{"id":13549881,"url":"https://github.com/delvelabs/vane","last_synced_at":"2025-04-02T23:31:24.788Z","repository":{"id":26237296,"uuid":"29684139","full_name":"delvelabs/vane","owner":"delvelabs","description":"A GPL fork of the popular wordpress vulnerability scanner WPScan","archived":true,"fork":false,"pushed_at":"2019-08-23T13:58:54.000Z","size":34677,"stargazers_count":211,"open_issues_count":3,"forks_count":63,"subscribers_count":25,"default_branch":"master","last_synced_at":"2024-11-03T19:37:21.462Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Ruby","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":"duydo/python-mapzen","license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/delvelabs.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2015-01-22T15:04:09.000Z","updated_at":"2024-08-30T09:07:04.000Z","dependencies_parsed_at":"2022-08-26T06:12:45.347Z","dependency_job_id":null,"html_url":"https://github.com/delvelabs/vane","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/delvelabs%2Fvane","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/delvelabs%2Fvane/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/delvelabs%2Fvane/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/delvelabs%2Fvane/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/delvelabs","download_url":"https://codeload.github.com/delvelabs/vane/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":246910955,"owners_count":20853652,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T12:01:26.608Z","updated_at":"2025-04-02T23:31:19.780Z","avatar_url":"https://github.com/delvelabs.png","language":"Ruby","funding_links":[],"categories":["Ruby"],"sub_categories":[],"readme":"# Vane\n\nVane is a GPL fork of the now non-free popular WordPress vulnerability scanner WPScan.\n\nPlease note that the WPScan team does not bear any responsibility for anything in this\nprogram.\n\n## LICENSE\n\nVane - A WordPress vulnerability scanner\n\nCopyright (C) 2012-2015 WPScan Team\nCopyright (C) 2015 Delve Labs inc.\n\nThis program is free software: you can redistribute it and/or modify\nit under the terms of the GNU General Public License as published by\nthe Free Software Foundation, either version 3 of the License, or\n(at your option) any later version.\n\nThis program is distributed in the hope that it will be useful,\nbut WITHOUT ANY WARRANTY; without even the implied warranty of\nMERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the\nGNU General Public License for more details.\n\nYou should have received a copy of the GNU General Public License\nalong with this program.  If not, see \u003chttp://www.gnu.org/licenses/\u003e.\n\n\n## INSTALL\n\n### Prerequisites\n\n   * Windows not supported\n   * Ruby =\u003e 1.9\n   * RubyGems\n   * Git\n\n## Run with docker\n\nUseful if you do not want to pollute your local environment with ruby gems.\n\n    docker build -t vane .\n    docker run --rm vane --help\n\n## Installing on Debian/Ubuntu\n\n    sudo apt-get install libcurl4-gnutls-dev libopenssl-ruby libxml2 libxml2-dev libxslt1-dev ruby-dev\n    git clone https://github.com/delvelabs/vane.git\n    cd vane\n    sudo gem install bundler \u0026\u0026 bundle install --without test development\n\n## Installing on Fedora\n\n    sudo yum install libcurl-devel\n    git clone https://github.com/delvelabs/vane.git\n    cd vane\n    sudo gem install bundler \u0026\u0026 bundle install --without test development\n\n## Installing on Archlinux\n\n    pacman -Sy ruby\n    pacman -Sy libyaml\n\n    git clone https://github.com/delvelabs/vane.git\n    cd vane\n    sudo gem install bundler \u0026\u0026 bundle install --without test development\n\n    gem install typhoeus\n    gem install nokogiri\n\n## Installing on Mac OS X\n\n    git clone https://github.com/delvelabs/vane.git\n    cd vane\n    sudo gem install bundler \u0026\u0026 bundle install --without test development\n\n## KNOWN ISSUES\n\n### Typhoeus segmentation fault\nUpdate cURL to version =\u003e 7.21 (may have to install from source)\nSee http://code.google.com/p/vane/issues/detail?id=81\n\n### Proxy not working\nUpdate cURL to version =\u003e 7.21.7 (may have to install from source).\n\nInstallation from sources :\n  - Grab the sources from http://curl.haxx.se/download.html\n  - Decompress the archive\n  - Open the folder with the extracted files\n  - Run `./configure`\n  - Run `make`\n  - Run `sudo make install`\n  - Run `sudo ldconfig`\n\n### cannot load such file -- readline\nRun `sudo aptitude install libreadline5-dev libncurses5-dev`\n\nThen, open the directory of the readline gem (you have to locate it)\n\n    cd ~/.rvm/src/ruby-1.9.2-p180/ext/readline\n    ruby extconf.rb\n    make\n    make install\n\nSee http://vvv.tobiassjosten.net/ruby-on-rails/fixing-readline-for-the-ruby-on-rails-console/ for more details\n\n\n\n## VANE ARGUMENTS\n\n--update   Update to the latest revision\n\n--url   | -u \u003ctarget url\u003e  The WordPress URL/domain to scan.\n\n--force | -f Forces WPScan to not check if the remote site is running WordPress.\n\n--enumerate | -e [option(s)]  Enumeration.\n  option :\n    u        usernames from id 1 to 10\n    u[10-20] usernames from id 10 to 20 (you must write [] chars)\n    p        plugins\n    vp       only vulnerable plugins\n    ap       all plugins (can take a long time)\n    tt       timthumbs\n    t        themes\n    vp       only vulnerable themes\n    at       all themes (can take a long time)\n  Multiple values are allowed : '-e tt,p' will enumerate timthumbs and plugins\n  If no option is supplied, the default is 'vt,tt,u,vp'\n\n--exclude-content-based '\u003cregexp or string\u003e'  Used with the enumeration option, will exclude all occurrences based on the regexp or string supplied\n                                              You do not need to provide the regexp delimiters, but you must write the quotes (simple or double)\n\n--config-file | -c \u003cconfig file\u003e Use the specified config file\n\n--follow-redirection  If the target url has a redirection, it will be followed without asking if you wanted to do so or not\n\n--wp-content-dir \u003cwp content dir\u003e  WPScan try to find the content directory (ie wp-content) by scanning the index page, however you can specified it. Subdirectories are allowed\n\n--wp-plugins-dir \u003cwp plugins dir\u003e  Same thing than --wp-content-dir but for the plugins directory. If not supplied, WPScan will use wp-content-dir/plugins. Subdirectories are allowed\n\n--proxy \u003c[protocol://]host:port\u003e  Supply a proxy (will override the one from conf/browser.conf.json).\n                                  HTTP, SOCKS4 SOCKS4A and SOCKS5 are supported. If no protocol is given (format host:port), HTTP will be used\n\n--proxy-auth \u003cusername:password\u003e  Supply the proxy login credentials (will override the one from conf/browser.conf.json).\n\n--basic-auth \u003cusername:password\u003e  Set the HTTP Basic authentication\n\n--wordlist | -w \u003cwordlist\u003e  Supply a wordlist for the password bruter and do the brute.\n\n--threads  | -t \u003cnumber of threads\u003e  The number of threads to use when multi-threading requests. (will override the value from conf/browser.conf.json)\n\n--username | -U \u003cusername\u003e  Only brute force the supplied username.\n\n--help     | -h This help screen.\n\n--verbose  | -v Verbose output.\n\n## VANE EXAMPLES\n\nDo 'non-intrusive' checks...\n\n    ruby vane.rb --url www.example.com\n\nDo wordlist password brute force on enumerated users using 50 threads...\n\n    ruby vane.rb --url www.example.com --wordlist darkc0de.lst --threads 50\n\nDo wordlist password brute force on the 'admin' username only...\n\n    ruby vane.rb --url www.example.com --wordlist darkc0de.lst --username admin\n\nEnumerate installed plugins...\n\n    ruby vane.rb --url www.example.com --enumerate p\n\n## VANETOOLS ARGUMENTS\n\n    --help    | -h   This help screen.\n    --Verbose | -v   Verbose output.\n    --update  | -u   Update to the latest revision.\n    --generate_plugin_list [number of pages]  Generate a new data/plugins.txt file. (supply number of *pages* to parse, default : 150)\n    --gpl  Alias for --generate_plugin_list\n    --check-local-vulnerable-files | --clvf \u003clocal directory\u003e  Perform a recursive scan in the \u003clocal directory\u003e to find vulnerable files or shells\n\n## VANETOOLS EXAMPLES\n\nGenerate a new 'most popular' plugin list, up to 150 pages ...\n\n    ruby vanetools.rb --generate_plugin_list 150\n\nLocally scan a WordPress installation for vulnerable files or shells :\n\n    ruby vanetools.rb --check-local-vulnerable-files /var/www/wordpress/\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdelvelabs%2Fvane","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdelvelabs%2Fvane","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdelvelabs%2Fvane/lists"}