Hi, i'm not gonna talk about something super new. ya people know, wordfence always publishes new vulnerabilities. so, if a site has an outdated plugin wich is vulnerable, it can be hacked without any effort. but, the fact is, i'm not talking about a bug hunting tool. this is a black hat tool. for doing these attacks on a target server, it needs to have those plugins isntalled and outdated. this tool doesn't target a specipic site. this targets vulnerable sites accross a whole list.
for example, if we could scan all the wordress websites, and find active plugins and their vertions, and from that we get sites with outdated plugins. we can further make it to filterout sites mwith outdated plugins which has proven security issues. display sites name, plugin, vertions, latest vertion, identified security issue, CVE. so, the attacker can attack these sites (maybe bulk attack using another specialized script) to gain acces. use cases - for fun, for making botnets, for bruit forcing pins and passwords which hanbs't an expiration time, .. or even for owning a whole website, for financial fraud,...
I alredy made a simple tool for detecting active plugins and their currect versions. now,m i need a list of sites, i can't crawl whole minternet. so, i think it is better to test with about 1000 sites ( a list). need help in how to get such a site list, ..
making this tools for YCS competition 2026 (next year) and Hackxjr hackathon. idk if they will throw me out or do what. I just need a merit certificate,lol
if this is illgeal and violate terms of elakiri, law, please tell me. this wool will be for educational purposes and i'm pretyy sure someone will make this before me, as it has an easy logic which can be made even using chatgpt
soyyry for english.,
tell me if I should remove this post, or make the tool? do you think i may even get a merit pass in hackathon?
@hacker T @hackerj @Nadun26 @clumsyhulk @emoji diaries @rukshrulz I saw you people have some software knowladge. so, please let me know. do you have any other hackathon ideas?
------ Post added on Oct 15, 2025 at 12:01 PM
for example, if we could scan all the wordress websites, and find active plugins and their vertions, and from that we get sites with outdated plugins. we can further make it to filterout sites mwith outdated plugins which has proven security issues. display sites name, plugin, vertions, latest vertion, identified security issue, CVE. so, the attacker can attack these sites (maybe bulk attack using another specialized script) to gain acces. use cases - for fun, for making botnets, for bruit forcing pins and passwords which hanbs't an expiration time, .. or even for owning a whole website, for financial fraud,...
I alredy made a simple tool for detecting active plugins and their currect versions. now,m i need a list of sites, i can't crawl whole minternet. so, i think it is better to test with about 1000 sites ( a list). need help in how to get such a site list, ..
making this tools for YCS competition 2026 (next year) and Hackxjr hackathon. idk if they will throw me out or do what. I just need a merit certificate,lol
if this is illgeal and violate terms of elakiri, law, please tell me. this wool will be for educational purposes and i'm pretyy sure someone will make this before me, as it has an easy logic which can be made even using chatgpt
soyyry for english.,
tell me if I should remove this post, or make the tool? do you think i may even get a merit pass in hackathon?
@hacker T @hackerj @Nadun26 @clumsyhulk @emoji diaries @rukshrulz I saw you people have some software knowladge. so, please let me know. do you have any other hackathon ideas?
------ Post added on Oct 15, 2025 at 12:01 PM