Skip to main content

"Your WordPress site's best friend"

Project description

WordSmash

"Your WordPress site's best friend" - Nobody.

Telegram | Discord

Features

  • Automatically enumerates WordPress usernames
  • Scrapes email addresses
  • Support for dynamic, site-specific values in passwords
  • Checks email account credentials for performing password reset attack
  • Multithreded

Installation

Requires python 3.9 or later.

Install with pip:

pip install wordsmash

Install from GitHub:

pip install git+https://github.com/TheArchivist01/wordsmash.git

Options

--wordlist: List of sites to attempt accessing
--site-list: List of sites to attempt accessing
--dynamic-wordlist: Enable dynamic placeholder values in wordlist
--persist: Continue trying to find additional logins for a site after login success
--threads: Maximum number of sites to check in parallel

Dynamic Wordlist?

The dynamic wordlist feature allows you to use placeholder values in the wordlist. Currently a password can contain {username} or {domain}.

Example: Logging into examplesite.com as "admin"

{username}123       -> admin123
{domain}pass        -> examplesitepass
{username}@{domain} -> admin@examplesite

More from The Archivist 01

Telegram Discord

Additional credits

@ph03n1x69 for helping with the wordpress login test.

Disclaimer

WordSmasher is intended to be used for educational and research purposes.
The Archivist and other contributors are not responsible for damages caused by the use of this tool.

See the LICENSE file for more details.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

WordSmash-0.0.1.tar.gz (6.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

WordSmash-0.0.1-py3-none-any.whl (7.8 kB view details)

Uploaded Python 3

File details

Details for the file WordSmash-0.0.1.tar.gz.

File metadata

  • Download URL: WordSmash-0.0.1.tar.gz
  • Upload date:
  • Size: 6.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.1 CPython/3.10.5

File hashes

Hashes for WordSmash-0.0.1.tar.gz
Algorithm Hash digest
SHA256 1a60f00566c8849951ead99d733c462e1116171d1429b2ce125ecb64380a2fb6
MD5 ca9f9f6f03eff9b047939b0cc88b48d4
BLAKE2b-256 e615af7e57064022a13361243c31a54d642cebc986ab1933e84ad8701f0efdf0

See more details on using hashes here.

File details

Details for the file WordSmash-0.0.1-py3-none-any.whl.

File metadata

  • Download URL: WordSmash-0.0.1-py3-none-any.whl
  • Upload date:
  • Size: 7.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.1 CPython/3.10.5

File hashes

Hashes for WordSmash-0.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 142a04ecdc04f2667299a8ca9bc45a1c8ba5e78fbea20d88201be9b32146a7c5
MD5 7bdf49d00e1abf013dbbeff42b883090
BLAKE2b-256 873b50c83d0231a02836b4009aaa073e9063f725afbdc952724609b5065b8baa

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page