Skip to main content
Vulnerability Scanning
Created bymhmdiaa-trickest
Last updated8/12/2024

Input Parameters

file
required
List of web server URLs
Header(s) to include in HTTP requests
string
Maximum number of requests to send per second per machine
file
Header(s) to include in HTTP requests

Outputs

findings

Scan for Misconfigured Software

Description

Scan for web misconfigurations that range from disclosing information and exposing sensitive functionality to enabling complete takeover of an asset

Features

  • Scans for a wide range of misconfiguration scenarios.
  • Validates the server responses to minimize false positives.
  • Can scan thousands of web servers simulataneously.

Inputs

Required

  • urls: a list of URLs

Optional

  • header: Header(s) to include in HTTP requests
  • header-file: File with header(s) to include in HTTP requests
  • rate-limit: Maximum number of requests to send per second per machine (default: 300)

Outputs

  • findings: JSONLines records of finding details.

Changelog

  • v1.0.0
    • Initial release
  • v1.0.1
    • Added Basic Auth to the list of flagged configurations with a severity level of info
  • v1.1.0
    • Added header-file input
  • v1.2.0
    • Added recursive scanning to detect vulnerabilities at every level of the input URL paths
  • v1.2.1
    • Included the HTTP request that triggered each finding in the request field of the findings output