
셸 기반 CMS 탐지 및 익스플로잇 키트로, 330개 이상의 콘텐츠 관리 시스템을 식별한 후 탐지된 대상에 대해 자동화된 보안 감사 및 익스플로잇 도구를 실행합니다.
Whatcms.org API를 기반으로 한 CMS 탐지 및 익스플로잇 키트.
Whatcms.sh는 현재 330개 이상의 다양한 CMS 애플리케이션 및 서비스 사용을 탐지한 후, 탐지된 CMS에 대한 유효한 보안 감사 도구 목록을 제공할 수 있습니다.
도구를 사용하려면 whatcms.org API 키가 필요합니다:
사용법: ./whatcms.sh example.com
-h 도움말 메시지 표시
-wh 호스팅 세부 정보 확인
--tools 도구 정보 표시

| 도구 | 유틸리티 | 저장소 URL |
|---|---|---|
| Dumb0 | 사용자명 스크래퍼 도구 | https://github.com/0verl0ad/Dumb0/ |
| CMSsc4n | 식별 도구 | https://github.com/n4xh4ck5/CMSsc4n |
| Puppet | 식별 도구 | https://github.com/Poil/puppet-websites-facts |
| pyfiscan | 식별 도구 | https://github.com/fgeek/pyfiscan |
| XAttacker | 익스플로잇 도구 | https://github.com/Moham3dRiahi/XAttacker |
| beecms | 익스플로잇 도구 | https://github.com/CHYbeta/cmsPoc |
| CMSXPL | 익스플로잇 도구 | https://github.com/tanprathan/CMS-XPL |
| JMassExploiter | 익스플로잇 도구 | https://github.com/anarcoder/JoomlaMassExploiter |
| WPMassExploiter | 익스플로잇 도구 | https://github.com/anarcoder/WordPressMassExploiter |
| CMSExpFram | 익스플로잇 도구 | https://github.com/Q2h1Cg/CMS-Exploit-Framework |
| LotusXploit | 익스플로잇 도구 | https://github.com/Hood3dRob1n/LotusCMS-Exploit |
| BadMod | 익스플로잇 도구 | https://github.com/MrSqar-Ye/BadMod |
| M0B | 익스플로잇 도구 | https://github.com/mobrine-mob/M0B-tool |
| LetMeFuckIt | 익스플로잇 도구 | https://github.com/onthefrontline/LetMeFuckIt-Scanner |
| magescan | 익스플로잇 도구 | https://github.com/steverobbins/magescan |
| PRESTA | 익스플로잇 도구 | https://github.com/AlisamTechnology/PRESTA-modules-shell-exploit |
| EktronE | 익스플로잇 도구 | https://github.com/tomkallo/Ektron_CMS_8.02_exploit |
| XBruteForcer | 무차별 대입 도구 | https://github.com/Moham3dRiahi/XBruteForcer |
| CoMisSion | 분석 도구 | https://github.com/Intrinsec/comission |
| droopescan | 분석 도구 | https://github.com/droope/droopescan |
| CMSmap | 분석 도구 | https://github.com/Dionach/CMSmap |
| JoomScan | 분석 도구 | https://github.com/rezasp/joomscan |
| VBScan | 분석 도구 | https://github.com/rezasp/vbscan |
| JoomlaScan | 분석 도구 | https://github.com/drego85/JoomlaScan |
| c5scan | 분석 도구 | https://github.com/auraltension/c5scan |
| T3scan | 분석 도구 | https://github.com/Oblady/T3Scan |
| moodlescan | 분석 도구 | https://github.com/inc0d3/moodlescan |
| SPIPScan | 분석 도구 | https://github.com/PaulSec/SPIPScan |
| WPHunter | 분석 도구 | https://github.com/aryanrtm/WP-Hunter |
| WPSeku | 분석 도구 | https://github.com/m4ll0k/WPSeku |
| ACDrupal | 분석 도구 | https://github.com/mrmtwoj/ac-drupal |
| Plown | 분석 도구 | https://github.com/unweb/plown |
| conscan | 분석 도구 | https://github.com/nullsecuritynet/tools/tree/master/scanner/conscan |
| CMSScanner | 분석 도구 | https://github.com/CMS-Garden/cmsscanner |
| cmsExplorer | 분석 도구 | https://code.google.com/archive/p/cms-explorer |
| WPScan | 분석 도구 | https://github.com/wpscanteam/wpscan |
| MooScan | 분석 도구 | https://github.com/vortexau/mooscan |
| Scanners | 분석 도구 | https://github.com/b3o1/Scanners |
| LiferayScan | 분석 도구 | https://github.com/bcoles/LiferayScan |
| InfoLeak | 분석 도구 | https://github.com/SIWECOS/InfoLeak-Scanner |
| joomlavs | 분석 도구 | https://github.com/rastating/joomlavs |
| WAScan | 분석 도구 | https://github.com/m4ll0k/WAScan |
| RedHawk | 분석 도구 | https://github.com/Tuhinshubhra/RED_HAWK |
| HostileSBF | 분석 도구 | https://github.com/nahamsec/HostileSubBruteforcer |