Penetration Test for WordPress Website Using WPScan in Kali Linux

How-to-do-Penetration-Test-for--WordPress-Website
How to do Penetration Test for  WordPress Website :-
Penetration testing is process of evaluating the security of Computer system or network System by simulating an attack .In this article i am going to show you How to perform penetration test for WordPress website with Kali Linux.
Navigate to Applications > Kali Linux > Web Applications > CMS identification > select wpscan 
How-to-do-Penetration-Test-for--WordPress-Website1
or enter the following command on the Terminal root@kali:~#wpscan -h
How-to-do-Penetration-Test-for--WordPress-Website1
1. Check the Installed Plugins :-
Open the Terminal and enter the following command
root@Kali:~#wpscan  – – url www.example.com –enumerate p

In this test, i performed this test on the one of the most popular computer education site to check the installed plugins. WP-Scan found the 15 active plugins.
How-to-do-Penetration-Test-for--WordPress-Website1
2. Check the Running WordPress version :-
Open the terminal and enter the following command
 root@Kali:~#wpscan – – url www.yourtargetsite.com 
it detects the WordPress version running on a site is 3.6.1 .
How-to-do-Penetration-Test-for--WordPress-Website1
3. Finding Username
Open the Terminal and enter the following command to enumerate the Username of WordPress site.
root@Kali:~#wpscan  – – url www.yourtargetsite.com – – enumerate u
As you seen in the below image, it,s find out two users on the WordPress site.
4. Perform Brute-force attack on “admin ” User only
Open the terminal and enter the following command to perform Brute force attack on the admin user.
root@Kali:~#wpscan  – – url www.yourtargetsite.com – -wordlist yourwordlist.txt – -username admin
Where youwordlist.txt is your wordlist location. Check my article HOW TO CREATE OUR OWN WORDLIST USING CRUNCH IN KALI LINUX
5. Brute Force attack on Enumerated User :-
Open the terminal and enter the following command
root@Kali:~#wpscan  – – url www.yourtargetsite.com – -wordlist yourwordlist.txt – -threads 50
6. Use HTTP and Socks 5 Proxy during Pen-testing :-
To use a HTTP Proxy enter the following command :-
root@Kali:~#wpscan  – – url www.yourtargetsite.com – -proxy 17.0.0.1:8118
To use a Socks 5 proxy ( cURL >= v7.21.7 needed )
root@Kali:~#wpscan  – – url www.yourtargetsite.com – -proxy socks5://127.0.0.1:9000
Thanks for your comment
Maaf untuk sementara ini klik kanan dinonaktifkan, karena banyak blogger yang copy paste sembarangan tanpa izin.

Jadi jika ingin Copy Tekan "
Ctrl
+
C
". Dan jika ingin buka link di new tab klik linknya sambil menekan tombol
Ctrl
. Terimakasih atas Pengertiannya, dan mohon maaf Jika anda terganggu. .
Best Regards سفياني محمد