requests Remaining: 73
[+] Finished: Tue Aug 23 04:03:01 2022
[+] Requests Done: 15
[+] Cached Requests: 47
[+] Data Sent: 3.675 KB
[+] Data Received: 42.351 KB
[+] Memory used: 185.246 MB
[+] Elapsed time: 00:00:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment