Tuesday, April 14, 2020

Spaghetti: A Website Applications Security Scanner


About Spaghetti
   Author: m4ll0k   Spaghetti is an Open Source web application scanner, it is designed to find various default and insecure files, configurations, and misconfigurations. Spaghetti is built on Python 2.7 and can run on any platform which has a Python environment.

Spaghetti Installation:

Spaghetti's Features:
   Fingerprints:
  • Server:
  • Web Frameworks (CakePHP,CherryPy,...)
  • Web Application Firewall (Waf)
  • Content Management System (CMS)
  • Operating System (Linux,Unix,..)
  • Language (PHP,Ruby,...)
  • Cookie Security
   Discovery:
  • Bruteforce:Admin Interface
    Common Backdoors
    Common Backup Directory
    Common Backup File
    Common Directory
    Common FileLog File
  • Disclosure: Emails, Private IP, Credit Cards
   Attacks:
  • HTML Injection
  • SQL Injection
  • LDAP Injection
  • XPath Injection
  • Cross Site Scripting (XSS)
  • Remote File Inclusion (RFI)
  • PHP Code Injection
   Other:
  • HTTP Allow Methods
  • HTML Object
  • Multiple Index
  • Robots Paths
  • Web Dav
  • Cross Site Tracing (XST)
  • PHPINFO
  • .Listing
   Vulns:
  • ShellShock
  • Anonymous Cipher (CVE-2007-1858)
  • Crime (SPDY) (CVE-2012-4929)
  • Struts-Shock
Spaghetti Example:
python spaghetti --url example.com --scan 0 --random-agent --verbose


More info

  1. Hacker Tools 2019
  2. Hack Tools Github
  3. Hacker Tools List
  4. What Are Hacking Tools
  5. How To Install Pentest Tools In Ubuntu
  6. Pentest Tools Website Vulnerability
  7. Pentest Reporting Tools
  8. Hacker Tool Kit
  9. Pentest Tools Open Source
  10. Hacker Tools Apk
  11. Hacking Tools Kit
  12. Hacking Tools For Mac
  13. Hack Tools Pc
  14. Kik Hack Tools
  15. Pentest Tools Android
  16. Hacker Search Tools
  17. Hack Tools Mac
  18. New Hack Tools
  19. Pentest Reporting Tools
  20. Hacking Tools For Beginners
  21. Bluetooth Hacking Tools Kali
  22. Hacker Tools Free
  23. Pentest Tools Website
  24. Hack Website Online Tool

No comments:

Post a Comment