A credential-collection toolkit dubbed TIKTOUK that combines WordPress reconnaissance, exposed-file harvesting, plugin credential decryption, and JavaScript secret scanning. The toolkit consists of two Python scripts, wp2s_poll.py and wp2s_crack.py, alongside a stripped Go-based Linux crawler named jscrawl-amd64. All three components retrieve targets from a central HTTP hub, execute assigned collection tasks, and submit status reports and […]
The post TIKTOUK WordPress Toolkit Could Enable AWS, SMTP and API Credential Theft Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Mayura Kathir
Source: gbHackers
Source Link: https://gbhackers.com/tiktouk-wordpress-toolkit/