Skip to content
Sections
>> Trisquel >> 套件 >> nabia >> python >> wapiti
etiona  ] [  nabia  ] [  aramo  ]
[ 原始碼: wapiti  ]

套件: wapiti (3.0.3+dfsg-1)

web application vulnerability scanner

Wapiti allows you to audit the security of your web applications. It performs "black-box" scans, i.e. it does not study the source code of the application but will scan the web pages of the deployed web applications, looking for scripts and forms where it can inject data. Once it gets this list, Wapiti acts like a fuzzer, injecting payloads to see if a script is vulnerable.

Wapiti can detect the following vulnerabilities:

 - Database Injection (PHP/ASP/JSP SQL Injections and XPath Injections)
 - Cross Site Scripting (XSS) reflected and permanent
 - File disclosure detection (local and remote include, require, fopen,
   readfile...)
 - Command Execution detection (eval(), system(), passtru()...)
 - XXE (Xml eXternal Entity) injection
 - CRLF Injection
 - Search for potentially dangerous files on the server (thank to the Nikto db)
 - Bypass of weak htaccess configurations
 - Search for copies (backup) of scripts on the server
 - Shellshock
 - DirBuster like
 - Server Side Request Forgery (through use of an external Wapiti website)

其他與 wapiti 有關的套件

  • 依賴
  • 推薦
  • 建議
  • dep: libjs-jquery
    JavaScript library for dynamic web applications
  • dep: python3
    interactive high-level object-oriented language (default python3 version)
  • dep: python3-bs4
    error-tolerant HTML parser for Python 3
  • dep: python3-mako
    fast and lightweight templating for the Python 3 platform
  • dep: python3-requests
    elegant and simple HTTP library for Python3, built for human beings
  • dep: python3-socks
    Python 3 SOCKS client module
  • dep: python3-tld
    Extract the top level domain (TLD) from a given URL (Python 3)
  • dep: python3-yaswfp
    Yet Another SWF Parser (Python 3)

下載 wapiti

下載可用於所有硬體架構的
硬體架構 套件大小 安裝後大小 檔案
all 311.5 kB1602 kB [文件列表]