Enumeración de CMS
Wordpress
Enumeración de temas y plugins Wordpress
Nmap
nmap -p80 --script http-wordpress-enum --script-args http-wordpress-enum.root='/wordpress',search-limit=1000 remote.nyxWpscan
wpscan --url http://192.168.1.10/wordpress --api-token $WP_TOKEN --plugins-detection aggressiveLa variable de entorno
$WP_TOKENcontiene el token generado en la web https://wpscan.com/
Nuclei
nuclei -u http://remote.nyx/wordpress/ -tags fuzz -t /home/d4redevil/.local/nuclei-templates/http/fuzzing/wordpress-plugins-detect.yamlGobuster
gobuster dir -u http://remote.nyx/wordpress/ -w /usr/share/seclists/Discovery/WebContent/CMS/wp-plugins.fuzz.txtJoomla
joomscan -u http://192.168.1.10Drupal
droopescan scan drupal -u http://example.org/ -t 32Magento
php magescan.phar scan:all <https://example.com>Última actualización