Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
工具/GitHubGitHub/urbanadventurer/whatweb
OSINT (开源情报)侦察漏洞扫描器Web漏洞扫描器网络映射动态代码分析 (DAST)Web应用程序漏洞利用信息收集WAF绕过Web安全渗透测试网络爬虫
6.8k1.0k1156个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网络爬虫 分类第 12 名
动态代码分析 (DAST) 分类第 17 名
信息收集 分类第 8 名
侦察 分类第 20 名
WAF绕过 分类第 17 名
Web应用程序漏洞利用 分类第 12 名
Web安全 分类第 11 名
Web漏洞扫描器 分类第 17 名
GitHuburbanadventurer/whatweb

WhatWeb

下一代 Web 扫描器

查看仓库网站

License Stable Release WhatWeb Plugins Repositories

logo

WhatWeb - 下一代网络扫描器

由 Andrew Horton urbanadventurer 与 Brendan Coles bcoles 开发

最新发布:v0.6.4. 2026年4月3日

许可证:GPLv2

本产品受许可协议中详述的条款约束。有关 WhatWeb 的更多信息,请访问 https://github.com/urbanadventurer/

Wiki:https://github.com/urbanadventurer/WhatWeb/wiki/

如果您对 WhatWeb 有任何问题、评论或疑虑,请在联系开发者之前查阅文档。我们始终欢迎您的反馈。

目录

  • 关于 WhatWeb
  • 示例用法
  • 用法
  • 日志与输出
  • 插件
  • 攻击级别
  • 性能与稳定性
  • 可选依赖
  • 编写插件
  • 更新与附加信息
  • 发布历史
  • 致谢

关于 WhatWeb

WhatWeb 识别网站。它的目标是回答“那是什么网站?”这个问题。WhatWeb 能够识别网页技术,包括内容管理系统(CMS)、博客平台、统计/分析包、JavaScript 库、Web 服务器和嵌入式设备。WhatWeb 拥有超过 1800 个插件,每个插件用于识别不同的内容。WhatWeb 还能识别版本号、电子邮件地址、账户 ID、Web 框架模块、SQL 错误等等。

WhatWeb 可以隐蔽而快速,也可以彻底但缓慢。WhatWeb 支持攻击级别来控制速度与可靠性之间的权衡。当您在浏览器中访问网站时,该事务包含了许多关于该网站由哪些 Web 技术驱动的线索。有时,仅访问一个网页就足以识别网站,但当信息不足时,WhatWeb 可以进一步询问网站。默认的攻击级别称为 'stealthy',是最快的,只需对网站发出一次 HTTP 请求。这适合扫描公共网站。更高级的攻击模式是为渗透测试而开发的。

大多数 WhatWeb 插件都很彻底,能够识别从细微到明显的一系列线索。例如,大多数 WordPress 网站可以通过 meta HTML 标签来识别,例如 '',但少数 WordPress 网站会移除这个识别标签,不过这并不能难倒 WhatWeb。WordPress 的 WhatWeb 插件有超过 15 项测试,包括检查 favicon、默认安装文件、登录页面,以及检查相对链接中的 "/wp-content/"。

功能

  • 超过 1800 个插件
  • 控制速度/隐蔽性与可靠性之间的权衡
  • 性能调优。通过自动输出优化控制并发扫描的网站数量。
  • 多种日志格式:简要(可 grep)、详细(人类可读)、XML、JSON、MagicTree、RubyObject、MongoDB、ElasticSearch、SQL。
  • 代理支持,包括 TOR
  • 自定义 HTTP 请求头
  • HTTP 基本认证
  • 控制网页重定向
  • IP 地址范围
  • 模糊匹配
  • 结果确定性感知
  • 在命令行上定义自定义插件
  • 支持 IDN(国际域名)
  • 对简单主机名进行双协议扫描(自动测试 HTTP 和 HTTPS)

示例用法

使用 WhatWeb 扫描 reddit.com。``` $ ./whatweb reddit.com http://reddit.com [301 Moved Permanently] Country[UNITED STATES][US], HTTPServer[snooserv], IP[151.101.65.140], RedirectLocation[https://www.reddit.com/], UncommonHeaders[retry-after,x-served-by,x-cache-hits,x-timer], Via-Proxy[1.1 varnish] https://www.reddit.com/ [200 OK] Cookies[edgebucket,eu_cookie_v2,loid,rabt,rseor3,session_tracker,token], Country[UNITED STATES][US], Email[[email protected],[email protected]], Frame, HTML5, HTTPServer[snooserv], HttpOnly[token], IP[151.101.37.140], Open-Graph-Protocol[website], Script[text/javascript], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], Title[reddit: the front page of the internet], UncommonHeaders[fastly-restarts,x-served-by,x-cache-hits,x-timer], Via-Proxy[1.1 varnish], X-Frame-Options[SAMEORIGIN]

## 用法```

.$$$     $.                                   .$$$     $.         
$$$$     $$. .$$$  $$$ .$$$$$$.  .$$$$$$$$$$. $$$$     $$. .$$$$$$$. .$$$$$$. 
$ $$     $$$ $ $$  $$$ $ $$$$$$. $$$$$ $$$$$$ $ $$     $$$ $ $$   $$ $ $$$$$$.
$ `$     $$$ $ `$  $$$ $ `$  $$$ $$' $ `$ `$$ $ `$     $$$ $ `$      $ `$  $$$'
$. $     $$$ $. $$$$$$ $. $$$$$$ `$  $. $  :' $. $     $$$ $. $$$$   $. $$$$$.
$::$  .  $$$ $::$  $$$ $::$  $$$     $::$     $::$  .  $$$ $::$      $::$  $$$$
$;;$ $$$ $$$ $;;$  $$$ $;;$  $$$     $;;$     $;;$ $$$ $$$ $;;$      $;;$  $$$$
$$$$$$ $$$$$ $$$$  $$$ $$$$  $$$     $$$$     $$$$$$ $$$$$ $$$$$$$$$ $$$$$$$$$'

WhatWeb - Next generation web scanner version 0.6.4.
Developed by Andrew Horton (urbanadventurer) and Brendan Coles (bcoles)
Homepage: https://morningstarsecurity.com/research/whatweb

Usage: whatweb [options] <URLs>

TARGET SELECTION:
  <TARGETs>             Enter URLs, hostnames, IP addresses, filenames or
                        IP ranges in CIDR, x.x.x-x, or x.x.x.x-x.x.x.x
                        format.
  --input-file=FILE, -i Read targets from a file. You can pipe
                        hostnames or URLs directly with -i /dev/stdin.

TARGET MODIFICATION:
  --url-prefix          Add a prefix to target URLs.
  --url-suffix          Add a suffix to target URLs.
  --url-pattern         Insert the targets into a URL. Requires --input-file,
                        eg. www.example.com/%insert%/robots.txt 

AGGRESSION:
  The aggression level controls the trade-off between speed/stealth and
  reliability.
  --aggression, -a=LEVEL Set the aggression level. Default: 1.
  Aggression levels are:
  1. Stealthy   Makes one HTTP request per target. Also follows redirects.
  3. Aggressive If a level 1 plugin is matched, additional requests will be
      made.
  4. Heavy      Makes a lot of HTTP requests per target. Aggressive tests from
      all plugins are used for all URLs.

HTTP OPTIONS:
  --user-agent, -U=AGENT Identify as AGENT instead of WhatWeb/0.6.3.
  --header, -H          Add an HTTP header. eg "Foo:Bar". Specifying a default
                        header will replace it. Specifying an empty value, eg.
                        "User-Agent:" will remove the header.
  --follow-redirect=WHEN Control when to follow redirects. WHEN may be `never',
                        `http-only', `meta-only', `same-site', or `always'.
                        Default: always.
  --max-redirects=NUM   Maximum number of contiguous redirects. Default: 10.

AUTHENTICATION:
  --user, -u=<user:password> HTTP basic authentication.
  --cookie, -c=COOKIES  Provide cookies, e.g. 'name=value; name2=value2'.
  --cookiejar=FILE      Read cookies from a file.
  --no-cookies          Disable automatic cookie handling (improves performance 
                        with high thread counts).

### Cookie Handling

WhatWeb automatically handles cookies across redirects by default. This improves fingerprinting accuracy on sites requiring session management.

- `--cookie, -c=COOKIES`  - Set initial cookies manually
- `--cookie-jar=FILE`  - Load cookies from file  
- `--no-cookies`  - Disable automatic cookie handling

**Performance Note:** With high thread counts (>100), cookie handling may impact performance. Use `--no-cookies` for maximum speed on large scans.

PROXY:
  --proxy           <hostname[:port]> Set proxy hostname and port.
                    Default: 8080.
  --proxy-user      <username:password> Set proxy user and password.

PLUGINS:
  --list-plugins, -l            List all plugins.
  --info-plugins, -I=[SEARCH]   List all plugins with detailed information.
                                Optionally search with keywords in a comma
                                delimited list.
  --search-plugins=STRING       Search plugins for a keyword.
  --plugins, -p=LIST  Select plugins. LIST is a comma delimited set of 
                      selected plugins. Default is all.
                      Each element can be a directory, file or plugin name and
                      can optionally have a modifier, eg. + or -
                      Examples: +/tmp/moo.rb,+/tmp/foo.rb
                      title,md5,+./plugins-disabled/
                      ./plugins-disabled,-md5
                      -p + is a shortcut for -p +plugins-disabled.

  --grep, -g=STRING|REGEXP      Search for STRING or a Regular Expression. Shows 
                                only the results that match.
                                Examples: --grep "hello"
                                --grep "/he[l]*o/"
  --custom-plugin=DEFINITION  Define a custom plugin named Custom-Plugin,
                        Examples: ":text=>'powered by abc'"
                        ":version=>/powered[ ]?by ab[0-9]/"
                        ":ghdb=>'intitle:abc \"powered by abc\"'"
                        ":md5=>'8666257030b94d3bdb46e05945f60b42'"
  --dorks=PLUGIN        List Google dorks for the selected plugin.
下载工具