• Skip to main content
  • Skip to primary sidebar
  • Skip to footer
  • Home
  • About Darknet
  • Hacking Tools
  • Popular Posts
  • Darknet Archives
  • Contact Darknet
    • Advertise
    • Submit a Tool
Darknet – Hacking Tools, Hacker News & Cyber Security

Darknet - Hacking Tools, Hacker News & Cyber Security

Darknet is your best source for the latest hacking tools, hacker news, cyber security best practices, ethical hacking & pen-testing.

Spaghetti Download – Web Application Security Scanner

October 18, 2017

Views: 8,919

Spaghetti is an Open-source Web Application Security Scanner, it is designed to find various default and insecure files, configurations, and misconfigurations.

Spaghetti Download - Web Application Security Scanner

It is built on Python 2.7 and can run on any platform which has a Python environment.

Features of Spaghetti Web Application Security Scanner

  • Fingerprints
    • Server
    • Web Frameworks (CakePHP, CherryPy,…)
    • Web Application Firewall (Waf)
    • Content Management System (CMS)
    • Operating System (Linux, Unix,..)
    • Language (PHP, Ruby,…)
    • Cookie Security
  • Bruteforce
    • Admin Interface
    • Common Backdoors
    • Common Backup Directory
    • Common Backup File
    • Common Directory
    • Common File
    • Log File
  • Disclosure
    • Emails
    • Private IP
    • Credit Cards
  • Attacks
    • HTML Injection
    • SQL Injection
    • LDAP Injection
    • XPath Injection
    • Cross Site Scripting (XSS)
    • Remote File Inclusion (RFI)
    • PHP Code Injection
  • Other
    • HTTP Allow Methods
    • HTML Object
    • Multiple Index
    • Robots Paths
    • Web Dav
    • Cross Site Tracing (XST)
    • PHPINFO
    • .Listing
  • Vulns
    • ShellShock
    • Anonymous Cipher (CVE-2007-1858)
    • Crime (SPDY) (CVE-2012-4929)
    • Struts-Shock

Using Spaghetti Web Application Security Scanner

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
root@darknet:~/Spaghetti# python spaghetti.py
  _____             _       _   _   _
|   __|___ ___ ___| |_ ___| |_| |_|_|
|__   | . | .'| . |   | -_|  _|  _| |
|_____|  _|__,|_  |_|_|___|_| |_| |_|
       |_|     |___|          v0.1.3
 
~/# Spaghetti - Web Application Security Scanner
~/# Codename - MR.R0B0T
~/# Momo Outaadi (@M4ll0k)
~/# https://github.com/m4ll0k/Spaghetti
 
Usage:
 
        -u --url        Target URL (eg: http://example.com)
        -s --scan       Scan Options (default=0):
 
                0:      Full Scan
                1:      Bruteforce (dirs,files,..)
                2:      Disclosure (ip,emails,..)
                3:      Attacks (sql,lfi,..)
                4:      Others (webdav,..)
                5:      Vulns (shellshock,..)
                6:      Fingerprint only
 
        --crawler       Deep crawling (slow)
        --agent         Use the specified user-agent
        --random-agent  Use a random user-agent
        --redirect      Redirect target URL, default=True
        --timeout       Set timeout, default=None
        --cookie        Set cookie, default=None
        --proxy         Set proxy, (host:port)
        --verbose       Verbose output
        --version       Show version
        --help          Show this help and exit
 
Examples:
 
        spaghetti.py --url http://example.com
        spaghetti.py --url http://example.com --scan [0-6]
        spaghetti.py --url http://example.com --scan 1 --crawler

Example:

1
python spaghetti.py --url site.com --scan 0 --random-agent --verbose

Installation of Spaghetti Web Scanner

1
2
3
4
$ git clone https://github.com/m4ll0k/Spaghetti.git
$ cd Spaghetti
$ pip install -r requirements.txt
$ python spaghetti.py

There are also other options to check out like:

– Arachni v0.2.2.1 – Web Application Security Scanner Framework
– Vega – Open Source Cross Platform Web-Application Security Assessment Platform

You can download Spaghetti Web Application Security Scanner here:

Spaghetti-v0.1.2.zip

Or read more here.

Related Posts:

  • An Introduction To Web Application Security Systems
  • HTTrack - Website Downloader Copier & Site Ripper Download
  • BloodHound - Hacking Active Directory Trust Relationships
  • XXEinjector - Automatic XXE Injection Tool For Exploitation
  • Intel Hidden Management Engine - x86 Security Risk?
  • Microsoft Azure Web Application Firewall (WAF) Launched
Share
Tweet115
Share95
Buffer44
WhatsApp
Email
254 Shares

Filed Under: Hacking Tools Tagged With: Python



Primary Sidebar

Search Darknet

  • Email
  • Facebook
  • LinkedIn
  • RSS
  • Twitter

Advertise on Darknet

Latest Posts

RedExt - Browser Extension-Based C2 Framework for Red Team Recon

RedExt – Browser Extension-Based C2 Framework for Red Team Recon

Views: 155

RedExt is a browser extension-based Command and Control (C2) framework designed for authorised red … ...More about RedExt – Browser Extension-Based C2 Framework for Red Team Recon

Cybersecurity Workforce Trends in 2025 - Skills Gap, Diversity and SOC Readiness

Cybersecurity Workforce Trends in 2025 – Skills Gap, Diversity and SOC Readiness

Views: 244

Cybersecurity teams now face a trifecta of pressure: widening SOC skill gaps, a chronic shortage of … ...More about Cybersecurity Workforce Trends in 2025 – Skills Gap, Diversity and SOC Readiness

AzureStrike - Offensive Toolkit for Attacking Azure Active Directory Environments

AzureStrike – Offensive Toolkit for Attacking Azure Active Directory Environments

Views: 478

AzureStrike is an offensive security toolkit built to help red teams and penetration testers assess … ...More about AzureStrike – Offensive Toolkit for Attacking Azure Active Directory Environments

ChromeAlone - Chromium Browser C2 Implant for Red Team Operations

ChromeAlone – Chromium Browser C2 Implant for Red Team Operations

Views: 345

Overview ChromeAlone is a red team Command and Control (C2) implant that leverages the Chromium … ...More about ChromeAlone – Chromium Browser C2 Implant for Red Team Operations

Darknet Communications in 2025 - From IRC Forums to Telegram Crime Networks

Darknet Communications in 2025 – From IRC Forums to Telegram Crime Networks

Views: 1,185

The way darknet actors coordinate has undergone a dramatic shift in the past decade. Once dominated … ...More about Darknet Communications in 2025 – From IRC Forums to Telegram Crime Networks

LostMyPassword - Dual Use Password Recovery and Credential Dumping Tool

LostMyPassword – Dual Use Password Recovery and Credential Dumping Tool

Views: 716

LostMyPassword v1.00 is a compact Windows utility from NirSoft that automatically reveals stored … ...More about LostMyPassword – Dual Use Password Recovery and Credential Dumping Tool

Topics

  • Advertorial (28)
  • Apple (46)
  • Cloud Security (4)
  • Countermeasures (231)
  • Cryptography (84)
  • Dark Web (3)
  • Database Hacking (89)
  • Events/Cons (7)
  • Exploits/Vulnerabilities (432)
  • Forensics (64)
  • GenAI (5)
  • Hacker Culture (10)
  • Hacking News (234)
  • Hacking Tools (696)
  • Hardware Hacking (82)
  • Legal Issues (179)
  • Linux Hacking (74)
  • Malware (240)
  • Networking Hacking Tools (352)
  • Password Cracking Tools (107)
  • Phishing (41)
  • Privacy (219)
  • Secure Coding (119)
  • Security Software (235)
  • Site News (51)
    • Authors (6)
  • Social Engineering (37)
  • Spammers & Scammers (76)
  • Stupid E-mails (6)
  • Telecomms Hacking (6)
  • UNIX Hacking (6)
  • Virology (6)
  • Web Hacking (384)
  • Windows Hacking (170)
  • Wireless Hacking (45)

Security Blogs

  • Dancho Danchev
  • F-Secure Weblog
  • Google Online Security
  • Graham Cluley
  • Internet Storm Center
  • Krebs on Security
  • Schneier on Security
  • TaoSecurity
  • Troy Hunt

Security Links

  • Exploits Database
  • Linux Security
  • Register – Security
  • SANS
  • Sec Lists
  • US CERT

Footer

Most Viewed Posts

  • Brutus Password Cracker Hacker – Download brutus-aet2.zip AET2 (2,355,996)
  • Darknet – Hacking Tools, Hacker News & Cyber Security (2,173,518)
  • Top 15 Security Utilities & Download Hacking Tools (2,097,029)
  • 10 Best Security Live CD Distros (Pen-Test, Forensics & Recovery) (1,199,933)
  • Password List Download Best Word List – Most Common Passwords (933,998)
  • wwwhack 1.9 – wwwhack19.zip Web Hacking Software Free Download (776,676)
  • Hack Tools/Exploits (673,655)
  • Wep0ff – Wireless WEP Key Cracker Tool (530,655)

Search

Recent Posts

  • RedExt – Browser Extension-Based C2 Framework for Red Team Recon August 29, 2025
  • Cybersecurity Workforce Trends in 2025 – Skills Gap, Diversity and SOC Readiness August 27, 2025
  • AzureStrike – Offensive Toolkit for Attacking Azure Active Directory Environments August 25, 2025
  • ChromeAlone – Chromium Browser C2 Implant for Red Team Operations August 22, 2025
  • Darknet Communications in 2025 – From IRC Forums to Telegram Crime Networks August 20, 2025
  • LostMyPassword – Dual Use Password Recovery and Credential Dumping Tool August 18, 2025

Tags

apple botnets computer-security darknet Database Hacking ddos dos exploits fuzzing google hacking-networks hacking-websites hacking-windows hacking tool Information-Security information gathering Legal Issues malware microsoft network-security Network Hacking Password Cracking pen-testing penetration-testing Phishing Privacy Python scammers Security Security Software spam spammers sql-injection trojan trojans virus viruses vulnerabilities web-application-security web-security windows windows-security Windows Hacking worms XSS

Copyright © 1999–2025 Darknet All Rights Reserved · Privacy Policy