← All cheat sheets

UNISCAN

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Uniscan is a web application vulnerability scanner that performs
fingerprinting, directory brute forcing, dynamic testing (LFI, RFI,
XSS, SQL injection), and stress testing against target websites.

BASIC USAGE#

uniscan -u <url> -qweds          # Full scan
uniscan -u <url> -q              # Directory check only

OPTIONS#

uniscan -u <url>                 # Target URL
uniscan -f <file>                # Target file (multiple URLs)
uniscan -b                       # Uniscan background mode
uniscan -q                       # Directory check (brute force)
uniscan -w                       # File check (common files)
uniscan -e                       # Dynamic testing (LFI, RFI, RCE)
uniscan -d                       # Dynamic testing (XSS, SQLi)
uniscan -s                       # Stress testing
uniscan -r                       # Crawler
uniscan -c                       # Enable use of crawler results
uniscan -j                       # Server fingerprint
uniscan -l                       # List available plugins
uniscan -o                       # Output to file
uniscan -g                       # Google search for targets
uniscan -i                       # Bing search for targets

SCAN TYPES#

# -q : Directory brute force
# Tries common directory names against the target

# -w : File check
# Checks for common sensitive files (config, backup, etc.)

# -e : Dynamic tests (LFI/RFI/RCE)
# - Local File Inclusion
# - Remote File Inclusion
# - Remote Command Execution

# -d : Dynamic tests (XSS/SQLi)
# - Cross-Site Scripting
# - SQL Injection

# -s : Stress test
# Sends multiple concurrent requests

EXAMPLES#

# Full vulnerability scan
uniscan -u http://target.com -qweds

# Directory brute force only
uniscan -u http://target.com -q

# Dynamic vulnerability testing
uniscan -u http://target.com -ed

# File and directory check
uniscan -u http://target.com -qw

# Crawl and then scan
uniscan -u http://target.com -rc -ed

# Server fingerprint
uniscan -u http://target.com -j

# Scan with Google target discovery
uniscan -g "site:example.com" -ed

DIRECTORY / FILE CHECKS#

# Directories checked (-q):
/admin/  /backup/  /config/  /data/
/database/  /debug/  /log/  /logs/
/old/  /temp/  /test/  /tmp/
/upload/  /uploads/  /private/

# Files checked (-w):
robots.txt  .htaccess  .htpasswd
wp-config.php  config.php  web.config
phpinfo.php  info.php  test.php
.git/HEAD  .svn/entries
crossdomain.xml  sitemap.xml

INTERPRETING RESULTS#

# [+] Vulnerability found: ...
# → Confirmed vulnerability detected

# [!] Alert: ...
# → Potential issue requiring manual verification

# Directory/file results show HTTP status:
# 200 = Exists and accessible
# 301/302 = Redirect (may still be interesting)
# 403 = Forbidden (exists but restricted)
# 404 = Not found

NOTES#

- Perl-based tool
- Combines multiple scanning techniques
- Can be noisy (many HTTP requests)
- Verify dynamic test findings manually
- May produce false positives
- Use -b for background scanning
- Results saved in /usr/share/uniscan/report/
- Consider OWASP ZAP for more thorough testing