{"id":34640,"date":"2015-02-24T13:16:35","date_gmt":"2015-02-24T13:16:35","guid":{"rendered":"https:\/\/wordpress.org\/plugins-wp\/wordstress\/"},"modified":"2018-03-28T10:47:15","modified_gmt":"2018-03-28T10:47:15","slug":"wordstress","status":"closed","type":"plugin","link":"https:\/\/da.wordpress.org\/plugins\/wordstress\/","author":14255016,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.7.0","stable_tag":"trunk","tested":"4.2.0","requires":"3.0.0","requires_php":"","requires_plugins":"","header_name":"wordstress","header_author":"Paolo Perego","header_description":"","assets_banners_color":"","last_updated":"2018-03-28 10:47:15","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/www.paypal.com\/cgi-bin\/webscr?cmd=_s-xclick&hosted_button_id=6AYKJFX87UFGW","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/wordstress","header_author_uri":"http:\/\/wordstress.org","rating":5,"author_block_rating":0,"active_installs":10,"downloads":1031,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":[],"upgrade_notice":[],"ratings":{"1":0,"2":0,"3":0,"4":0,"5":"1"},"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":[],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[67173,600,67175,8645,67174],"plugin_category":[54],"plugin_contributors":[91086],"plugin_business_model":[],"class_list":["post-34640","plugin","type-plugin","status-closed","hentry","plugin_tags-penetration-test","plugin_tags-security","plugin_tags-security-assessment","plugin_tags-security-scan","plugin_tags-wapt","plugin_category-security-and-spam-protection","plugin_contributors-thesp0nge","plugin_committers-thesp0nge"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/wordstress.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p><a href=\"https:\/\/rubygems.org\/gems\/wordstress\">wordstress<\/a> is a whitebox\nsecurity scanner for wordpress powered websites.<\/p>\n\n<p>Site owners don't want to spend time in reading complex blackbox security scan\nreports trying to remove false positives. A useful security tool must give them\nonly vulnerabilities really affecting installed plugins or themes.<\/p>\n\n<p>Let's assume, plugin <code>foobar_plugin<\/code> version 3.4.3 has a sever SQL Injection\nvulnerability. In one of several wordpress powered website, you installed\nversion 3.2.1 version that <strong>is not vulnerable<\/strong>.<\/p>\n\n<p>A blackbox security scanner will try to enumerate installed plugins but it\ncan't tell the exact installed version. So, using a blackbox approach you'll\nhave a alleged SQL Injection vulnerability you must validate and mitigate.\nUnfortunately, you will lose precious time to spot a false positive since your\nplugin is safe.<\/p>\n\n<p>With wordstress plugin, you'll give <a href=\"https:\/\/rubygems.org\/gems\/wordstress\">the security\ntool<\/a> the exact <code>foobar_plugin<\/code> version\ninstalled on the system, 3.2.1. The tool will scan the knowledge base and\nreport 0 vulnerabilities. You save time and you can be focused only on stuff\nreally need your attention.<\/p>\n\n<p>Of course you may argue that giving on the Internet a place where all your\nwebsite third parties plugins and themes name with version is not a wise\ndecision. This is correct, that's why wordstress plugin creates a secure access\nkey the scanner must use in order to access \/wordstress virtual page.<\/p>\n\n<p>People without the correct key can't access your website information. The key\nis unique per server and created with hashing functions so to be resilient to\nguessing account. Bruteforcing the key will lead to an unsuccessful attempt,\nand you'll be busted. For sure.<\/p>\n\n<p>You must pass the correct key value to wordstress ruby gem in order to perform\nthe whitebox scan. If you provide the wrong key or you won't provide a key at\nall, the wordstress plugin will give no information as output and then no\nwhitebox scan will be possible.<\/p>\n\n<p>You don't like the key? Just reload the page a couple of times since you're\ncomfortable about the generated entropy and then save the settings.<\/p>\n\n<!--section=installation-->\n<p>To install wordstress we must do the following:<\/p>\n\n<ol>\n<li>As a preliminary step you may want to install on your laptop (or somewhere)\nthe wordstress ruby scanner. You need a working ruby environment, please ask\nyour preferred search engine if you need instructions on how to setup ruby on\nyour operating system. Installing wordstress security scanner is\nstraightforwardly easy: <code>gem install wordstress<\/code>.<\/li>\n<li>download wordstress.zip and unpack the content to your\n  \/wp-content\/plugins\/ directory<\/li>\n<li>activate the plugin through the 'Plugins' menu in WordPress<\/li>\n<li>navigate the Settings-&gt;Wordstress admin page<\/li>\n<li>every time you enter wordstress setting page, a new key is automagically\ngenerated, to increase entropy you may want to reload the page a couple of\ntimes. When you're comfortable with the generated key, press the \"Save Changes\"\nbutton.\nThe virtual page is now available at the url http:\/\/youblogurl\/wordstress?worstress-key=the_key<\/li>\n<li>from the command line, use wordstress security scanner this way:\nworstress -u http:\/\/yourblogurl\/wordstress -k the_key<\/li>\n<li>enjoy results<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt>Installation Instructions<\/dt>\n<dd><p>To install wordstress we must do the following:<\/p>\n\n<ol>\n<li>As a preliminary step you may want to install on your laptop (or somewhere)\nthe wordstress ruby scanner. You need a working ruby environment, please ask\nyour preferred search engine if you need instructions on how to setup ruby on\nyour operating system. Installing wordstress security scanner is\nstraightforwardly easy: <code>gem install wordstress<\/code>.<\/li>\n<li>download wordstress.zip and unpack the content to your\n  \/wp-content\/plugins\/ directory<\/li>\n<li>activate the plugin through the 'Plugins' menu in WordPress<\/li>\n<li>navigate the Settings-&gt;Wordstress admin page<\/li>\n<li>every time you enter wordstress setting page, a new key is automagically\ngenerated, to increase entropy you may want to reload the page a couple of\ntimes. When you're comfortable with the generated key, press the \"Save Changes\"\nbutton.\nThe virtual page is now available at the url http:\/\/youblogurl\/wordstress?worstress-key=the_key<\/li>\n<li>from the command line, use wordstress security scanner this way:\nworstress -u http:\/\/yourblogurl\/wordstress -k the_key<\/li>\n<li>enjoy results<\/li>\n<\/ol><\/dd>\n<dt>Do I need this?<\/dt>\n<dd><p>Well, the short answer is... <strong>yes<\/strong>. <a href=\"https:\/\/wordpress.org\">WordPress<\/a> is a\nhuge and popular platform and there are tons of plugins released every day.\nThere are also dailiy released security issues affecting those tiny php scripts\nthat may have a huge impact on thousands of websites out there; even yours.<\/p>\n\n<p>So, yes, you <strong>do<\/strong> need a scheduled security scan over your websites.\nwordstress is here to give you just the security issues you really have to\nmitigate, no false positives, no waste of time.<\/p><\/dd>\n<dt>How do I change the API Key?<\/dt>\n<dd><p>In order to change the API key, you have just to reload the wordstress plugin\nsettings page and save the changes.<\/p><\/dd>\n<dt>Why do I need this plugin?<\/dt>\n<dd><p>Unlike <a href=\"http:\/\/wpscan.org\/\">wpscan<\/a> or other blackbox security scanners,\n<a href=\"https:\/\/rubygems.org\/gems\/wordstress\">wordstress<\/a> uses a whitebox approach\nwhen scanning a wordpress powered website. The idea behind wordstress is to\nhave a 100% false positives free scan and in order to do this, we can't rely on\nbruteforce or guessing to enumerate plugins or themes.<\/p>\n\n<p><a href=\"https:\/\/rubygems.org\/gems\/wordstress\">wordstress<\/a> is intended to be used by\nsysadmin or people authorized to scan a site, so whitebox approach is the best\noption we have. With the list of installed plugins and themes, their version\nnumber and their active\/inactive status,\n<a href=\"https:\/\/rubygems.org\/gems\/wordstress\">wordstress<\/a> can give site owners the\nexact status of the vulnerabilities they have to patch.<\/p><\/dd>\n<dt>Will wordstress harm my website?<\/dt>\n<dd><p>Not at all. <a href=\"https:\/\/rubygems.org\/gems\/wordstress\">wordstress<\/a> will get the\nvirtual page on your website and it will found there all the information needed\nto give you a whitebox security scan. In future scanner versions there will be\nsupport for robots.txt inspection, but at your site it will be just some HTTP\nGETs.<\/p><\/dd>\n<dt>Can BAD guys access the virtual page content?<\/dt>\n<dd><p>No. You choose the key you in the setting page. The key is generated hashing\nsome information about your website, a couple of timestamps and a couple of\npseudo randomic number.\nIn order to guess the key, an attacker must bruteforce a 39 alphanumeric string\nand it will take a <strong>lot<\/strong> of attempts.<\/p>\n\n<p>Without the key, the virtual page shows empty content. No information is given\nwithout the correct key.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.7<\/h4>\n\n<ul>\n<li>Change in internal endsWith routine to avoid warning about offset not present\nin strpos() call.<\/li>\n<li>Improved layout of plugin settings. A lot of people were confused about the\ncurrent key and the newly generated one, and a lot of them overwrites the\ncurrent value by mistake. Now instructions should be more readable.<\/li>\n<\/ul>\n\n<h4>0.6<\/h4>\n\n<ul>\n<li>First public version<\/li>\n<\/ul>","raw_excerpt":"wordstress is a whitebox security scanner for wordpress powered websites.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/da.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/34640","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/da.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/da.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/da.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=34640"}],"author":[{"embeddable":true,"href":"https:\/\/da.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/thesp0nge"}],"wp:attachment":[{"href":"https:\/\/da.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=34640"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/da.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=34640"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/da.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=34640"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/da.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=34640"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/da.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=34640"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/da.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=34640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}