Web Hack List

Collected research

Using WordPress as a intranet and internet port scanner

FireFart/WordpressPingbackPortScanner

A Ruby tool that turns WordPress blogs into port scanners. The Pingback API, exposed over XML-RPC, makes the blog server fetch an attacker-supplied URL, so responses reveal whether a host and port are open behind the firewall. It scans a target through one blog or spreads a single target's scan across many blogs; WordPress 3.5.1 fixed the issue.

Record

Document
FireFart/WordpressPingbackPortScanner
Published by
GitHub
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of GitHub, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .