• XSS.stack #1 – первый литературный журнал от юзеров форума

Web WP Rest Api Disclosure of Admin / Authors Username [Username Enumeration]

WujingKlaus

(L1) cache
Пользователь
Регистрация
05.05.2020
Сообщения
527
Реакции
33
Гарант сделки
2
By default most Wordpress admin username is set to admin , but if not and your targetted wordpress site is does not restrict users from accessing parts of the site.
(no 403 protection)
You can mostly find the author / admin username here .
then try the names on wp-login.php with invalid password for accurate response ..
if username exist response will be ( invalid password for the user .)
 
By default most Wordpress admin username is set to admin , but if not and your targetted wordpress site is does not restrict users from accessing parts of the site.
(no 403 protection)
You can mostly find the author / admin username here .
then try the names on wp-login.php with invalid password for accurate response ..
if username exist response will be ( invalid password for the user .)
Holy crap it works! Cool tip! Some WordPress sites disallow it though, but just check their subdomains trolololo.
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх