
अगली पीढ़ी का वेब स्कैनर
एंड्रयू हॉर्टन urbanadventurer और ब्रेंडन कोल्स bcoles द्वारा विकसित
नवीनतम रिलीज़: v0.6.4। 3 अप्रैल, 2026
लाइसेंस: GPLv2
यह उत्पाद लाइसेंस समझौते में विस्तृत शर्तों के अधीन है। WhatWeb के बारे में अधिक जानकारी के लिए https://github.com/urbanadventurer/ पर जाएँ।
विकी: https://github.com/urbanadventurer/WhatWeb/wiki/
यदि आपके पास WhatWeb के संबंध में कोई प्रश्न, टिप्पणी या चिंताएँ हैं, तो किसी डेवलपर से संपर्क करने से पहले कृपया दस्तावेज़ देखें। आपकी प्रतिक्रिया का हमेशा स्वागत है।
WhatWeb वेबसाइटों की पहचान करता है। इसका लक्ष्य इस प्रश्न का उत्तर देना है, "वह वेबसाइट क्या है?"। WhatWeb वेब तकनीकों की पहचान करता है जिनमें कंटेंट प्रबंधन प्रणालियाँ (CMS), ब्लॉगिंग प्लेटफ़ॉर्म, सांख्यिकी/विश्लेषण पैकेज, जावास्क्रिप्ट लाइब्रेरी, वेब सर्वर और एम्बेडेड डिवाइस शामिल हैं। WhatWeb के पास 1800 से अधिक प्लगइन्स हैं, प्रत्येक कुछ अलग पहचानने के लिए। WhatWeb संस्करण संख्याओं, ईमेल पतों, खाता ID, वेब फ्रेमवर्क मॉड्यूल, SQL त्रुटियों और अधिक की भी पहचान करता है।
WhatWeb गुप्त (stealthy) और तेज़, या गहन लेकिन धीमा हो सकता है। WhatWeb गति और विश्वसनीयता के बीच समझौते को नियंत्रित करने के लिए आक्रामकता स्तर (aggression level) का समर्थन करता है। जब आप अपने ब्राउज़र में किसी वेबसाइट पर जाते हैं, तो लेन-देन में कई संकेत शामिल होते हैं कि उस वेबसाइट को कौन सी वेब तकनीकें शक्ति दे रही हैं। कभी-कभी एक ही वेबपेज विज़िट किसी वेबसाइट की पहचान करने के लिए पर्याप्त जानकारी रखती है, लेकिन जब ऐसा नहीं होता है, तो WhatWeb वेबसाइट की और अधिक जाँच कर सकता है। आक्रामकता का डिफ़ॉल्ट स्तर, जिसे 'stealthy' कहा जाता है, सबसे तेज़ है और इसके लिए वेबसाइट की केवल एक HTTP अनुरोध की आवश्यकता होती है। यह सार्वजनिक वेबसाइटों को स्कैन करने के लिए उपयुक्त है। अधिक आक्रामक मोड पेनेट्रेशन परीक्षणों में उपयोग के लिए विकसित किए गए थे।
अधिकांश WhatWeb प्लगइन्स गहन होते हैं और सूक्ष्म से स्पष्ट तक कई प्रकार के संकेतों को पहचानते हैं। उदाहरण के लिए, अधिकांश WordPress वेबसाइटों की पहचान मेटा HTML टैग से की जा सकती है, जैसे '', लेकिन कुछ WordPress वेबसाइटें इस पहचान टैग को हटा देती हैं, फिर भी यह WhatWeb को विफल नहीं करता। WordPress के लिए WhatWeb प्लगइन में 15 से अधिक परीक्षण हैं, जिनमें favicon की जाँच, डिफ़ॉल्ट इंस्टॉलेशन फ़ाइलें, लॉगिन पेज और सापेक्ष लिंक के भीतर "/wp-content/" की जाँच शामिल है।
reddit.com को स्कैन करने के लिए WhatWeb का उपयोग करना।``` $ ./whatweb reddit.com http://reddit.com [301 Moved Permanently] Country[UNITED STATES][US], HTTPServer[snooserv], IP[151.101.65.140], RedirectLocation[https://www.reddit.com/], UncommonHeaders[retry-after,x-served-by,x-cache-hits,x-timer], Via-Proxy[1.1 varnish] https://www.reddit.com/ [200 OK] Cookies[edgebucket,eu_cookie_v2,loid,rabt,rseor3,session_tracker,token], Country[UNITED STATES][US], Email[[email protected],[email protected]], Frame, HTML5, HTTPServer[snooserv], HttpOnly[token], IP[151.101.37.140], Open-Graph-Protocol[website], Script[text/javascript], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], Title[reddit: the front page of the internet], UncommonHeaders[fastly-restarts,x-served-by,x-cache-hits,x-timer], Via-Proxy[1.1 varnish], X-Frame-Options[SAMEORIGIN]
## उपयोग```
.$$$ $. .$$$ $.
$$$$ $$. .$$$ $$$ .$$$$$$. .$$$$$$$$$$. $$$$ $$. .$$$$$$$. .$$$$$$.
$ $$ $$$ $ $$ $$$ $ $$$$$$. $$$$$ $$$$$$ $ $$ $$$ $ $$ $$ $ $$$$$$.
$ `$ $$$ $ `$ $$$ $ `$ $$$ $$' $ `$ `$$ $ `$ $$$ $ `$ $ `$ $$$'
$. $ $$$ $. $$$$$$ $. $$$$$$ `$ $. $ :' $. $ $$$ $. $$$$ $. $$$$$.
$::$ . $$$ $::$ $$$ $::$ $$$ $::$ $::$ . $$$ $::$ $::$ $$$$
$;;$ $$$ $$$ $;;$ $$$ $;;$ $$$ $;;$ $;;$ $$$ $$$ $;;$ $;;$ $$$$
$$$$$$ $$$$$ $$$$ $$$ $$$$ $$$ $$$$ $$$$$$ $$$$$ $$$$$$$$$ $$$$$$$$$'
WhatWeb - Next generation web scanner version 0.6.4.
Developed by Andrew Horton (urbanadventurer) and Brendan Coles (bcoles)
Homepage: https://morningstarsecurity.com/research/whatweb
Usage: whatweb [options] <URLs>
TARGET SELECTION:
<TARGETs> Enter URLs, hostnames, IP addresses, filenames or
IP ranges in CIDR, x.x.x-x, or x.x.x.x-x.x.x.x
format.
--input-file=FILE, -i Read targets from a file. You can pipe
hostnames or URLs directly with -i /dev/stdin.
TARGET MODIFICATION:
--url-prefix Add a prefix to target URLs.
--url-suffix Add a suffix to target URLs.
--url-pattern Insert the targets into a URL. Requires --input-file,
eg. www.example.com/%insert%/robots.txt
AGGRESSION:
The aggression level controls the trade-off between speed/stealth and
reliability.
--aggression, -a=LEVEL Set the aggression level. Default: 1.
Aggression levels are:
1. Stealthy Makes one HTTP request per target. Also follows redirects.
3. Aggressive If a level 1 plugin is matched, additional requests will be
made.
4. Heavy Makes a lot of HTTP requests per target. Aggressive tests from
all plugins are used for all URLs.
HTTP OPTIONS:
--user-agent, -U=AGENT Identify as AGENT instead of WhatWeb/0.6.3.
--header, -H Add an HTTP header. eg "Foo:Bar". Specifying a default
header will replace it. Specifying an empty value, eg.
"User-Agent:" will remove the header.
--follow-redirect=WHEN Control when to follow redirects. WHEN may be `never',
`http-only', `meta-only', `same-site', or `always'.
Default: always.
--max-redirects=NUM Maximum number of contiguous redirects. Default: 10.
AUTHENTICATION:
--user, -u=<user:password> HTTP basic authentication.
--cookie, -c=COOKIES Provide cookies, e.g. 'name=value; name2=value2'.
--cookiejar=FILE Read cookies from a file.
--no-cookies Disable automatic cookie handling (improves performance
with high thread counts).
### Cookie Handling
WhatWeb automatically handles cookies across redirects by default. This improves fingerprinting accuracy on sites requiring session management.
- `--cookie, -c=COOKIES` - Set initial cookies manually
- `--cookie-jar=FILE` - Load cookies from file
- `--no-cookies` - Disable automatic cookie handling
**Performance Note:** With high thread counts (>100), cookie handling may impact performance. Use `--no-cookies` for maximum speed on large scans.