aress31 / xmlrpc-bruteforcer

Multi-threaded XMLRPC brute forcer using amplification attacks targeting WordPress installations prior to version 4.4.
Apache License 2.0
116 stars 41 forks source link

Fails to find valid password #12

Open Whiterabbitz opened 2 years ago

Whiterabbitz commented 2 years ago

Hi - Not a python Guru.

If the password is the first in list - works OK Otherwise fails

If using the -c 1 option finds the correct password anywhere in list.

Was reported several years ago - but marked as fixed.

Testing on WP 6.6