Sha256: 3211f8456ba51bceac0b98036b52419d020e885a2f81ee95edb0cdd779b5178e
Contents?: true
Size: 692 Bytes
Versions: 25
Compression:
Stored size: 692 Bytes
Contents
# frozen_string_literal: true module WPScan module Finders module Passwords # Password attack against the XMLRPC interface class XMLRPC < CMSScanner::Finders::Finder include CMSScanner::Finders::Finder::BreadthFirstDictionaryAttack def login_request(username, password) target.method_call('wp.getUsersBlogs', [username, password], cache_ttl: 0) end def valid_credentials?(response) response.code == 200 && response.body.include?('blogName') end def errored_response?(response) response.code != 200 && response.body !~ /Incorrect username or password/i end end end end end
Version data entries
25 entries across 25 versions & 1 rubygems