Wapiti

Vulnerability scanner for web applications
Download

Wapiti Ranking & Summary

Advertisement

  • Rating:
  • License:
  • GPL
  • Price:
  • FREE
  • Publisher Name:
  • Wapiti Team
  • Publisher web site:
  • Operating Systems:
  • Mac OS X
  • File Size:
  • 349 KB

Wapiti Tags


Wapiti Description

Vulnerability scanner for web applications Wapiti currently search vulnerabilities like XSS, SQL and XPath injections, file inclusions, command execution, LDAP injections, CRLF injections.Wapiti uses the Python programming language.Wapiti allows you to audit the security of your web applications.Wapiti performs "black-box" scans and does not study the source code of the application but scans the webpages of the deployed webapp, looking for scripts and forms where it can inject data.Wapiti can detect the following vulnerabilities :· File Handling Errors (Local and remote include/require, fopen, readfile...)· Database Injection (PHP/JSP/ASP SQL Injections and XPath Injections)· XSS (Cross Site Scripting) Injection· LDAP Injection· Command Execution detection (eval(), system(), passtru()...)· CRLF Injection (HTTP Response Splitting, session fixation...)Wapiti is able to differentiate punctual and permanent XSS vulnerabilities. Wapiti prints a warning everytime it founds a script allowing HTTP uploads.A warning is also issued when a HTTP 500 code is returned (useful for ASP/IIS)Wapiti does not rely on a vulnerability database like Nikto do. Wapiti aims to discover unknown vulnerabilities in web applications.Wapiti does not provide a GUI for the moment and you must use it from a terminal. Here are some key features of "Wapiti": · File Handling Errors (Local and remote include/require, open, read file...) · Database Injection (PHP/JSP/ASP SQL Injections and XPath Injections) · XSS (Cross Site Scripting) Injection · LDAP Injection · Command Execution detection (eval(), system(), pass through · CRLF Injection (HTTP Response Splitting, session fixation What's New in This Release: · Added more patterns for file handling vulnerabilities in PHP. · Added GET_SQL and POST_SQL as modules (-m) for attacks. · Modifier getcookie.py and cookie.py so they try to get the cookies · Even if cookielib fails.


Wapiti Related Software