WPRecon 是一款基于Go构建的现代WordPress安全侦察工具,帮助安全工程师识别WordPress安装中的漏洞、错误配置和信息泄露问题。
与传统漏洞扫描器使用硬编码检查不同,WPRecon 采用 YAML驱动的模板架构,实现了:
| 特性 | 描述 |
|---|---|
| 并行扫描 | 可配置的工作池(默认:10个工作线程)用于并发请求 |
| 速率限制 | 内置请求节流(默认:50 req/s)以保持网络友好 |
| 自动重试 | 针对失败的HTTP请求的自动重试逻辑 |
| 热加载模板 | 无需重新编译 — 添加模板即可扫描 |
| 变量解析 | 动态变量:{{BaseURL}}、{{Timestamp}}、{{RandomInt}} |
| 多格式输出 | 人类可读的表格和结构化JSON |
| CLI与API模式 | 同时提供命令行和REST API接口 |
| 严重性等级 | 发现结果分类为:信息、低、中、高、严重 |
识别响应中的正面命中:
从匹配的响应中提取可操作的数据:
150+个生产级模板,涵盖:
# 克隆仓库
git clone https://github.com/ffx64/wprecon.git
cd wprecon
# 构建二进制文件
go build -o wprecon ./cmd/wprecon/main.go
# 移动到PATH(可选)
sudo mv wprecon /usr/local/bin/
go install github.com/ffx64/wprecon/cmd/wprecon@latest
docker build -t wprecon .
docker run wprecon scan https://example.com
使用所有可用模板扫描WordPress网站:
wprecon scan https://example.com
仅运行选中的模板:
wprecon scan https://example.com -t wordpress-detection,plugin-detection,user-enumeration
# JSON输出,适合自动化
wprecon scan https://example.com --output json
# 漂亮打印的表格(默认)
wprecon scan https://example.com --output table
# 使用20个并发工作线程,100请求/秒
wprecon scan https://example.com --workers 20 --rate-limit 100
wprecon list-templates
wprecon --help
运行扫描时,WPRecon会生成详细的发现结果:
表格格式:
ID | 模板 | 名称 | 严重性 | 目标 | 证据
---------------------|------------------------|--------------------------|----------|---------------------|----------
finding_001 | wordpress-version | WordPress版本已找到 | info | example.com | 6.2.1
finding_002 | plugin-detection | 检测到插件 | low | example.com | Yoast SEO 16.0
finding_003 | security-headers | 缺少安全头 | medium | example.com | X-Frame-Options
JSON格式:
{
"scan_id": "scan_uuid_001",
"timestamp": "2026-04-10T14:37:00Z",
"target": "https://example.com",
"total_findings": 15,
"findings": [
{
"id": "finding_uuid_001",
"template_id": "wordpress-detection",
"name": "检测到WordPress安装",
"description": "在目标上识别到WordPress CMS安装",
"severity": "info",
"cvss_score": 0.0,
"matched_url": "https://example.com/wp-admin/",
"http_method": "GET",
"status_code": 200,
"response_time_ms": 245,
"evidence": {
"version": "6.2.1",
"wp_version_header": "6.2.1"
},
"timestamp": "2026-04-10T14:37:00Z",
"remediation": "保持WordPress更新到最新版本"
}
]
}
wprecon/
├── cmd/wprecon/
│ └── main.go # CLI入口点
├── internal/
│ ├── app/
│ │ ├── cli.go # CLI命令处理器
│ │ └── api.go # REST API处理器
│ ├── engine/
│ │ ├── scanner.go # 扫描编排
│ │ ├── worker_pool.go # 并行化引擎
│ │ ├── context.go # 扫描上下文管理
│ │ ├── logger.go # 日志工具
│ │ └── rate_limit.go # 速率限制
│ ├── executor/
│ │ ├── http_executor.go # HTTP客户端
│ │ ├── request_builder.go # 请求构建
│ │ └── variables.go # 变量解析
│ ├── matchers/
│ │ └── matchers.go # 响应匹配逻辑
│ ├── extractors/
│ │ └── extractors.go # 数据提取
│ ├── templates/
│ │ ├── loader.go # 模板发现
│ │ └── parser.go # YAML解析
│ ├── pipeline/
│ │ └── pipeline.go # 扫描工作流
│ └── domain/
│ ├── template.go # 数据模型
│ ├── finding.go
│ ├── http.go
│ ├── matcher.go
│ └── extractor.go
├── templates/ # YAML模板库
│ ├── wordpress/ # WordPress专用
│ ├── cves/ # CVE检测
│ ├── exposures/ # 信息泄露
│ ├── common/ # 通用检查
│ └── waf/ # WAF检测
└── go.mod # 依赖管理
┌─────────────────────────────────────────────┐
│ 用户界面(CLI/API) │
└─────────────────────────────────────────────┘
│
├─→ 模板加载器
├─→ 速率限制器
└─→ 工作池管理器
│
▼
┌─────────────────────────────────────────────┐
│ 扫描流水线引擎 │
│ ┌────────→ 请求构建器 │
│ │ ┌────────→ HTTP执行器 │
│ │ │ ┌────────→ 匹配器(5种类型) │
│ │ │ │ ┌────────→ 提取器(2种类型) │
│ │ │ │ │ ┌────────→ 发现报告 │
│ │ │ │ │ │ │
│ ▼ ▼ ▼ ▼ ▼ │
│ 模板 → 请求 → 响应 → 发现 │
└─────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────┐
│ 输出格式化器与存储 │
│ (JSON、表格、报告生成) │
└─────────────────────────────────────────────┘
模板是YAML文件,定义了WPRecon如何扫描特定漏洞或信息。
id: wordpress-version-detection
name: WordPress版本检测
description: 从readme.html检测并提取WordPress版本
severity: info
author: WPRecon Team
requests:
- url: "{{BaseURL}}/readme.html"
method: GET
matchers:
- type: status
status:
- 200
- type: word
words:
- "WordPress"
extractors:
- type: regex
regex:
- 'Version (\d+\.\d+\.\d+)'
| 模板 | 用途 |
|---|---|
wordpress-detection | 检测WordPress安装 |
wordpress-version | 指纹识别WordPress版本 |
plugins.yaml | 检测已安装插件 |
themes.yaml | 检测已安装主题 |
users.yaml | 枚举WordPress用户 |
templates/custom/ 下创建新的YAML文件示例:
# 创建自定义模板
cat > templates/custom/my-check.yaml << 'EOF'
id: my-custom-check
name: 我的自定义检查
description: 检测自定义漏洞
severity: medium
author: Your Name