
Shell-basiertes CMS-Erkennungs- und Exploit-Kit, das 330+ Content-Management-Systeme identifiziert und dann automatisierte Sicherheitsaudits und Exploitation-Tools gegen erkannte Ziele startet.
CMS Erkennungs- und Exploit-Kit basierend auf der Whatcms.org API.
Whatcms.sh kann derzeit die Nutzung von mehr als 330 verschiedenen CMS-Applikationen und -Diensten erkennen und anschließend eine Liste von geeigneten Sicherheits-Audit-Tools für das erkannte CMS anzeigen.
Sie benötigen den whatcms.org-API-Schlüssel, um das Tool zu nutzen:
Usage: ./whatcms.sh example.com
-h Display help message
-wh Check hosting details
--tools Display tools information

| TOOLS | NUTZUNG | REPO-URL |
|---|---|---|
| Dumb0 | Benutzername-Scanner-Tool | https://github.com/0verl0ad/Dumb0/ |
| CMSsc4n | Identifikationstool | https://github.com/n4xh4ck5/CMSsc4n |
| Puppet | Identifikationstool | https://github.com/Poil/puppet-websites-facts |
| pyfiscan | Identifikationstool | https://github.com/fgeek/pyfiscan |
| XAttacker | Exploit-Tool | https://github.com/Moham3dRiahi/XAttacker |
| beecms | Exploit-Tool | https://github.com/CHYbeta/cmsPoc |
| CMSXPL | Exploit-Tool | https://github.com/tanprathan/CMS-XPL |
| JMassExploiter | Exploit-Tool | https://github.com/anarcoder/JoomlaMassExploiter |
| WPMassExploiter | Exploit-Tool | https://github.com/anarcoder/WordPressMassExploiter |
| CMSExpFram | Exploit-Tool | https://github.com/Q2h1Cg/CMS-Exploit-Framework |
| LotusXploit | Exploit-Tool | https://github.com/Hood3dRob1n/LotusCMS-Exploit |
| BadMod | Exploit-Tool | https://github.com/MrSqar-Ye/BadMod |
| M0B | Exploit-Tool | https://github.com/mobrine-mob/M0B-tool |
| LetMeFuckIt | Exploit-Tool | https://github.com/onthefrontline/LetMeFuckIt-Scanner |
| magescan | Exploit-Tool | https://github.com/steverobbins/magescan |
| PRESTA | Exploit-Tool | https://github.com/AlisamTechnology/PRESTA-modules-shell-exploit |
| EktronE | Exploit-Tool | https://github.com/tomkallo/Ektron_CMS_8.02_exploit |
| XBruteForcer | Brute-Force-Tool | https://github.com/Moham3dRiahi/XBruteForcer |
| CoMisSion | Analyse-Tool | https://github.com/Intrinsec/comission |
| droopescan | Analyse-Tool | https://github.com/droope/droopescan |
| CMSmap | Analyse-Tool | https://github.com/Dionach/CMSmap |
| JoomScan | Analyse-Tool | https://github.com/rezasp/joomscan |
| VBScan | Analyse-Tool | https://github.com/rezasp/vbscan |
| JoomlaScan | Analyse-Tool | https://github.com/drego85/JoomlaScan |
| c5scan | Analyse-Tool | https://github.com/auraltension/c5scan |
| T3scan | Analyse-Tool | https://github.com/Oblady/T3Scan |
| moodlescan | Analyse-Tool | https://github.com/inc0d3/moodlescan |
| SPIPScan | Analyse-Tool | https://github.com/PaulSec/SPIPScan |
| WPHunter | Analyse-Tool | https://github.com/aryanrtm/WP-Hunter |
| WPSeku | Analyse-Tool | https://github.com/m4ll0k/WPSeku |
| ACDrupal | Analyse-Tool | https://github.com/mrmtwoj/ac-drupal |
| Plown | Analyse-Tool | https://github.com/unweb/plown |
| conscan | Analyse-Tool | https://github.com/nullsecuritynet/tools/tree/master/scanner/conscan |
| CMSScanner | Analyse-Tool | https://github.com/CMS-Garden/cmsscanner |
| cmsExplorer | Analyse-Tool | https://code.google.com/archive/p/cms-explorer |
| WPScan | Analyse-Tool | https://github.com/wpscanteam/wpscan |
| MooScan | Analyse-Tool | https://github.com/vortexau/mooscan |
| Scanners | Analyse-Tool | https://github.com/b3o1/Scanners |
| LiferayScan | Analyse-Tool | https://github.com/bcoles/LiferayScan |
| InfoLeak | Analyse-Tool | https://github.com/SIWECOS/InfoLeak-Scanner |
| joomlavs | Analyse-Tool | https://github.com/rastating/joomlavs |
| WAScan | Analyse-Tool | https://github.com/m4ll0k/WAScan |
| RedHawk | Analyse-Tool | https://github.com/Tuhinshubhra/RED_HAWK |
| HostileSBF | Analyse-Tool | https://github.com/nahamsec/HostileSubBruteforcer |