Webshag a open web server audit tool multi-threaded, multi-platform written in Python, it gathers commonly useful functionalities for web server auditing like website crawling, URL scanning or file fuzzing.

Webshag supports both http and https , it can also be used through proxy. In addition to that it proposes innovative IDS evasion functionalities aimed at making correlation between request more complicated. you can use multiple proxy to make thing complicated for IDS or IPS.

Click To enlarge

Webshag URL scanner and file fuzzer are aimed at reducing the number of false positives and thus producing cleaner result sets. For this purpose, webshag implements a web page fingerprinting mechanism resistant to content changes. This fingerprinting mechanism is then used in a false positive removal algorithm specially aimed at dealing with “soft 404″ server responses. Webshag provides a full featured and intuitive graphical user interface as well as a text-based command line interface and is available for Linux and Windows platforms, under GPL license

Requirements

- Python 2.5 or Python 2.6 (NOT compatible with Python 3.0)
- wxPython 2.8.9.0 (or greater) GUI toolkit
- Nmap port scanner (for port scanning module only)
- A valid Live Search AppID (for domain information module only)

Download Webshag

Linux

Windows

Related Blogs

Random Posts

  • March 13, 2010 -- CVE-2010-0188.py.txt
    Adobe PDF LibTiff integer overflow code execution exploit that affects versions 8.3.0 and below and ...
  • March 10, 2010 -- uebimiauwebmail-disclose.txt
    Uebimiau Webmail version 3.2.0-2.0 suffers from a remote email disclosure vulnerability....
  • March 28, 2010 -- UPDATE: keykeriki v2
    We have talked about keykeriki in detail Here keykeriki is updated and ready for action.Pra...
  • August 8, 2010 -- iKAT: The Interactive Kiosk Attack Tool for all!
    Designed as a SaaS, iKAT features many methods of escaping out of a browser jailed environment and g...
  • January 14, 2010 -- WebCruiser – A Web Vulnerability Scanner!
    Webcruiser is a Web Vulnerability Scanner which perform basic and some advance scanning good thing i...
  • March 12, 2010 -- joomlagigfe-sql.txt
    The Joomla Gigfe component suffers from a remote SQL injection vulnerability....
  • April 6, 2010 -- ZDI-CAN-674: Novell
    A Medium severity vulnerability discovered by 'Francis Provencher' was reported to the affected vend...
  • May 19, 2010 -- UPDATE: Metasploit Framework 3.4.0!
    The Metasploit Framework has been updated to version 3.4.0 after almost four months now! Considering...
  • August 18, 2010 -- UPDATE: WhatWeb v0.4.5!
    We originally wrote about WhatWeb in our previous post here. It has now been updated to WhatWeb ve...

Comments on this entry are closed.

Previous post:

Next post: