Wednesday, April 15, 2020

Spaghetti: A Website Applications Security Scanner


About Spaghetti
   Author: m4ll0k   Spaghetti is an Open Source web application scanner, it is designed to find various default and insecure files, configurations, and misconfigurations. Spaghetti is built on Python 2.7 and can run on any platform which has a Python environment.

Spaghetti Installation:

Spaghetti's Features:
   Fingerprints:
  • Server:
  • Web Frameworks (CakePHP,CherryPy,...)
  • Web Application Firewall (Waf)
  • Content Management System (CMS)
  • Operating System (Linux,Unix,..)
  • Language (PHP,Ruby,...)
  • Cookie Security
   Discovery:
  • Bruteforce:Admin Interface
    Common Backdoors
    Common Backup Directory
    Common Backup File
    Common Directory
    Common FileLog File
  • Disclosure: Emails, Private IP, Credit Cards
   Attacks:
  • HTML Injection
  • SQL Injection
  • LDAP Injection
  • XPath Injection
  • Cross Site Scripting (XSS)
  • Remote File Inclusion (RFI)
  • PHP Code Injection
   Other:
  • HTTP Allow Methods
  • HTML Object
  • Multiple Index
  • Robots Paths
  • Web Dav
  • Cross Site Tracing (XST)
  • PHPINFO
  • .Listing
   Vulns:
  • ShellShock
  • Anonymous Cipher (CVE-2007-1858)
  • Crime (SPDY) (CVE-2012-4929)
  • Struts-Shock
Spaghetti Example:
python spaghetti --url example.com --scan 0 --random-agent --verbose


More information


  1. Pentest Tools Free
  2. Wifi Hacker Tools For Windows
  3. Pentest Box Tools Download
  4. Pentest Tools Free
  5. Pentest Automation Tools
  6. Hacking Tools Free Download
  7. Pentest Tools Kali Linux
  8. Wifi Hacker Tools For Windows
  9. Hacking Tools Github
  10. Beginner Hacker Tools
  11. Hacker Tools List
  12. New Hack Tools
  13. Hack Tools
  14. Pentest Tools Alternative
  15. Pentest Tools Github
  16. Wifi Hacker Tools For Windows
  17. Pentest Tools Website
  18. Hack Tools For Games
  19. Hacker Hardware Tools
  20. Tools 4 Hack
  21. Easy Hack Tools
  22. What Is Hacking Tools
  23. New Hack Tools
  24. Hacking Tools Online
  25. Hackrf Tools

No comments: