Web Discovery
Last updated
Last updated
ApacheTomcatScanner: A python script to scan for Apache Tomcat server vulnerabilities.
bypass-cf: This tool is a simple bypass for a website running Cloudflare by finding the Origin IP of the domain. By doing so we are able to access the website without going trough Cloudflare's IP.
dirsearch: Dirsearch is a mature command-line tool designed to brute force directories and files in webservers.
feroxbuster: A simple, fast, recursive content discovery tool written in Rust.
kiterunner: Contextual Content Discovery Tool. Kiterunner is a tool that is capable of not only performing traditional content discovery at lightning fast speeds, but also bruteforcing routes/endpoints in modern applications.
CMSmap: CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs. The main purpose of CMSmap is to integrate common vulnerabilities for different types of CMSs in a single tool.
droopescan: A plugin-based scanner that aids security researchers in identifying issues with several CMS (SilverStripe, WordPress, Drupal).
drupwn: Drupwn claims to provide an efficient way to gather drupal information.
magescan: The idea behind this is to evaluate the quality and security of a Magento site you don't have access to. The scenario when you're interviewing a potential developer or vetting a new client and want to have an idea of what you're getting into.
moodlescan: Tool for scan vulnerabilities in Moodle platforms.
wpscan: WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites.
IIS-ShortName-Scanner: The latest version of scanner for IIS short file name (8.3) disclosure vulnerability by using the tilde (~) character.
relative-url-extractor: During reconnaissance (recon) it is often helpful to get a quick overview of all the relative endpoints in a file.
XSStrike: Most advanced XSS scanner.
xsscrapy: XSS spider - 66/66 wavsep XSS detected.
dalfox: DalFox(Finder Of XSS) / Parameter Analysis and XSS Scanning tool based on golang.
nginxpwner: Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.