
ماسح ويب من الجيل التالي
تم تطويره بواسطة Andrew Horton urbanadventurer و Brendan Coles bcoles
آخر إصدار: v0.6.4. 3 أبريل 2026
الترخيص: GPLv2
يخضع هذا المنتج للشروط المفصلة في اتفاقية الترخيص. لمزيد من المعلومات حول WhatWeb، يرجى زيارة https://github.com/urbanadventurer/
الويكي: https://github.com/urbanadventurer/WhatWeb/wiki/
إذا كان لديك أي أسئلة أو تعليقات أو مخاوف بشأن WhatWeb، يرجى الرجوع إلى الوثائق قبل الاتصال بأحد المطورين. ملاحظاتك مرحب بها دائمًا.
يقوم WhatWeb بتحديد هوية مواقع الويب. هدفه هو الإجابة على السؤال: "ما هو هذا الموقع؟". يتعرف WhatWeb على تقنيات الويب بما في ذلك أنظمة إدارة المحتوى (CMS)، ومنصات التدوين، وحزم الإحصائيات/التحليلات، ومكتبات JavaScript، وخوادم الويب، والأجهزة المضمنة. يحتوي WhatWeb على أكثر من 1800 إضافة، كل منها للتعرف على شيء مختلف. كما يحدد WhatWeb أرقام الإصدارات، وعناوين البريد الإلكتروني، ومعرفات الحسابات، ووحدات إطار عمل الويب، وأخطاء SQL، والمزيد.
يمكن أن يكون WhatWeb خفيًا وسريعًا، أو شاملاً ولكن بطيئًا. يدعم WhatWeb مستوى عدوانية للتحكم في المفاضلة بين السرعة والموثوقية. عندما تزور موقعًا إلكترونيًا في متصفحك، تتضمن المعاملة العديد من التلميحات حول تقنيات الويب التي تشغل ذلك الموقع. في بعض الأحيان، تحتوي زيارة صفحة ويب واحدة على معلومات كافية لتحديد هوية موقع ويب، ولكن عندما لا تحتوي، يمكن لـ WhatWeb الاستفسار عن الموقع بشكل أعمق. مستوى العدوانية الافتراضي، المسمى 'stealthy'، هو الأسرع ويتطلب طلب HTTP واحد فقط لموقع الويب. هذا مناسب لمسح المواقع العامة. تم تطوير أوضاع أكثر عدوانية للاستخدام في اختبارات الاختراق.
معظم إضافات WhatWeb شاملة وتتعرف على مجموعة من الإشارات من الدقيقة إلى الواضحة. على سبيل المثال، يمكن التعرف على معظم مواقع WordPress عن طريق علامة HTML الوصفية، مثل ''، لكن أقلية من مواقع WordPress تزيل علامة التعريف هذه لكن هذا لا يعيق WhatWeb. تحتوي إضافة WordPress WhatWeb على أكثر من 15 اختبارًا، والتي تشمل فحص الأيقونة المفضلة، وملفات التثبيت الافتراضية، وصفحات تسجيل الدخول، والتحقق من وجود "/wp-content/" داخل الروابط النسبية.
استخدام WhatWeb لمسح reddit.com.``` $ ./whatweb reddit.com http://reddit.com [301 Moved Permanently] Country[UNITED STATES][US], HTTPServer[snooserv], IP[151.101.65.140], RedirectLocation[https://www.reddit.com/], UncommonHeaders[retry-after,x-served-by,x-cache-hits,x-timer], Via-Proxy[1.1 varnish] https://www.reddit.com/ [200 OK] Cookies[edgebucket,eu_cookie_v2,loid,rabt,rseor3,session_tracker,token], Country[UNITED STATES][US], Email[[email protected],[email protected]], Frame, HTML5, HTTPServer[snooserv], HttpOnly[token], IP[151.101.37.140], Open-Graph-Protocol[website], Script[text/javascript], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], Title[reddit: the front page of the internet], UncommonHeaders[fastly-restarts,x-served-by,x-cache-hits,x-timer], Via-Proxy[1.1 varnish], X-Frame-Options[SAMEORIGIN]
## الاستخدام```
.$$$ $. .$$$ $.
$$$$ $$. .$$$ $$$ .$$$$$$. .$$$$$$$$$$. $$$$ $$. .$$$$$$$. .$$$$$$.
$ $$ $$$ $ $$ $$$ $ $$$$$$. $$$$$ $$$$$$ $ $$ $$$ $ $$ $$ $ $$$$$$.
$ `$ $$$ $ `$ $$$ $ `$ $$$ $$' $ `$ `$$ $ `$ $$$ $ `$ $ `$ $$$'
$. $ $$$ $. $$$$$$ $. $$$$$$ `$ $. $ :' $. $ $$$ $. $$$$ $. $$$$$.
$::$ . $$$ $::$ $$$ $::$ $$$ $::$ $::$ . $$$ $::$ $::$ $$$$
$;;$ $$$ $$$ $;;$ $$$ $;;$ $$$ $;;$ $;;$ $$$ $$$ $;;$ $;;$ $$$$
$$$$$$ $$$$$ $$$$ $$$ $$$$ $$$ $$$$ $$$$$$ $$$$$ $$$$$$$$$ $$$$$$$$$'
WhatWeb - Next generation web scanner version 0.6.4.
Developed by Andrew Horton (urbanadventurer) and Brendan Coles (bcoles)
Homepage: https://morningstarsecurity.com/research/whatweb
Usage: whatweb [options] <URLs>
TARGET SELECTION:
<TARGETs> Enter URLs, hostnames, IP addresses, filenames or
IP ranges in CIDR, x.x.x-x, or x.x.x.x-x.x.x.x
format.
--input-file=FILE, -i Read targets from a file. You can pipe
hostnames or URLs directly with -i /dev/stdin.
TARGET MODIFICATION:
--url-prefix Add a prefix to target URLs.
--url-suffix Add a suffix to target URLs.
--url-pattern Insert the targets into a URL. Requires --input-file,
eg. www.example.com/%insert%/robots.txt
AGGRESSION:
The aggression level controls the trade-off between speed/stealth and
reliability.
--aggression, -a=LEVEL Set the aggression level. Default: 1.
Aggression levels are:
1. Stealthy Makes one HTTP request per target. Also follows redirects.
3. Aggressive If a level 1 plugin is matched, additional requests will be
made.
4. Heavy Makes a lot of HTTP requests per target. Aggressive tests from
all plugins are used for all URLs.
HTTP OPTIONS:
--user-agent, -U=AGENT Identify as AGENT instead of WhatWeb/0.6.3.
--header, -H Add an HTTP header. eg "Foo:Bar". Specifying a default
header will replace it. Specifying an empty value, eg.
"User-Agent:" will remove the header.
--follow-redirect=WHEN Control when to follow redirects. WHEN may be `never',
`http-only', `meta-only', `same-site', or `always'.
Default: always.
--max-redirects=NUM Maximum number of contiguous redirects. Default: 10.
AUTHENTICATION:
--user, -u=<user:password> HTTP basic authentication.
--cookie, -c=COOKIES Provide cookies, e.g. 'name=value; name2=value2'.
--cookiejar=FILE Read cookies from a file.
--no-cookies Disable automatic cookie handling (improves performance
with high thread counts).
### Cookie Handling
WhatWeb automatically handles cookies across redirects by default. This improves fingerprinting accuracy on sites requiring session management.
- `--cookie, -c=COOKIES` - Set initial cookies manually
- `--cookie-jar=FILE` - Load cookies from file
- `--no-cookies` - Disable automatic cookie handling
**Performance Note:** With high thread counts (>100), cookie handling may impact performance. Use `--no-cookies` for maximum speed on large scans.
PROXY:
--proxy <hostname[:port]> Set proxy hostname and port.
Default: 8080.
--proxy-user <username:password> Set proxy user and password.