
Kit basato su shell per il rilevamento e lo sfruttamento di CMS che identifica oltre 330 sistemi di gestione dei contenuti, per poi lanciare audit di sicurezza automatizzati e strumenti di sfruttamento contro i target rilevati.
Kit di rilevamento e sfruttamento di CMS basato sull'API di Whatcms.org.
Whatcms.sh è attualmente in grado di rilevare l'uso di più di 330 diversi CMS applicazioni e servizi per poi indicare un elenco di strumenti validi per audit di sicurezza per il CMS rilevato.
È necessaria l'API di whatcms.org per utilizzare lo strumento:
Usage: ./whatcms.sh example.com
-h Display help message
-wh Check hosting details
--tools Display tools information

| STRUMENTI | UTILITÀ | URL REPO |
|---|---|---|
| Dumb0 | Strumento di scraping degli username | https://github.com/0verl0ad/Dumb0/ |
| CMSsc4n | Strumento di identificazione | https://github.com/n4xh4ck5/CMSsc4n |
| Puppet | Strumento di identificazione | https://github.com/Poil/puppet-websites-facts |
| pyfiscan | Strumento di identificazione | https://github.com/fgeek/pyfiscan |
| XAttacker | Strumento di exploit | https://github.com/Moham3dRiahi/XAttacker |
| beecms | Strumento di exploit | https://github.com/CHYbeta/cmsPoc |
| CMSXPL | Strumento di exploit | https://github.com/tanprathan/CMS-XPL |
| JMassExploiter | Strumento di exploit | https://github.com/anarcoder/JoomlaMassExploiter |
| WPMassExploiter | Strumento di exploit | https://github.com/anarcoder/WordPressMassExploiter |
| CMSExpFram | Strumento di exploit | https://github.com/Q2h1Cg/CMS-Exploit-Framework |
| LotusXploit | Strumento di exploit | https://github.com/Hood3dRob1n/LotusCMS-Exploit |
| BadMod | Strumento di exploit | https://github.com/MrSqar-Ye/BadMod |
| M0B | Strumento di exploit | https://github.com/mobrine-mob/M0B-tool |
| LetMeFuckIt |
| Strumento di exploit |
| https://github.com/onthefrontline/LetMeFuckIt-Scanner |
| magescan | Strumento di exploit | https://github.com/steverobbins/magescan |
| PRESTA | Strumento di exploit | https://github.com/AlisamTechnology/PRESTA-modules-shell-exploit |
| EktronE | Strumento di exploit | https://github.com/tomkallo/Ektron_CMS_8.02_exploit |
| XBruteForcer | Strumento di forza bruta | https://github.com/Moham3dRiahi/XBruteForcer |
| CoMisSion | Strumento di analisi | https://github.com/Intrinsec/comission |
| droopescan | Strumento di analisi | https://github.com/droope/droopescan |
| CMSmap | Strumento di analisi | https://github.com/Dionach/CMSmap |
| JoomScan | Strumento di analisi | https://github.com/rezasp/joomscan |
| VBScan | Strumento di analisi | https://github.com/rezasp/vbscan |
| JoomlaScan | Strumento di analisi | https://github.com/drego85/JoomlaScan |
| c5scan | Strumento di analisi | https://github.com/auraltension/c5scan |
| T3scan | Strumento di analisi | https://github.com/Oblady/T3Scan |
| moodlescan | Strumento di analisi | https://github.com/inc0d3/moodlescan |
| SPIPScan | Strumento di analisi | https://github.com/PaulSec/SPIPScan |
| WPHunter | Strumento di analisi | https://github.com/aryanrtm/WP-Hunter |
| WPSeku | Strumento di analisi | https://github.com/m4ll0k/WPSeku |
| ACDrupal | Strumento di analisi | https://github.com/mrmtwoj/ac-drupal |
| Plown | Strumento di analisi | https://github.com/unweb/plown |
| conscan | Strumento di analisi | https://github.com/nullsecuritynet/tools/tree/master/scanner/conscan |
| CMSScanner | Strumento di analisi | https://github.com/CMS-Garden/cmsscanner |
| cmsExplorer | Strumento di analisi | https://code.google.com/archive/p/cms-explorer |
| WPScan | Strumento di analisi | https://github.com/wpscanteam/wpscan |
| MooScan | Strumento di analisi | https://github.com/vortexau/mooscan |
| Scanners | Strumento di analisi | https://github.com/b3o1/Scanners |
| LiferayScan | Strumento di analisi | https://github.com/bcoles/LiferayScan |
| InfoLeak | Strumento di analisi | https://github.com/SIWECOS/InfoLeak-Scanner |
| joomlavs | Strumento di analisi | https://github.com/rastating/joomlavs |
| WAScan | Strumento di analisi | https://github.com/m4ll0k/WAScan |
| RedHawk | Strumento di analisi | https://github.com/Tuhinshubhra/RED_HAWK |
| HostileSBF | Strumento di analisi | https://github.com/nahamsec/HostileSubBruteforcer |