[~] The config file is expected to be at "/root/.rustscan.toml" [!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers [!] Your file limit is very small, which negatively impacts RustScan's speed. Use the Docker image, or up the Ulimit with '--ulimit 5000'. Open 192.168.43.53:22 Open 192.168.43.53:80 [~] Starting Script(s) [~] Starting Nmap 7.95 ( https://nmap.org ) at 2026-04-14 08:13 EDT Initiating ARP Ping Scan at 08:13 Scanning 192.168.43.53 [1 port] Completed ARP Ping Scan at 08:13, 0.05s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 08:13 Completed Parallel DNS resolution of 1 host. at 08:13, 0.04s elapsed DNS resolution of 1 IPs took 0.05s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 08:13 Scanning 192.168.43.53 [2 ports] Discovered open port 80/tcp on 192.168.43.53 Discovered open port 22/tcp on 192.168.43.53 Completed SYN Stealth Scan at 08:13, 0.02s elapsed (2 total ports) Nmap scan report for 192.168.43.53 Host is up, received arp-response (0.00040s latency). Scanned at 2026-04-14 08:13:16 EDT for 0s
PORT STATE SERVICE REASON 22/tcp open ssh syn-ack ttl 64 80/tcp open http syn-ack ttl 64 MAC Address: 08:00:27:86:0E:78 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Read data files from: /usr/share/nmap Nmap done: 1 IP address (1 host up) scanned in 0.21 seconds Raw packets sent: 3 (116B) | Rcvd: 3 (116B)
WordPress Security Scanner by the WPScan Team Version 3.8.28 Sponsored by Automattic - https://automattic.com/ @_WPScan_, @ethicalhack3r, @erwan_lr, @firefart _______________________________________________________________
[i] It seems like you have not updated the database for some time. [+] URL: http://thefirstavenger.thl/wp1/ [192.168.43.53] [+] Started: Sun Apr 19 10:41:54 2026
[+] WordPress theme in use: twentytwentyfour | Location: http://thefirstavenger.thl/wp1/wp-content/themes/twentytwentyfour/ | Last Updated: 2025-12-03T00:00:00.000Z | Readme: http://thefirstavenger.thl/wp1/wp-content/themes/twentytwentyfour/readme.txt | [!] The version is out of date, the latest version is 1.4 | [!] Directory listing is enabled | Style URL: http://thefirstavenger.thl/wp1/wp-content/themes/twentytwentyfour/style.css | Style Name: Twenty Twenty-Four | Style URI: https://wordpress.org/themes/twentytwentyfour/ | Description: Twenty Twenty-Four is designed to be flexible, versatile and applicable to any website. Its collecti... | Author: the WordPress team | Author URI: https://wordpress.org | | Found By: Urls In Homepage (Passive Detection) | Confirmed By: Urls In 404 Page (Passive Detection) | | Version: 1.2 (80% confidence) | Found By: Style (Passive Detection) | - http://thefirstavenger.thl/wp1/wp-content/themes/twentytwentyfour/style.css, Match: 'Version: 1.2'
WordPress Security Scanner by the WPScan Team Version 3.8.28 Sponsored by Automattic - https://automattic.com/ @_WPScan_, @ethicalhack3r, @erwan_lr, @firefart _______________________________________________________________
[i] It seems like you have not updated the database for some time.
[+] XML-RPC seems to be enabled: http://thefirstavenger.thl/wp1/xmlrpc.php | Found By: Direct Access (Aggressive Detection) | Confidence: 100% | References: | - http://codex.wordpress.org/XML-RPC_Pingback_API | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner/ | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access/
[+] WordPress readme found: http://thefirstavenger.thl/wp1/readme.html | Found By: Direct Access (Aggressive Detection) | Confidence: 100%
[+] Upload directory has listing enabled: http://thefirstavenger.thl/wp1/wp-content/uploads/ | Found By: Direct Access (Aggressive Detection) | Confidence: 100%
[+] The external WP-Cron seems to be enabled: http://thefirstavenger.thl/wp1/wp-cron.php | Found By: Direct Access (Aggressive Detection) | Confidence: 60% | References: | - https://www.iplocation.net/defend-wordpress-from-ddos | - https://github.com/wpscanteam/wpscan/issues/1299
[+] WordPress version 6.6.2 identified (Insecure, released on 2024-09-10). | Found By: Rss Generator (Passive Detection) | - http://thefirstavenger.thl/wp1/index.php/feed/, <generator>https://wordpress.org/?v=6.6.2</generator> | - http://thefirstavenger.thl/wp1/index.php/comments/feed/, <generator>https://wordpress.org/?v=6.6.2</generator>
[+] WordPress theme in use: twentytwentyfour | Location: http://thefirstavenger.thl/wp1/wp-content/themes/twentytwentyfour/ | Last Updated: 2025-12-03T00:00:00.000Z | Readme: http://thefirstavenger.thl/wp1/wp-content/themes/twentytwentyfour/readme.txt | [!] The version is out of date, the latest version is 1.4 | [!] Directory listing is enabled | Style URL: http://thefirstavenger.thl/wp1/wp-content/themes/twentytwentyfour/style.css | Style Name: Twenty Twenty-Four | Style URI: https://wordpress.org/themes/twentytwentyfour/ | Description: Twenty Twenty-Four is designed to be flexible, versatile and applicable to any website. Its collecti... | Author: the WordPress team | Author URI: https://wordpress.org | | Found By: Urls In Homepage (Passive Detection) | Confirmed By: Urls In 404 Page (Passive Detection) | | Version: 1.2 (80% confidence) | Found By: Style (Passive Detection) | - http://thefirstavenger.thl/wp1/wp-content/themes/twentytwentyfour/style.css, Match: 'Version: 1.2'
[+] Enumerating All Plugins (via Passive Methods) [+] Checking Plugin Versions (via Passive and Aggressive Methods)
[i] Plugin(s) Identified:
[+] stop-user-enumeration | Location: http://thefirstavenger.thl/wp1/wp-content/plugins/stop-user-enumeration/ | Last Updated: 2025-12-15T10:48:00.000Z | [!] The version is out of date, the latest version is 1.7.7 | | Found By: Urls In Homepage (Passive Detection) | Confirmed By: Urls In 404 Page (Passive Detection) | | Version: 1.6.3 (100% confidence) | Found By: Query Parameter (Passive Detection) | - http://thefirstavenger.thl/wp1/wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js?ver=1.6.3 | Confirmed By: | Readme - Stable Tag (Aggressive Detection) | - http://thefirstavenger.thl/wp1/wp-content/plugins/stop-user-enumeration/readme.txt | Readme - ChangeLog Section (Aggressive Detection) | - http://thefirstavenger.thl/wp1/wp-content/plugins/stop-user-enumeration/readme.txt
[!] No WPScan API Token given, as a result vulnerability data has not been output. [!] You can get a free API token with 25 daily requests by registering at https://wpscan.com/register
steve@TheHackersLabs-Thefirstavenger:~$ chmod +x socat steve@TheHackersLabs-Thefirstavenger:~$ ls -al total 5704 drwxr-x--- 3 steve steve 4096 Apr 19 15:15 . drwxr-xr-x 3 root root 4096 Oct 7 2024 .. lrwxrwxrwx 1 steve steve 9 Oct 8 2024 .bash_history -> /dev/null drwx------ 2 steve steve 4096 Oct 14 2024 .cache lrwxrwxrwx 1 steve steve 9 Oct 8 2024 .mysql_history -> /dev/null -rwxrwxr-x 1 steve steve 975444 Jan 7 11:46 linpeas.sh -rwxrwxr-x 1 steve steve 4838312 Apr 29 2025 socat -rw-rw-r-- 1 steve steve 41 Oct 8 2024 user.txt -rw-rw-r-- 1 steve steve 992 Apr 19 15:14 wget-log steve@TheHackersLabs-Thefirstavenger:~$ ./socat TCP-LISTEN:8080,fork TCP:127.0.0.1:7092 & [2] 14494 [1] Exit 127 socat TCP-LISTEN:8080,fork TCP:127.0.0.1:7092