SlideShare a Scribd company logo
Wordpress Plugins Scanner


„To hack or not hack, that is the real question!“




  Avădănei Andrei
  Founder & CEO DefCamp
  linkedin.com/in/andreiavadanei
  twitter.com/AndreiAvadanei
Short bio

●   Founder & CEO of DefCamp … and CTO (tech), CFO (financial), CMO (marketing), Sales
    Manager, Community Manager, Speaker, Team Coordinator :))
●   Founder Cyber Security Research Center from Romania (CCSIR)
●   Community manager @worldit.info
●   Vice President at GREPIT
●   Volunteer at BitDefender Romania
●   ...
Once upon a time..

●   Somewhere in the www appeared HTML websites
          (bullshit)
●   Then web 2.0 websites took the lights
●   + third party plugins (hell yeah)
●   It was a wonderful time full of innovation and peace (>:D<)
●   Then came the hackers and seized a big opportunnity
●   But that is another story. >:)
Third-party apps


●   Some sort of crowd development
●   A good idea, poorly implemented
●   Used by everybody in different ways (Google, Facebook,
    Apple, Wordpress, Joomla, Vbulletin, Moodle ..)
●   Usually there is no security test for apps before being
    accepted in their market store
●   And there is the place where all magic starts
Case study : Wordpress

●   23,688 plugins
●   416,305,218 downloads
●   and counting
●   Not bad, right?
●   If we cannot break in the core, lets hack his chilldrens
●   And here WP Plugins Scanner come in
WP Plugins Scanner

●       White box pentesting tool
●       Hooked RIPS implemented
●       You can download plugins from WP directory
●       You can build some sort of repository on your localhost
●       Asynchronous scanning
●       Soon :
    –    target websites and enumerate their plugins
    –    subversioning for plugins
    –    auto-monitor updates
    –    cache-ing results
    –    similar scanners for Joomla, Vbulletin and others?
Demo
Questions? :-)
Thanks!




Avădănei Andrei
Founder & CEO DefCamp
linkedin.com/in/andreiavadanei
twitter.com/AndreiAvadanei
github.com/CCSIR/WP-Plugins-Scanner
Thanks!




Avădănei Andrei
Founder & CEO DefCamp
linkedin.com/in/andreiavadanei
twitter.com/AndreiAvadanei
github.com/CCSIR/WP-Plugins-Scanner

More Related Content

PDF
Women Who Mule - Workshop series #2: Ghost
PDF
Hinting at a better web
PDF
Web security 101
PDF
eZ Summer Camp 2014: interactive dive into ez product backlog
PDF
Android "Fight Club" : In pursuit of APPiness -- null Humla Delhi Chapter
PDF
We Economy - Drupalsouth
PPTX
Develop, Debug, Learn? - Dotjs2019
PDF
Seven ways to be a happier JavaScript developer - NDC Oslo
Women Who Mule - Workshop series #2: Ghost
Hinting at a better web
Web security 101
eZ Summer Camp 2014: interactive dive into ez product backlog
Android "Fight Club" : In pursuit of APPiness -- null Humla Delhi Chapter
We Economy - Drupalsouth
Develop, Debug, Learn? - Dotjs2019
Seven ways to be a happier JavaScript developer - NDC Oslo

Similar to Wordpress Plugins Scanner (20)

ODP
Build and Deploy a Python Web App to Amazon in 30 Mins
PDF
Байки із пожежного депо або як працює Big Data в Sigma Software, Денис Пишьєв,
PDF
Pentester++
PDF
Understanding and implementing website security
PDF
wp cli- don’t fear the command line
PPTX
Hacker vs company, Cloud Cyber Security Automated with Kubernetes - Demi Ben-...
PDF
WordCamp Milwaukee 2012 - Aaron Saray - Secure Wordpress Coding
PDF
My Tools for Success in WordPress
PDF
Tools to Save Time
PDF
Tooling Matters - Development tools
PPTX
Javascript Security - Three main methods of defending your MEAN stack
PDF
EMFcamp2022 - What if apps logged into you, instead of you logging into apps?
PDF
Year Zero
PDF
Codebits 2014 - Secure Coding - Gamification and automation for the win
PDF
Do WordPress developers write code?
PDF
Mobile backends with Google Cloud Platform (MBLTDev'14)
PDF
Hacking for fun & profit - The Kubernetes Way - Demi Ben-Ari - Panorays
PDF
Hacking for Innovation: IIT Kharagpur
PPTX
No Code Development.pptx
PDF
EuroPython 2011 - How to build complex web applications having fun?
Build and Deploy a Python Web App to Amazon in 30 Mins
Байки із пожежного депо або як працює Big Data в Sigma Software, Денис Пишьєв,
Pentester++
Understanding and implementing website security
wp cli- don’t fear the command line
Hacker vs company, Cloud Cyber Security Automated with Kubernetes - Demi Ben-...
WordCamp Milwaukee 2012 - Aaron Saray - Secure Wordpress Coding
My Tools for Success in WordPress
Tools to Save Time
Tooling Matters - Development tools
Javascript Security - Three main methods of defending your MEAN stack
EMFcamp2022 - What if apps logged into you, instead of you logging into apps?
Year Zero
Codebits 2014 - Secure Coding - Gamification and automation for the win
Do WordPress developers write code?
Mobile backends with Google Cloud Platform (MBLTDev'14)
Hacking for fun & profit - The Kubernetes Way - Demi Ben-Ari - Panorays
Hacking for Innovation: IIT Kharagpur
No Code Development.pptx
EuroPython 2011 - How to build complex web applications having fun?
Ad

More from Avădănei Andrei (11)

PPT
How you can become a hacker with no security experience
PDF
Honeypots - The Art of Building Secure Systems by Making them Vulnerable
PPT
DefCamp 2012 @Bucharest
ODP
A journey through an INFOSEC labyrinth
ODP
Polish the Wheel
PPT
Virtual Anonimity – What? Why? When? How?
PPT
SmartFender
PPT
SYDO - Secure Your Data by Obscurity
PPT
Xss is more than a simple threat
PPT
Arta de a susţine o prezentare
ODP
Spaghetti Code vs MVC
How you can become a hacker with no security experience
Honeypots - The Art of Building Secure Systems by Making them Vulnerable
DefCamp 2012 @Bucharest
A journey through an INFOSEC labyrinth
Polish the Wheel
Virtual Anonimity – What? Why? When? How?
SmartFender
SYDO - Secure Your Data by Obscurity
Xss is more than a simple threat
Arta de a susţine o prezentare
Spaghetti Code vs MVC
Ad

Wordpress Plugins Scanner

  • 1. Wordpress Plugins Scanner „To hack or not hack, that is the real question!“ Avădănei Andrei Founder & CEO DefCamp linkedin.com/in/andreiavadanei twitter.com/AndreiAvadanei
  • 2. Short bio ● Founder & CEO of DefCamp … and CTO (tech), CFO (financial), CMO (marketing), Sales Manager, Community Manager, Speaker, Team Coordinator :)) ● Founder Cyber Security Research Center from Romania (CCSIR) ● Community manager @worldit.info ● Vice President at GREPIT ● Volunteer at BitDefender Romania ● ...
  • 3. Once upon a time.. ● Somewhere in the www appeared HTML websites (bullshit) ● Then web 2.0 websites took the lights ● + third party plugins (hell yeah) ● It was a wonderful time full of innovation and peace (>:D<) ● Then came the hackers and seized a big opportunnity ● But that is another story. >:)
  • 4. Third-party apps ● Some sort of crowd development ● A good idea, poorly implemented ● Used by everybody in different ways (Google, Facebook, Apple, Wordpress, Joomla, Vbulletin, Moodle ..) ● Usually there is no security test for apps before being accepted in their market store ● And there is the place where all magic starts
  • 5. Case study : Wordpress ● 23,688 plugins ● 416,305,218 downloads ● and counting ● Not bad, right? ● If we cannot break in the core, lets hack his chilldrens ● And here WP Plugins Scanner come in
  • 6. WP Plugins Scanner ● White box pentesting tool ● Hooked RIPS implemented ● You can download plugins from WP directory ● You can build some sort of repository on your localhost ● Asynchronous scanning ● Soon : – target websites and enumerate their plugins – subversioning for plugins – auto-monitor updates – cache-ing results – similar scanners for Joomla, Vbulletin and others?
  • 9. Thanks! Avădănei Andrei Founder & CEO DefCamp linkedin.com/in/andreiavadanei twitter.com/AndreiAvadanei github.com/CCSIR/WP-Plugins-Scanner
  • 10. Thanks! Avădănei Andrei Founder & CEO DefCamp linkedin.com/in/andreiavadanei twitter.com/AndreiAvadanei github.com/CCSIR/WP-Plugins-Scanner