WAPITI
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Wapiti is a web application vulnerability scanner that performs black-box testing. It crawls web pages, identifies forms and scripts, and tests for vulnerabilities including SQL injection, XSS, file disclosure, command execution, and more.
BASIC USAGE#
wapiti -u <url> # Scan target URL wapiti -u <url> -o <report> # Scan with report output
SCAN OPTIONS#
wapiti -u <url> # Target URL wapiti -s <url> # Start scanning from specific URL wapiti --scope page # Scan only the target page wapiti --scope folder # Scan only the target directory wapiti --scope domain # Scan entire domain (default) wapiti --scope punk # Scan everything wapiti -d <depth> # Crawl depth limit wapiti -m <modules> # Select specific modules wapiti --max-links <n> # Max links to follow wapiti --max-files <n> # Max forms to test wapiti --max-scan-time <secs> # Max scan duration wapiti --max-attack-time <secs> # Max attack time per module
MODULES (-m)#
wapiti -u <url> -m all # All modules (default)
wapiti -u <url> -m sql # SQL injection
wapiti -u <url> -m xss # Cross-Site Scripting
wapiti -u <url> -m xxe # XML External Entity
wapiti -u <url> -m exec # Command execution
wapiti -u <url> -m file # File handling (LFI/path traversal)
wapiti -u <url> -m crlf # CRLF injection
wapiti -u <url> -m htaccess # .htaccess bypass
wapiti -u <url> -m backup # Backup file discovery
wapiti -u <url> -m nikto # Nikto-like checks
wapiti -u <url> -m shellshock # Shellshock vulnerability
wapiti -u <url> -m ssrf # Server-Side Request Forgery
wapiti -u <url> -m redirect # Open redirect
wapiti -u <url> -m csrf # Cross-Site Request Forgery
wapiti -u <url> -m cookieflags # Cookie security flags
wapiti -u <url> -m csp # Content Security Policy
wapiti -u <url> -m wapp # Web application fingerprint
wapiti -u <url> -m log4shell # Log4Shell (CVE-2021-44228)
wapiti -u <url> -m spring4shell # Spring4Shell
wapiti -u <url> -m "sql,xss,exec"
# Multiple specific modules
AUTHENTICATION#
wapiti -u <url> --auth-cred "user%pass"
# HTTP Basic/Digest auth
wapiti -u <url> --cookie "PHPSESSID=abc123"
# Use cookies
wapiti -u <url> --cookie <cookie_file>
# Load cookies from file
wapiti -u <url> --form-cred "user%pass"
# Form-based authentication
wapiti -u <url> --form-url <login_url>
# Login form URL
PROXY & NETWORK#
wapiti -u <url> -p http://127.0.0.1:8080
# HTTP proxy (e.g., Burp)
wapiti -u <url> --verify-ssl 0 # Disable SSL verification
wapiti -u <url> -a "CustomAgent" # Custom User-Agent
wapiti -u <url> -H "X-Custom: v" # Custom header
wapiti -u <url> --timeout <secs> # Request timeout
OUTPUT OPTIONS#
wapiti -u <url> -o report.html -f html
# HTML report
wapiti -u <url> -o report.json -f json
# JSON report
wapiti -u <url> -o report.xml -f xml
# XML report
wapiti -u <url> -o report.txt -f txt
# Text report
wapiti -u <url> -v 1 # Verbose level 1
wapiti -u <url> -v 2 # Verbose level 2 (max)
CRAWL OPTIONS#
wapiti -u <url> --crawl-only # Crawl without attacking wapiti -u <url> -x <url_pattern> # Exclude URLs from scan wapiti -u <url> -r <url_pattern> # Remove URLs from scan wapiti -u <url> --skip-crawl # Skip crawl, test only seed URL
EXAMPLES#
# Full scan with HTML report wapiti -u http://target.com -o /tmp/report.html -f html # SQL injection and XSS only wapiti -u http://target.com -m "sql,xss" # Scan with authentication wapiti -u http://target.com --form-cred "admin%password" --form-url http://target.com/login # Scan through Burp proxy wapiti -u http://target.com -p http://127.0.0.1:8080 --verify-ssl 0 # Quick scan with depth limit wapiti -u http://target.com -d 3 --max-scan-time 3600 # Crawl only (no attacks) wapiti -u http://target.com --crawl-only -o crawl.json -f json
NOTES#
- Python-based tool - Black-box testing (no source code needed) - Crawls before attacking (two-phase approach) - Supports pause/resume of scans - Database of known attack payloads - Can detect both reflected and stored XSS - HTML reports with color-coded severities - Actively maintained and updated - Good alternative to commercial scanners