<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; web scanner</title>
	<atom:link href="http://www.darknet.org.uk/tag/web-scanner/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>WhatWeb &#8211; Next Gen Web Scanner &#8211; Identify CMS (Content Management System)</title>
		<link>http://www.darknet.org.uk/2010/05/whatweb-next-gen-web-scanner-identify-cms-content-management-system/</link>
		<comments>http://www.darknet.org.uk/2010/05/whatweb-next-gen-web-scanner-identify-cms-content-management-system/#comments</comments>
		<pubDate>Mon, 31 May 2010 06:40:33 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[identify cms]]></category>
		<category><![CDATA[identify content management system]]></category>
		<category><![CDATA[identify fluxbb version]]></category>
		<category><![CDATA[identify joomla version]]></category>
		<category><![CDATA[identify oscommerce version]]></category>
		<category><![CDATA[identify phpbb version]]></category>
		<category><![CDATA[identify tomcat version]]></category>
		<category><![CDATA[identify web application]]></category>
		<category><![CDATA[identify wordpress plugins]]></category>
		<category><![CDATA[morningstar]]></category>
		<category><![CDATA[morningstar security]]></category>
		<category><![CDATA[next gen web scanner]]></category>
		<category><![CDATA[web application fingerprinting]]></category>
		<category><![CDATA[web scanner]]></category>
		<category><![CDATA[web scanning]]></category>
		<category><![CDATA[web-server-fingerprinting]]></category>
		<category><![CDATA[what web]]></category>
		<category><![CDATA[whatweb]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2700</guid>
		<description><![CDATA[Identify content management systems (CMS), blogging platforms, stats/analytics packages, javascript libraries, servers and more. When you visit a website in your browser the transaction includes many unseen hints about how the webserver is set up and what software is delivering the webpage. Some of these hints are obvious, eg. “Powered by XYZ” and others are [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Identify content management systems (CMS), blogging platforms, stats/analytics packages, javascript libraries, servers and more. When you visit a website in your browser the transaction includes many unseen hints about how the webserver is set up and what software is delivering the webpage. Some of these hints are obvious, eg. “Powered by XYZ” and others are more subtle. WhatWeb recognises these hints and reports what it finds.</p>
<p>WhatWeb has over 80 plugins and needs community support to develop more. Plugins can identify systems with obvious signs removed by looking for subtle clues. For example, a WordPress site might remove the tag but the WordPress plugin also looks for “wp-content” which is less easy to disguise. Plugins are flexible and can return any datatype, for example plugins can return version numbers, email addresses, account ID’s and more.</p>
<p>There are both passive and aggressive plugins, passive plugins use information on the page, in cookies and in the URL to identify the system. A passive request is as light weight as a simple GET / HTTP/1.1 request. Aggressive plugins guess URLs and request more files. Plugins are easy to write, you don’t need to know ruby to make them.</p>
<p>Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.</p>
<p><strong>Log Ouput</strong></p>
<p>There are currently 3 types of log output. They are:</p>
<ul>
<li>Brief logging</li>
<li>Full logging</li>
<li>XML logging</li>
</ul>
<p><strong>Plugins</strong></p>
<p>There are over 90 plugins as of version 0.4.3. Plugins are easy to make. Matches are made with regular expressions, Google Hack Database queries, and custom ruby code. For now the probability means maybe (25%), probably (75%) and certain (100%).</p>
<p>You can download WhatWeb 0.4.3 here:</p>
<p><a href="http://www.morningstarsecurity.com/downloads/whatweb-0.4.3.tar.gz">whatweb-0.4.3.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://www.morningstarsecurity.com/research/whatweb">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=WhatWeb+%E2%80%93+Next+Gen+Web+Scanner+%E2%80%93+Identify+CMS+%28Content+Management+System%29+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2700+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/05/whatweb-next-gen-web-scanner-identify-cms-content-management-system/&amp;t=WhatWeb+%E2%80%93+Next+Gen+Web+Scanner+%E2%80%93+Identify+CMS+%28Content+Management+System%29" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/05/whatweb-next-gen-web-scanner-identify-cms-content-management-system/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/05/whatweb-next-gen-web-scanner-identify-cms-content-management-system/&amp;title=WhatWeb+%E2%80%93+Next+Gen+Web+Scanner+%E2%80%93+Identify+CMS+%28Content+Management+System%29" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/05/whatweb-next-gen-web-scanner-identify-cms-content-management-system/&amp;title=WhatWeb+%E2%80%93+Next+Gen+Web+Scanner+%E2%80%93+Identify+CMS+%28Content+Management+System%29" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/05/whatweb-next-gen-web-scanner-identify-cms-content-management-system/&amp;title=WhatWeb+%E2%80%93+Next+Gen+Web+Scanner+%E2%80%93+Identify+CMS+%28Content+Management+System%29" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/05/whatweb-next-gen-web-scanner-identify-cms-content-management-system/&amp;title=WhatWeb+%E2%80%93+Next+Gen+Web+Scanner+%E2%80%93+Identify+CMS+%28Content+Management+System%29" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F05%2Fwhatweb-next-gen-web-scanner-identify-cms-content-management-system%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/05/whatweb-next-gen-web-scanner-identify-cms-content-management-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nikto 2.1.0 Released &#8211; Web Server Security Scanning Tool</title>
		<link>http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/</link>
		<comments>http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 09:52:06 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[gpl]]></category>
		<category><![CDATA[hacking web apps]]></category>
		<category><![CDATA[hacking-websites]]></category>
		<category><![CDATA[libwhisker]]></category>
		<category><![CDATA[nikto]]></category>
		<category><![CDATA[nikto 2]]></category>
		<category><![CDATA[nikto 2.1]]></category>
		<category><![CDATA[web scanner]]></category>
		<category><![CDATA[web server scanning]]></category>
		<category><![CDATA[web-application-hacking]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-server-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2206</guid>
		<description><![CDATA[It&#8217;s been almost 2 years since the last update on Nikto, which was version 2. For those that don&#8217;t know, Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3500 potentially dangerous files/CGIs, versions on over 900 servers, and version specific problems on [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It&#8217;s been almost 2 years since the last update on <a href="http://www.darknet.org.uk/2007/12/nikto-2-released-web-server-scanning-tool/">Nikto, which was version 2</a>.</p>
<p>For those that don&#8217;t know, Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3500 potentially dangerous files/CGIs, versions on over 900 servers, and version specific problems on over 250 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired).</p>
<p>Nikto is not designed as an overly stealthy tool. It will test a web server in the shortest timespan possible, and it&#8217;s fairly obvious in log files. However, there is support for LibWhisker&#8217;s anti-IDS methods in case you want to give it a try (or test your IDS system).</p>
<p><strong>Changes</strong></p>
<p>This version has gone through significant rewrites under the hood to how Nikto works, to make it more expandable and usable.</p>
<ul>
<li>
Rewrite to the plugin engine allowing more control of the plugin structure and making it easier to add plugins</li>
<li>Rewrite to the reporting engine allowing reporting plugins to cover more and also ensuring that output is written if Nikto is quit before finishing</li>
<li>Large overhaul of documentation to document built-in methods and variables</li>
<li>Addition of caching to reduce amount of calls made to the web servers, as well as a facility to disable smart 404 guessing.</li>
<li>Addition of simple guessing for whether a system is an embedded device and to report what it is</li>
<li>Plugin to use OWASPs dictionary lists to attempt to brute force directories on the remote web server (as mutate 6)</li>
<li>Plugin to attempt to brute force domains (as mutate 5)</li>
<li>Allow username guessing (mutate 3 and 4) to use a dictionary file as well as brute forcing</li>
<li>Support for NTLM authentication</li>
<li>Lots of bug fixes and new security checks</li>
</ul>
<p>You can download Nikon 2.1.0 here:</p>
<p><a href="http://cirt.net/nikto/nikto-current.tar.gz">nikto-current.tar.gz</a></p>
<p>Plugins and DB can be found <a href="http://cirt.net/nikto/UPDATES/2.1.0/">here</a>.</p>
<p></p>
<p>Or read more <a href="http://cirt.net/nikto2">here</a>. </p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Nikto+2.1.0+Released+%E2%80%93+Web+Server+Security+Scanning+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2206+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/&amp;t=Nikto+2.1.0+Released+%E2%80%93+Web+Server+Security+Scanning+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/&amp;title=Nikto+2.1.0+Released+%E2%80%93+Web+Server+Security+Scanning+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/&amp;title=Nikto+2.1.0+Released+%E2%80%93+Web+Server+Security+Scanning+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/&amp;title=Nikto+2.1.0+Released+%E2%80%93+Web+Server+Security+Scanning+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/&amp;title=Nikto+2.1.0+Released+%E2%80%93+Web+Server+Security+Scanning+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F10%2Fnikto-2-1-0-released-web-server-security-scanning-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

