WhatWeb has over 80 plugins and needs community support to develop more. Plugins can identify systems with obvious signs removed by looking for subtle clues. For example, a WordPress site might remove the tag but the WordPress plugin also looks for “wp-content” which is less easy to disguise. Plugins are flexible and can return any datatype, for example plugins can return version numbers, email addresses, account ID’s and more.
There are both passive and aggressive plugins, passive plugins use information on the page, in cookies and in the URL to identify the system. A passive request is as light weight as a simple GET / HTTP/1.1 request. Aggressive plugins guess URLs and request more files. Plugins are easy to write, you don’t need to know ruby to make them.
Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.
There are currently 3 types of log output. They are:
- Brief logging
- Full logging
- XML logging
There are over 90 plugins as of version 0.4.3. Plugins are easy to make. Matches are made with regular expressions, Google Hack Database queries, and custom ruby code. For now the probability means maybe (25%), probably (75%) and certain (100%).
You can download WhatWeb 0.4.3 here:
Or read more here.
Recent in Hacking Tools:
- LANs.py ARP Spoofer – Multithreaded Asynchronous Packet Parsing/Injecting
- hashcat – Multi-Threaded Password Hash Cracking Tool
- aidSQL – PHP Application For SQL Injection Detection & Exploitation
- Web-Sorrow v1.48 – Version Detection, CMS Identification, Enumeration & Server Scanning Tool
- OWASP – SQLiX Project – SQL Injection Scanner
- SSA Version 1.5.2 – OVAL Vulnerability Assessment Software
Most Read in Hacking Tools:
- Top 15 Security/Hacking Tools & Utilities - 1,825,974 views
- Brutus Password Cracker – Download brutus-aet2.zip AET2 - 1,015,153 views
- wwwhack 1.9 – Download wwwhack19.zip Web Hacking Tool - 606,057 views