← All cheat sheets

WAPITI

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Wapiti is a web application vulnerability scanner that performs
black-box testing. It crawls web pages, identifies forms and scripts,
and tests for vulnerabilities including SQL injection, XSS, file
disclosure, command execution, and more.

BASIC USAGE#

wapiti -u <url>                  # Scan target URL
wapiti -u <url> -o <report>      # Scan with report output

SCAN OPTIONS#

wapiti -u <url>                  # Target URL
wapiti -s <url>                  # Start scanning from specific URL
wapiti --scope page              # Scan only the target page
wapiti --scope folder            # Scan only the target directory
wapiti --scope domain            # Scan entire domain (default)
wapiti --scope punk              # Scan everything
wapiti -d <depth>                # Crawl depth limit
wapiti -m <modules>              # Select specific modules
wapiti --max-links <n>           # Max links to follow
wapiti --max-files <n>           # Max forms to test
wapiti --max-scan-time <secs>    # Max scan duration
wapiti --max-attack-time <secs>  # Max attack time per module

MODULES (-m)#

wapiti -u <url> -m all           # All modules (default)
wapiti -u <url> -m sql           # SQL injection
wapiti -u <url> -m xss           # Cross-Site Scripting
wapiti -u <url> -m xxe           # XML External Entity
wapiti -u <url> -m exec          # Command execution
wapiti -u <url> -m file          # File handling (LFI/path traversal)
wapiti -u <url> -m crlf          # CRLF injection
wapiti -u <url> -m htaccess      # .htaccess bypass
wapiti -u <url> -m backup        # Backup file discovery
wapiti -u <url> -m nikto         # Nikto-like checks
wapiti -u <url> -m shellshock    # Shellshock vulnerability
wapiti -u <url> -m ssrf          # Server-Side Request Forgery
wapiti -u <url> -m redirect      # Open redirect
wapiti -u <url> -m csrf          # Cross-Site Request Forgery
wapiti -u <url> -m cookieflags   # Cookie security flags
wapiti -u <url> -m csp           # Content Security Policy
wapiti -u <url> -m wapp          # Web application fingerprint
wapiti -u <url> -m log4shell     # Log4Shell (CVE-2021-44228)
wapiti -u <url> -m spring4shell  # Spring4Shell
wapiti -u <url> -m "sql,xss,exec"
                                 # Multiple specific modules

AUTHENTICATION#

wapiti -u <url> --auth-cred "user%pass"
                                 # HTTP Basic/Digest auth
wapiti -u <url> --cookie "PHPSESSID=abc123"
                                 # Use cookies
wapiti -u <url> --cookie <cookie_file>
                                 # Load cookies from file
wapiti -u <url> --form-cred "user%pass"
                                 # Form-based authentication
wapiti -u <url> --form-url <login_url>
                                 # Login form URL

PROXY & NETWORK#

wapiti -u <url> -p http://127.0.0.1:8080
                                 # HTTP proxy (e.g., Burp)
wapiti -u <url> --verify-ssl 0   # Disable SSL verification
wapiti -u <url> -a "CustomAgent" # Custom User-Agent
wapiti -u <url> -H "X-Custom: v" # Custom header
wapiti -u <url> --timeout <secs> # Request timeout

OUTPUT OPTIONS#

wapiti -u <url> -o report.html -f html
                                 # HTML report
wapiti -u <url> -o report.json -f json
                                 # JSON report
wapiti -u <url> -o report.xml -f xml
                                 # XML report
wapiti -u <url> -o report.txt -f txt
                                 # Text report
wapiti -u <url> -v 1             # Verbose level 1
wapiti -u <url> -v 2             # Verbose level 2 (max)

CRAWL OPTIONS#

wapiti -u <url> --crawl-only     # Crawl without attacking
wapiti -u <url> -x <url_pattern> # Exclude URLs from scan
wapiti -u <url> -r <url_pattern> # Remove URLs from scan
wapiti -u <url> --skip-crawl     # Skip crawl, test only seed URL

EXAMPLES#

# Full scan with HTML report
wapiti -u http://target.com -o /tmp/report.html -f html

# SQL injection and XSS only
wapiti -u http://target.com -m "sql,xss"

# Scan with authentication
wapiti -u http://target.com --form-cred "admin%password" --form-url http://target.com/login

# Scan through Burp proxy
wapiti -u http://target.com -p http://127.0.0.1:8080 --verify-ssl 0

# Quick scan with depth limit
wapiti -u http://target.com -d 3 --max-scan-time 3600

# Crawl only (no attacks)
wapiti -u http://target.com --crawl-only -o crawl.json -f json

NOTES#

- Python-based tool
- Black-box testing (no source code needed)
- Crawls before attacking (two-phase approach)
- Supports pause/resume of scans
- Database of known attack payloads
- Can detect both reflected and stored XSS
- HTML reports with color-coded severities
- Actively maintained and updated
- Good alternative to commercial scanners