Hallo, ich habe mir mal den Spass erlaubt meine eigene Webseite mit WP-Scan abzutasten.
Was kann ich nun daraus auslesen bzw. wie kann ich die Sicherheit meiner Wordpress Webseite erhöhen.
Danke voraus.
Code
Interesting Finding(s):
[+] Headers
| Interesting Entries:
| - Server: Apache
| - Referrer-Policy: no-referrer, same-origin
| - Feature-Policy: vibrate 'self'; camera 'none'; microphone 'none'; usb 'none'; autoplay 'none'
| - Content-Security-Policy: object-src 'self';base-uri 'self';frame-ancestors 'self';form-action 'self';frame-src https://domainxxx.com https://*.domainxxx.com https://www.youtube.com https://*.google.com;
| - Upgrade: h2,h2c
| - X-Powered-By: PleskLin
| Found By: Headers (Passive Detection)
| Confidence: 100%
[+] robots.txt found: https://www.domain-example.de/robots.txt
| Found By: Robots Txt (Aggressive Detection)
| Confidence: 100%
[+] WordPress readme found: https://www.domain-example.de/readme.html
| Found By: Direct Access (Aggressive Detection)
| Confidence: 100%
[+] A backup directory has been found: https://www.domain-example.de/wp-content/backup-db/
| Found By: Direct Access (Aggressive Detection)
| Confidence: 70%
| Reference: https://github.com/wpscanteam/wpscan/issues/422
[+] This site has 'Must Use Plugins': https://www.domain-example.de/wp-content/mu-plugins/
| Found By: Direct Access (Aggressive Detection)
| Confidence: 80%
| Reference: http://codex.wordpress.org/Must_Use_Plugins
[+] The external WP-Cron seems to be enabled: https://www.domain-example.de/wp-cron.php
| Found By: Direct Access (Aggressive Detection)
| Confidence: 60%
| References:
| - https://www.iplocation.net/defend-wordpress-from-ddos
| - https://github.com/wpscanteam/wpscan/issues/1299
[+] WordPress version 5.5.1 identified (Latest, released on 2020-09-01).
| Found By: Rss Generator (Aggressive Detection)
| - https://www.domain-example.de/feed/, <generator>https://wordpress.org/?v=5.5.1</generator>
| - https://www.domain-example.de/comments/feed/, <generator>https://wordpress.org/?v=5.5.1</generator>
[+] WordPress theme in use: twentyfifteen-child
| Location: https://www.domain-example.de/wp-content/themes/twentyfifteen-child/
| Style URL: https://www.domain-example.de/wp-content/themes/twentyfifteen-child/style.css
|
| Found By: Urls In Homepage (Passive Detection)
| Confirmed By: Urls In 404 Page (Passive Detection)
|
| The version could not be determined.
[+] Enumerating All Plugins (via Passive Methods)
[i] No plugins Found.
[+] Enumerating Config Backups (via Passive and Aggressive Methods)
Checking Config Backups - Time: 00:00:00 <======================================> (21 / 21) 100.00% Time: 00:00:00
[i] No Config Backups Found.
Alles anzeigen