EyeWitness

Website scanner

An automated web vulnerability scanning tool designed to take screenshots of websites and identify default credentials.

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

GitHub

20 stars
0 watching
0 forks
last commit: over 2 years ago
Linked from 2 awesome lists


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
r0075h3ll/oralyzerA tool to identify vulnerabilities in web applications by probing for Open Redirections and other types of attacks.758
lirantal/is-website-vulnerableA tool that scans websites for publicly known security vulnerabilities in their frontend JavaScript libraries.1,942
whwlsfb/log4j2scanA tool that scans websites for Log4j2 remote code execution vulnerabilities using multiple DNS log platforms and supports various scan types776
byt3bl33d3r/witnessmeA tool that uses headless Chromium to take screenshots of webpages and provides additional functionality for inventory management.737
kathanp19/gaussrfA tool for identifying potential vulnerabilities in websites by fetching known URLs and filtering out ones with open redirects or SSRF parameters.168
edoardottt/cariddiA tool for crawling and scanning websites for sensitive information such as endpoints, secrets, and tokens.1,551
samuirai/grackerA web application security testing tool built using Groovy and leveraging web technologies to identify vulnerabilities in web applications.9
thesp0nge/dawnscannerA security scanner designed to review web applications for potential vulnerabilities.736
emo-crab/observer_wardA tool for identifying vulnerabilities in web applications and services by analyzing patterns of web servers and services1,295
m0nad/hellraiserScans networks to identify vulnerabilities by correlating CPEs with CVEs using an API562
1n3/blackwidowA Python-based web application scanner that gathers OSINT and fuzz data to identify OWASP vulnerabilities on target websites.1,545
assetnote/surfA tool that identifies and filters potential Server-Side Request Forgery (SSRF) vulnerabilities in cloud environments by probing external hosts.599
usscltd/dorksAutomates searching for vulnerabilities in databases and websites using predefined query patterns200
sectooladdict/wavsepAn open-source tool for evaluating web application vulnerabilities by analyzing the separation of concerns in web applications.232
david-a-wheeler/flawfinderAnalyzes C/C++ source code for security vulnerabilities and reports potential flaws.498