WAScan – Web Application Scanner

wascan

WAScan ((W)eb (A)pplication (Scan)ner) is a Open Source web application security scanner. It is designed to find various vulnerabilities using “black-box” method, that means it won’t study the source code of web applications but will work like a fuzzer, scanning the pages of the deployed web application, extracting links and forms and attacking the scripts, sending payloads and looking for error messages,..etc. WAScan is built on python2.7 and can run on any platform which has a Python environment.

Features:

Fingerprint
[*]Content Management System (CMS) -> 6
[*]Web Frameworks -> 22
[*]Cookies/Headers Security
[*]Languages -> 9
[*]Operating Systems (OS) -> 7
[*]Server -> ALL
[*]Web App Firewall (WAF) -> 50+

Attacks
[*]Bash Commands Injection
[*]Blind SQL Injection
[*]Buffer Overflow
[*]Carriage Return Line Feed
[*]SQL Injection in Headers
[*]XSS in Headers
[*]HTML Injection
[*]LDAP Injection
[*]Local File Inclusion
[*]OS Commanding
[*]PHP Code Injection
[*]SQL Injection
[*]Server Side Injection
[*]XPath Injection
[*]Cross Site Scripting
[*]XML External Entity

Audit
[*]Apache Status Page
[*]Open Redirect
[*]PHPInfo
[*]Robots.txt
[*]XST

Bruteforce
[*]Admin Panel
[*]Common Backdoor
[*]Common Backup Dir
[*]Common Backup File
[*]Common Dir
[*]Common File
[*]Hidden Parameters

Disclosure
[*]Credit Cards
[*]Emails
[*]Private IP
[*]Errors -> (fatal errors,…)
[*]SSN

Installation:

[su_quote]
$ git clone https://github.com/m4ll0k/WAScan.git wascan
$ cd wascan
$ pip install BeautifulSoup
$ python wascan.py
[/su_quote]

Download:

[su_quote]
https://github.com/m4ll0k/WAScan
[/su_quote]

Please follow and like us: