Skip to content

xskullboyx/xmlrpc-hunt

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

8 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

xmlrpc-hunt

xmlrpc-hunt is simple tool for find XML-RPC Pingback DDoS Vulnerability. it can be used for bug bounty hunters for find XML-RPC Pingback DDoS Vulnerability and exploit.

What this tool doing?

*) first tool (xmlrpc-finder.sh) checks xmlrpc.php is enabled or not in all domains in "subdomains.txt" *) if yes, tool check for pingback.ping enabled or not.

Usage:


  1. list out all subdomain to text file "subdomains.txt"
  2. run bash xmlrpc-finder.sh
  3. run bash xmlrpc-ping-exploit.sh

similar h1 reports

https://hackerone.com/reports/325040 https://hackerone.com/reports/752073

About

bug bounty tool - xmlrpc-hunt

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages