
शेल-आधारित CMS पहचान और एक्सप्लॉइट किट जो 330+ सामग्री प्रबंधन प्रणालियों की पहचान करती है, फिर पहचाने गए लक्ष्यों के विरुद्ध स्वचालित सुरक्षा ऑडिट और शोषण उपकरण लॉन्च करती है।
CMS पहचान और शोषण किट, Whatcms.org API पर आधारित।
Whatcms.sh वर्तमान में 330 से अधिक विभिन्न CMS अनुप्रयोगों और सेवाओं के उपयोग का पता लगा सकता है, ताकि बाद में पहचाने गए CMS के लिए मान्य सुरक्षा ऑडिट उपकरणों की एक सूची इंगित की जा सके।
इस उपकरण का उपयोग करने के लिए आपको whatcms.org API की आवश्यकता है:
उपयोग: ./whatcms.sh example.com
-h Display help message
-wh Check hosting details
--tools Display tools information

| उपकरण | उपयोगिता | रेपो URL |
|---|---|---|
| Dumb0 | उपयोगकर्ता नाम स्क्रैपर उपकरण | https://github.com/0verl0ad/Dumb0/ |
| CMSsc4n | पहचान उपकरण | https://github.com/n4xh4ck5/CMSsc4n |
| Puppet | पहचान उपकरण | https://github.com/Poil/puppet-websites-facts |
| pyfiscan | पहचान उपकरण | https://github.com/fgeek/pyfiscan |
| XAttacker | शोषण उपकरण | https://github.com/Moham3dRiahi/XAttacker |
| beecms | शोषण उपकरण | https://github.com/CHYbeta/cmsPoc |
| CMSXPL | शोषण उपकरण | https://github.com/tanprathan/CMS-XPL |
| JMassExploiter | शोषण उपकरण | https://github.com/anarcoder/JoomlaMassExploiter |
| WPMassExploiter | शोषण उपकरण | https://github.com/anarcoder/WordPressMassExploiter |
| CMSExpFram | शोषण उपकरण | https://github.com/Q2h1Cg/CMS-Exploit-Framework |
| LotusXploit | शोषण उपकरण | https://github.com/Hood3dRob1n/LotusCMS-Exploit |
| BadMod | शोषण उपकरण | https://github.com/MrSqar-Ye/BadMod |
| M0B | शोषण उपकरण | https://github.com/mobrine-mob/M0B-tool |
| LetMeFuckIt | शोषण उपकरण | https://github.com/onthefrontline/LetMeFuckIt-Scanner |
| magescan | शोषण उपकरण | https://github.com/steverobbins/magescan |
| PRESTA | शोषण उपकरण | https://github.com/AlisamTechnology/PRESTA-modules-shell-exploit |
| EktronE | शोषण उपकरण | https://github.com/tomkallo/Ektron_CMS_8.02_exploit |
| XBruteForcer | ब्रूट फोर्स उपकरण | https://github.com/Moham3dRiahi/XBruteForcer |
| CoMisSion | विश्लेषण उपकरण | https://github.com/Intrinsec/comission |
| droopescan | विश्लेषण उपकरण | https://github.com/droope/droopescan |
| CMSmap | विश्लेषण उपकरण | https://github.com/Dionach/CMSmap |
| JoomScan | विश्लेषण उपकरण | https://github.com/rezasp/joomscan |
| VBScan | विश्लेषण उपकरण | https://github.com/rezasp/vbscan |
| JoomlaScan | विश्लेषण उपकरण | https://github.com/drego85/JoomlaScan |
| c5scan | विश्लेषण उपकरण | https://github.com/auraltension/c5scan |
| T3scan | विश्लेषण उपकरण | https://github.com/Oblady/T3Scan |
| moodlescan | विश्लेषण उपकरण | https://github.com/inc0d3/moodlescan |
| SPIPScan | विश्लेषण उपकरण | https://github.com/PaulSec/SPIPScan |
| WPHunter | विश्लेषण उपकरण | https://github.com/aryanrtm/WP-Hunter |
| WPSeku | विश्लेषण उपकरण | https://github.com/m4ll0k/WPSeku |
| ACDrupal | विश्लेषण उपकरण | https://github.com/mrmtwoj/ac-drupal |
| Plown | विश्लेषण उपकरण | https://github.com/unweb/plown |
| conscan | विश्लेषण उपकरण | https://github.com/nullsecuritynet/tools/tree/master/scanner/conscan |
| CMSScanner | विश्लेषण उपकरण | https://github.com/CMS-Garden/cmsscanner |
| cmsExplorer | विश्लेषण उपकरण | https://code.google.com/archive/p/cms-explorer |
| WPScan | विश्लेषण उपकरण | https://github.com/wpscanteam/wpscan |
| MooScan | विश्लेषण उपकरण | https://github.com/vortexau/mooscan |
| Scanners | विश्लेषण उपकरण | https://github.com/b3o1/Scanners |
| LiferayScan | विश्लेषण उपकरण | https://github.com/bcoles/LiferayScan |
| InfoLeak | विश्लेषण उपकरण | https://github.com/SIWECOS/InfoLeak-Scanner |
| joomlavs | विश्लेषण उपकरण | https://github.com/rastating/joomlavs |
| WAScan | विश्लेषण उपकरण | https://github.com/m4ll0k/WAScan |
| RedHawk | विश्लेषण उपकरण | https://github.com/Tuhinshubhra/RED_HAWK |
| HostileSBF | विश्लेषण उपकरण | https://github.com/nahamsec/HostileSubBruteforcer |