Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
WhatWeb — 차세대 웹 스캐너 | Kitploit
도구/GitHubGitHub/urbanadventurer/whatweb
OSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersWeb Vulnerability ScannersNetwork MappingDynamic Code Analysis (DAST)Web Application ExploitationInformation GatheringWAF BypassWeb SecurityPenetration Testing
6.8k1.0k1156개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
Crawler
Crawler #12위
Dynamic Code Analysis (DAST) #17위
Information Gathering #8위
Reconnaissance #20위
WAF Bypass #17위
Web Application Exploitation #12위
Web Security #11위
Web Vulnerability Scanners #17위
GitHuburbanadventurer/whatweb

WhatWeb

차세대 웹 스캐너

저장소 보기웹사이트

License Stable Release WhatWeb Plugins Repositories

logo

WhatWeb - 차세대 웹 스캐너

개발자: Andrew Horton (urbanadventurer) 및 Brendan Coles (bcoles)

최신 릴리즈: v0.6.4. 2026년 4월 3일

라이선스: GPLv2

이 제품은 라이선스 계약에 명시된 조건을 따릅니다. WhatWeb에 대한 자세한 내용은 https://github.com/urbanadventurer/ 를 방문하세요.

위키: https://github.com/urbanadventurer/WhatWeb/wiki/

WhatWeb에 관한 질문, 의견 또는 우려 사항이 있으시면 개발자에게 연락하기 전에 문서를 먼저 참조하시기 바랍니다. 여러분의 피드백은 항상 환영합니다.

목차

  • WhatWeb 소개
  • 사용 예시
  • 사용법
  • 로깅 및 출력
  • 플러그인
  • 공격성
  • 성능 및 안정성
  • 선택적 종속성
  • 플러그인 작성
  • 업데이트 및 추가 정보
  • 릴리즈 기록
  • 크레딧

WhatWeb 소개

WhatWeb은 웹사이트를 식별합니다. 목표는 "그 웹사이트는 무엇인가?"라는 질문에 답하는 것입니다. WhatWeb은 콘텐츠 관리 시스템(CMS), 블로그 플랫폼, 통계/분석 패키지, JavaScript 라이브러리, 웹 서버, 임베디드 장치를 포함한 웹 기술을 인식합니다. WhatWeb은 1800개 이상의 플러그인을 보유하고 있으며, 각 플러그인은 서로 다른 것을 인식합니다. 또한 WhatWeb은 버전 번호, 이메일 주소, 계정 ID, 웹 프레임워크 모듈, SQL 오류 등을 식별합니다.

WhatWeb은 은밀하고 빠르게, 혹은 철저하지만 느리게 작동할 수 있습니다. WhatWeb은 속도와 신뢰성 사이의 균형을 제어하기 위해 공격성 수준을 지원합니다. 브라우저에서 웹사이트를 방문할 때, 트랜잭션에는 해당 웹사이트를 구동하는 웹 기술에 대한 많은 힌트가 포함됩니다. 때로는 단일 웹페이지 방문만으로 웹사이트를 식별하기에 충분한 정보를 얻을 수 있지만, 그렇지 않은 경우 WhatWeb은 웹사이트를 추가로 조사할 수 있습니다. 기본 공격성 수준인 '스텔스(stealthy)'는 가장 빠르며 웹사이트에 대해 하나의 HTTP 요청만 필요합니다. 이는 공개 웹사이트 스캔에 적합합니다. 보다 공격적인 모드는 침투 테스트에서 사용하기 위해 개발되었습니다.

대부분의 WhatWeb 플러그인은 철저하며 미묘한 단서부터 명백한 단서까지 다양한 신호를 인식합니다. 예를 들어, 대부분의 WordPress 웹사이트는 메타 HTML 태그(예: '')로 식별될 수 있지만, 일부 WordPress 웹사이트는 이 식별 태그를 제거하지만 WhatWeb을 막을 수는 없습니다. WordPress WhatWeb 플러그인은 15개 이상의 테스트를 가지고 있으며, 여기에는 파비콘 확인, 기본 설치 파일, 로그인 페이지, 상대 링크 내 "/wp-content/" 확인 등이 포함됩니다.

기능

  • 1800개 이상의 플러그인
  • 속도/은밀성과 신뢰성 사이의 균형 제어
  • 성능 튜닝. 자동 출력 최적화와 함께 동시에 스캔할 웹사이트 수를 제어합니다.
  • 다양한 로그 형식: 간결(그렙 가능), 상세(사람이 읽기 쉬움), XML, JSON, MagicTree, RubyObject, MongoDB, ElasticSearch, SQL.
  • 프록시 지원 (TOR 포함)
  • 사용자 정의 HTTP 헤더
  • 기본 HTTP 인증
  • 웹페이지 리디렉션 제어
  • IP 주소 범위
  • 퍼지 매칭
  • 결과 확실성 인식
  • 명령줄에서 정의하는 사용자 정의 플러그인
  • IDN(국제 도메인 이름) 지원
  • 단순 호스트 이름에 대한 이중 프로토콜 스캔 (HTTP와 HTTPS를 자동으로 테스트)

사용 예시

WhatWeb을 사용하여 reddit.com 스캔하기.``` $ ./whatweb reddit.com http://reddit.com [301 Moved Permanently] Country[UNITED STATES][US], HTTPServer[snooserv], IP[151.101.65.140], RedirectLocation[https://www.reddit.com/], UncommonHeaders[retry-after,x-served-by,x-cache-hits,x-timer], Via-Proxy[1.1 varnish] https://www.reddit.com/ [200 OK] Cookies[edgebucket,eu_cookie_v2,loid,rabt,rseor3,session_tracker,token], Country[UNITED STATES][US], Email[[email protected],[email protected]], Frame, HTML5, HTTPServer[snooserv], HttpOnly[token], IP[151.101.37.140], Open-Graph-Protocol[website], Script[text/javascript], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], Title[reddit: the front page of the internet], UncommonHeaders[fastly-restarts,x-served-by,x-cache-hits,x-timer], Via-Proxy[1.1 varnish], X-Frame-Options[SAMEORIGIN]

## 사용법```

.$$$     $.                                   .$$$     $.         
$$$$     $$. .$$$  $$$ .$$$$$$.  .$$$$$$$$$$. $$$$     $$. .$$$$$$$. .$$$$$$. 
$ $$     $$$ $ $$  $$$ $ $$$$$$. $$$$$ $$$$$$ $ $$     $$$ $ $$   $$ $ $$$$$$.
$ `$     $$$ $ `$  $$$ $ `$  $$$ $$' $ `$ `$$ $ `$     $$$ $ `$      $ `$  $$$'
$. $     $$$ $. $$$$$$ $. $$$$$$ `$  $. $  :' $. $     $$$ $. $$$$   $. $$$$$.
$::$  .  $$$ $::$  $$$ $::$  $$$     $::$     $::$  .  $$$ $::$      $::$  $$$$
$;;$ $$$ $$$ $;;$  $$$ $;;$  $$$     $;;$     $;;$ $$$ $$$ $;;$      $;;$  $$$$
$$$$$$ $$$$$ $$$$  $$$ $$$$  $$$     $$$$     $$$$$$ $$$$$ $$$$$$$$$ $$$$$$$$$'

WhatWeb - Next generation web scanner version 0.6.4.
Developed by Andrew Horton (urbanadventurer) and Brendan Coles (bcoles)
Homepage: https://morningstarsecurity.com/research/whatweb

Usage: whatweb [options] <URLs>

TARGET SELECTION:
  <TARGETs>             Enter URLs, hostnames, IP addresses, filenames or
                        IP ranges in CIDR, x.x.x-x, or x.x.x.x-x.x.x.x
                        format.
  --input-file=FILE, -i Read targets from a file. You can pipe
                        hostnames or URLs directly with -i /dev/stdin.

TARGET MODIFICATION:
  --url-prefix          Add a prefix to target URLs.
  --url-suffix          Add a suffix to target URLs.
  --url-pattern         Insert the targets into a URL. Requires --input-file,
                        eg. www.example.com/%insert%/robots.txt 

AGGRESSION:
  The aggression level controls the trade-off between speed/stealth and
  reliability.
  --aggression, -a=LEVEL Set the aggression level. Default: 1.
  Aggression levels are:
  1. Stealthy   Makes one HTTP request per target. Also follows redirects.
  3. Aggressive If a level 1 plugin is matched, additional requests will be
      made.
  4. Heavy      Makes a lot of HTTP requests per target. Aggressive tests from
      all plugins are used for all URLs.

HTTP OPTIONS:
  --user-agent, -U=AGENT Identify as AGENT instead of WhatWeb/0.6.3.
  --header, -H          Add an HTTP header. eg "Foo:Bar". Specifying a default
                        header will replace it. Specifying an empty value, eg.
                        "User-Agent:" will remove the header.
  --follow-redirect=WHEN Control when to follow redirects. WHEN may be `never',
                        `http-only', `meta-only', `same-site', or `always'.
                        Default: always.
  --max-redirects=NUM   Maximum number of contiguous redirects. Default: 10.

AUTHENTICATION:
  --user, -u=<user:password> HTTP basic authentication.
  --cookie, -c=COOKIES  Provide cookies, e.g. 'name=value; name2=value2'.
  --cookiejar=FILE      Read cookies from a file.
  --no-cookies          Disable automatic cookie handling (improves performance 
                        with high thread counts).

### Cookie Handling

WhatWeb automatically handles cookies across redirects by default. This improves fingerprinting accuracy on sites requiring session management.

- `--cookie, -c=COOKIES`  - Set initial cookies manually
- `--cookie-jar=FILE`  - Load cookies from file  
- `--no-cookies`  - Disable automatic cookie handling

**Performance Note:** With high thread counts (>100), cookie handling may impact performance. Use `--no-cookies` for maximum speed on large scans.

PROXY:
  --proxy           <hostname[:port]> Set proxy hostname and port.
                    Default: 8080.
  --proxy-user      <username:password> Set proxy user and password.

PLUGINS:
  --list-plugins, -l            List all plugins.
  --info-plugins, -I=[SEARCH]   List all plugins with detailed information.
                                Optionally search with keywords in a comma
                                delimited list.
  --search-plugins=STRING       Search plugins for a keyword.
  --plugins, -p=LIST  Select plugins. LIST is a comma delimited set of 
                      selected plugins. Default is all.
                      Each element can be a directory, file or plugin name and
                      can optionally have a modifier, eg. + or -
                      Examples: +/tmp/moo.rb,+/tmp/foo.rb
                      title,md5,+./plugins-disabled/
                      ./plugins-disabled,-md5
                      -p + is a shortcut for -p +plugins-disabled.
도구 다운로드