Name:wapiti
Category:Scanners
Publisher:trickest-mhmdiaa
Created:9/7/2022
Container:
quay.io/trickest/wapiti:3.1.3Output Type:
License:Unknown
Source:View Source
Parameters
--urlThe base URL used to define the scan scope--dataUrlencoded data to send with the base URL if it is a POST request--skipSkip attacking given parameter(s)--colorColorize output--depthSet how deep the scanner should explore the website--levelSet attack level--proxySet the HTTP(S) proxy to use. Supported: http(s) and socks proxies--scopeSet scan scope (page, folder, domain, url, or punk)--startAdds a url to start scan with--tasksNumber of concurrent tasks to use for the exploration (crawling) of the target.--cookieSet a JSON cookie file to use.--formatSet output format. Supported: csv, html, json, txt, xml. Default is html.--headerSet a custom header to use for every requests--moduleList of modules to load--removeRemove this parameter from urls--excludeAdds a url to exclude from the scan--timeoutSet timeout for requests in seconds--verboseSet verbosity level (0: quiet, 1: normal, 2: verbose)--endpointURL serving as endpoint for both attacker and target--auth-credSet HTTP authentication credentials--auth-typeSet the authentication type to use (basic, digest, ntlm, or post)--scan-forceEasy way to reduce the number of scanned and attacked URLs. Possible values: paranoid, sneaky, polite, normal, aggressive, insane--user-agentSet a custom user-agent to use for every requests--verify-sslSet SSL check (0 or 1, default is 0)--dns-endpointDomain serving as DNS endpoint for Log4Shell attack--no-bugreportDon't send automatic bug report when an attack module fails--max-scan-timeSet how many seconds you want the scan to last (floats accepted)--max-parametersURLs and forms having more than MAX input parameters will be erased before attack.--drop-set-cookieIgnore Set-Cookie header from HTTP responses--max-attack-timeSet how many seconds you want each attack module to last (floats accepted)--external-endpointURL serving as endpoint for target--internal-endpointURL serving as endpoint for attacker--max-files-per-dirSet how many pages the scanner should explore per directory--max-links-per-pageSet how many (in-scope) links the scanner should extract for each page