URL: https://covocova.ru/ [2a03:6f00:1::5c35:60de] Started: Wed Jan 22 16:43:50 2025 Interesting Finding(s): Headers | Interesting Entry: Server: nginx/1.26.1 | Found By: Headers (Passive Detection) | Confidence: 100% robots.txt found: https://covocova.ru/robots.txt | Interesting Entries: | - /cgi-bin | - /xmlrpc.php | - /wp- | - */author | - */trackback | - */feed | - */attachment | - */embed | - *? | - *.inc$ | - *.php$ | - *utm= | - /cart/ | - /checkout/ | - /*add-to-cart=* | - /?s=* | - /my-account/ | - */uploads | - /*/*.js | - /*/*.css | - /wp-*.png | - /wp-*.jpg | - /wp-*.jpeg | - /wp-*.gif | - /wp-admin/admin-ajax.php | Found By: Robots Txt (Aggressive Detection) | Confidence: 100% XML-RPC seems to be enabled: https://covocova.ru/xmlrpc.php | Found By: Direct Access (Aggressive Detection) | Confidence: 100% | References: | - http://codex.wordpress.org/XML-RPC_Pingback_API | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner/ | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access/ WordPress readme found: https://covocova.ru/readme.html | Found By: Direct Access (Aggressive Detection) | Confidence: 100% This site has 'Must Use Plugins': https://covocova.ru/wp-content/mu-plugins/ | Found By: Direct Access (Aggressive Detection) | Confidence: 80% | Reference: http://codex.wordpress.org/Must_Use_Plugins Registration is enabled: https://covocova.ru/wp-login.php?action=register | Found By: Direct Access (Aggressive Detection) | Confidence: 100% The external WP-Cron seems to be enabled: https://covocova.ru/wp-cron.php | Found By: Direct Access (Aggressive Detection) | Confidence: 60% | References: | - https://www.iplocation.net/defend-wordpress-from-ddos | - https://github.com/wpscanteam/wpscan/issues/1299 No WPScan API Token given, as a result vulnerability data has not been output. You can get a free API token with 25 daily requests by registering at https://wpscan.com/register Finished: Wed Jan 22 16:44:43 2025 Requests Done: 33 Cached Requests: 5 Data Sent: 9.87 KB Data Received: 1.9 MB Memory used: 114.098 MB Elapsed time: 00:00:52 Scan Aborted: Max Scan Duration Reached WPScan API Token given, as a result vulnerability data has not been output. You can get a free API token with 25 daily requests by registering at https://wpscan.com/register Finished: Wed Jan 22 16:44:40 2025 Requests Done: 38 Cached Requests: 7 Data Sent: 10.775 KB Data Received: 2.056 MB Memory used: 173.363 MB Elapsed time: 00:00:47 Scan Aborted: Max Scan Duration Reached