[Nikto-discuss] [Fwd: Fwd: [Full-disclosure] Release of webshag 1.00!]

Sullo sullo at cirt.net
Thu Mar 20 14:10:36 UTC 2008

Forwarding this along as Webshag uses the Nikto scan database for one of
its features. I haven't had a chance to try it just yet, but welcome
comments on the list if anyone has.


---------- Forwarded message ----------
From: <webshag at scrt.ch <mailto:webshag at scrt.ch>>
Date: Thu, Mar 20, 2008 at 5:17 AM
Subject: [Full-disclosure] Release of webshag 1.00!
To: full-disclosure at lists.grok.org.uk
<mailto:full-disclosure at lists.grok.org.uk>

Webshag is a free, multi-threaded, multi-platform web server audit tool.

Written in Python, it gathers commonly useful functionalities for web
server auditing like website crawling, URL scanning or file fuzzing. It
also provides innovative functionalities like the capability of
retrieving  the list of domain names hosted on a target machine and file
fuzzing using *dynamically* generated filenames (in addition to common
list-based fuzzing).

Webshag URL scanner and file fuzzer are aimed at reducing the number of
false positives and thus producing cleaner result sets. For this
purpose, webshag implements a web page fingerprinting mechanism
resistant to content changes. This fingerprinting mechanism is then used
in a false positive removal algorithm specially aimed at dealing with
"soft 404" server responses.

Webshag provides a full featured and intuitive graphical user interface
as well as a text-based command line interface.

It is freely downloadable (GPL license) for Linux and Windows platforms
from http://www.scrt.ch/pages_en/outils.html

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


http://www.cirt.net | http://www.osvdb.org/

More information about the Nikto-discuss mailing list