WordPress Brute Force Tool -
13 June, 2011 by ethicalhack3r

Following on from my previous post Patching WordPress Username Disclosure I got bored over the weekend and decided to implement Veronica Valeros’s username disclosure technique into a WordPress password brute force tool.

It is nothing revolutionary or difficult to code, but it may come in handy one day on a pentest or web application assessment, mainly to automate the process.

Currently you can use the tool in 3 different ways.

Only the ‘–url’ option:
Enumerate wordpress usernames.

The ‘–wordlist’ option:
Enumerate wordpress usernames.
Start a dictionary attack on all usernames enumerated.

The ‘–username’ option:
Specify a single username to start the dictionary attack on.

I won’t be releasing the tool, not yet anyway, I may release it in future.

Here is a video of it in action:

UPDATE

The video of my tool seems to have raised lots of interest and questions.

Please understand that I think this this tool is quite trivial to code and I am very surprised that it got so much attention.

One question that was raised more than once, was, why did I not release the code?!

The reason I did not release it is because I was considering the ethicality of such a tool being released. I first wanted to guage the interest in such a tool and if interest was positive, expand the tool further.

I will go into further detail as the code base expands. I can confirm that I will be releasing the code as part of a bigger project called WPScan.

14 Responses



  1. This looks very nice, I’ve pretty much standardized on WordPress for my sites, and like it quite a bit, but should hack its security a bit more. I think for version 2.8 or something they recommended not using the ‘admin’ handle, which is good advice anywhere :) shoot a ping out on twitter if you decide to release this tool, I need to get better with Ruby and this sounds like a good one to start with.

    @fak3r


    Comment posted on June 13, 2011 at 18:36:33 BST

  2. Tester

    the tool works for all version of wordpress ?

    regards


    Comment posted on September 14, 2011 at 13:35:18 BST

  3. hilabi kela

    tumi kela koti mara


    Comment posted on September 20, 2011 at 13:39:38 BST

  4. saeid

    ok if you don’t want to publish so don’t fuck every one to see the video,asshole


    Comment posted on October 11, 2011 at 16:28:32 BST


  5. @saeid

    My code was published.


    Comment posted on October 11, 2011 at 21:13:10 BST

  6. aaa

    ax ad skf ael glejc n’wege0 j


    Comment posted on October 20, 2011 at 18:50:00 BST

  7. hamza

    who know what is this tool ?


    Comment posted on November 1, 2011 at 01:29:45 BST


  8. [...] for Linux and essentially looks for any passwords that are only letters. Originally called “WordPress Brute Force Tool,” this is a great tool to use for consulting purposes. By no means should this be used for [...]


    Comment posted on November 8, 2011 at 16:28:28 BST


  9. I think its best not to give out this code, you will end up with thousands of 13 year old
    little kids fucking with a lot of sites.

    Im now saying its better than some 30 year old but people that know how to make this kind of code dont use it often.

    More so people with the brains to put this together understand what it means to have built something and how hard it can be to build a full site.

    So at most they will rip off a few emails to blast or give there sites some links and call it good.

    KIDs on the other hand will try to mess up the site and could really hurt someones income.

    Just my $0.02


    Comment posted on December 12, 2011 at 23:32:56 BST


  10. Release the code dude!


    Comment posted on January 29, 2012 at 05:41:13 BST

  11. jpjhacker

    Hmmmmmm


    Comment posted on February 9, 2012 at 07:44:23 BST


  12. Wanna download the code


    Comment posted on March 7, 2012 at 10:06:30 BST

  13. Chrispy

    Probably a bad idea to release this code (as much as I’d enjoy using it).

    Too many people would fuck up too many site,
    and then how long before there’s a fix for it and your code is useless.

    Enjoy it for yourself.


    Comment posted on April 30, 2012 at 05:50:36 BST


  14. [...] “Wpscan“. The creator of this tool is ethicalhack3r and this is another creation built from WordPress Brute Force Tool. This tool comes pre-installed on this following [...]


    Comment posted on August 13, 2012 at 11:46:12 BST

Leave a Reply