Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow for simpler way to skip enumeration #1688

Open
fitzg2 opened this issue Nov 21, 2021 · 5 comments
Open

Allow for simpler way to skip enumeration #1688

fitzg2 opened this issue Nov 21, 2021 · 5 comments

Comments

@fitzg2
Copy link

fitzg2 commented Nov 21, 2021

Is your feature request related to a problem? Please describe.
Sometimes we have admin access to a certain amount of WP sites and want to skip enumeration in order to obtain faster results.
Besides faster we also want more precise results. For example we have 12 and we get 6 with or without enumerating. Those other 6 could also be attack vectors. In our example WordFence gets ignored with or without enumeration.

Describe the solution you'd like
Not sure. A plugin maybe that precisely lists all plugins and themes plus WP version? the information protected by IP whitelist.
API access to WP?
SSH access?

Describe alternatives you've considered
None

Additional context
None

@erwanlr
Copy link
Member

erwanlr commented Nov 24, 2021

It's quite unclear what you want here, you mention skipping the enumeration but still want to find more plugins. WPScan has a lot of options, the current default being set to provide the best trade between result and speed but you can change any of them to get more results and more accurate one, which will take more time though. wpscan --hh will list all available options

If you have admin access, then you could simply install our plugin - https://wordpress.org/plugins/wpscan/

@vansh1
Copy link

vansh1 commented Jan 20, 2022

can you tell how to skip enumerate I'm trying to bruteforce but its annoying everytime i have to do enumeration part ehich takes time

@fitzg2
Copy link
Author

fitzg2 commented Jan 20, 2022

@vansh1 your comment is even more unclear than mine. We have access to our sites as admin and want the scanner to login and get the plugins and themes instead of bruteforcing or scanning.

By the way we use a wp-scan wrapper called wp-watcher so idk who to talk to.

@vansh1
Copy link

vansh1 commented Jan 21, 2022

@fitzg2 sorry dude i came in between of your thread actually mine question is just as simple as i said i want to skip enumeration part while doing bruteforce, is it possible?

@alexsanford
Copy link
Contributor

We have access to our sites as admin and want the scanner to login and get the plugins and themes instead of bruteforcing or scanning.

Flagging this as a feature request.

i want to skip enumeration part while doing bruteforce, is it possible?

Added a feature request here: #1802

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants