Skip to main content

web-cms-scanning

CMS-specific scans — WordPress (wpscan), Joomla, Drupal version detection.

跳到安装

来源信息

仓库
BitterSecurity/Decepticon
最近来源活动
2026年5月26日 15:19
检测到的 SKILL.md 语言
英语
星标
5,565
分支
1,053

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
web-cms-scanning
description
CMS-specific scans — WordPress (wpscan), Joomla, Drupal version detection.
allowed-tools
Bash Read Write
metadata
{"subdomain":"reconnaissance","when_to_use":"WordPress, wpscan, Joomla, Drupal, CMS scan, CMS detection","tags":"cms-scan, wpscan","mitre_attack":"T1592.004"}
# CMS-Specific Scanning Once tech fingerprinting (or HTML inspection) confirms a CMS, switch from generic discovery to CMS-aware tooling — version, plugins/themes, user enum, and CMS-specific RCE entry points. ## WordPress ```bash # wpscan (comprehensive) wpscan --url https://<target> --enumerate vp,vt,u,be --api-token <WP_API_TOKEN> # Quick checks curl -s "https://<target>/wp-json/wp/v2/users" | python3 -m json.tool curl -s "https://<target>/xmlrpc.php" -d '<methodCall><methodName>system.listMethods</methodName></methodCall>' curl -s "https://<target>/?author=1" -I | grep Location ``` ## Joomla ```bash # Version detection curl -s "https://<target>/administrator/manifests/files/joomla.xml" | grep -oP '<version>\K[^<]+' ``` ## Drupal ```bash curl -s "https://<target>/CHANGELOG.txt" | head -5 ```
在 GitHub 查看