
wig هي أداة لجمع معلومات تطبيقات الويب، يمكنها التعرف على العديد من أنظمة إدارة المحتوى والتطبيقات الإدارية الأخرى.
تعتمد بصمة التطبيق على المجاميع الاختبارية (checksums) ومطابقة السلاسل النصية للملفات المعروفة لإصدارات مختلفة من أنظمة إدارة المحتوى. ينتج عن ذلك حساب درجة لكل CMS مكتشف وإصداراته. يتم عرض كل CMS مكتشف مع الإصدار (أو الإصدارات) الأكثر احتمالاً له. يعتمد حساب الدرجة على الأوزان وكمية "الإصابات" لمجموع اختباري معين.
تحاول wig أيضًا تخمين نظام التشغيل على الخادم بناءً على الرؤوس 'server' و 'x-powered-by'. تتضمن wig قاعدة بيانات تحتوي على قيم رؤوس معروفة لأنظمة تشغيل مختلفة، مما يسمح لـ wig بتخمين إصدارات Microsoft Windows وتوزيعات Linux وإصداراتها.
تم بناء wig باستخدام Python 3، وبالتالي فهي غير متوافقة مع Python 2.
يمكن تشغيل wig من سطر الأوامر أو تثبيتها باستخدام distuils.
$ python3 wig.py example.com
قم بالتثبيت باستخدام
$ python3 setup.py install
ومن ثم يمكن استيراد wig من أي مكان كالتالي:
>>>> from wig.wig import wig
>>>> w = wig(url='example.com')
>>>> w.run()
>>>> results = w.get_results()
السلوك الافتراضي لـ wig هو التعرف على نظام إدارة المحتوى (CMS) والخروج بعد اكتشاف إصداره. يتم ذلك للحد من كمية الحركة المرسلة إلى الخادم المستهدف. يمكن تجاوز هذا السلوك بوضع العلامة '-a'، وفي هذه الحالة ستختبر wig جميع البصمات المعروفة. نظرًا لأن بعض تكوينات التطبيقات لا تستخدم الموقع الافتراضي للملفات والموارد، فمن الممكن أن تجلب wig جميع الموارد الثابتة التي تواجهها أثناء فحصها. يتم ذلك باستخدام الخيار '-c'. الخيار '-m' يختبر جميع البصمات مقابل جميع عناوين URL التي تم جلبها، وهو مفيد إذا تم تغيير الموقع الافتراضي.
usage: wig.py [-h] [-l INPUT_FILE] [-q] [-n STOP_AFTER] [-a] [-m] [-u] [-d]
[-t THREADS] [--no_cache_load] [--no_cache_save] [-N]
[--verbosity] [--proxy PROXY] [-w OUTPUT_FILE]
[url]
WebApp Information Gatherer
positional arguments:
url The url to scan e.g. http://example.com
optional arguments:
-h, --help show this help message and exit
-l INPUT_FILE File with urls, one per line.
-q Set wig to not prompt for user input during run
-n STOP_AFTER Stop after this amount of CMSs have been detected. Default:
1
-a Do not stop after the first CMS is detected
-m Try harder to find a match without making more requests
-u User-agent to use in the requests
-d Disable the search for subdomains
-t THREADS Number of threads to use
--no_cache_load Do not load cached responses
--no_cache_save Do not save the cache for later use
-N Shortcut for --no_cache_load and --no_cache_save
--verbosity, -v Increase verbosity. Use multiple times for more info
--proxy PROXY Tunnel through a proxy (format: localhost:8080)
-w OUTPUT_FILE File to dump results into (JSON)
$ python3 wig.py example.com
wig - WebApp Information Gatherer
Redirected to http://www.example.com
Continue? [Y|n]:
Scanning http://www.example.com...
_____________________________________________________ SITE INFO _____________________________________________________
IP Title
256.256.256.256 PAGE_TITLE
______________________________________________________ VERSION ______________________________________________________
Name Versions Type
Drupal 7.38 CMS
nginx Platform
amazons3 Platform
Varnish Platform
IIS 7.5 Platform
ASP.NET 4.0.30319 Platform
jQuery 1.4.4 JavaScript
Microsoft Windows Server 2008 R2 OS
_____________________________________________________ SUBDOMAINS ____________________________________________________
Name Page Title IP
http://m.example.com:80 Mobile Page 256.256.256.257
https://m.example.com:443 Secure Mobil Page 256.256.256.258
____________________________________________________ INTERESTING ____________________________________________________
URL Note Type
/test/ Test directory Interesting
/login/ Login Page Interesting
_______________________________________________ PLATFORM OBSERVATIONS _______________________________________________
Platform URL Type
ASP.NET 2.0.50727 /old.aspx Observation
ASP.NET 4.0.30319 /login/ Observation
IIS 6.0 http://www.example.com/templates/file.css Observation
IIS 7.0 https://www.example.com/login/ Observation
IIS 7.5 http://www.example.com Observation
_______________________________________________________ TOOLS _______________________________________________________
Name Link Software
droopescan https://github.com/droope/droopescan Drupal
CMSmap https://github.com/Dionach/CMSmap Drupal
__________________________________________________ VULNERABILITIES __________________________________________________
Affected #Vulns Link
Drupal 7.38 5 http://cvedetails.com/version/185744
_____________________________________________________________________________________________________________________
Time: 11.3 sec Urls: 310 Fingerprints: 37580