← All cheat sheets

WEBSPLOIT

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

WebSploit is an open-source project for remote scanning and analysis
of network and web application vulnerabilities. It provides a
Metasploit-like console interface for various attack modules.

LAUNCHING#

websploit                        # Launch interactive console

BASIC COMMANDS#

help                             # Show available commands
show modules                     # List all modules
use <module>                     # Load a module
show options                     # Show module options
set <option> <value>             # Set option value
run                              # Execute module
back                             # Return to main menu
exit                             # Exit websploit
update                           # Update framework

WEB MODULES#

use web/dir_scanner              # Directory brute force
use web/pma_scanner              # phpMyAdmin scanner
use web/wmap                     # Web mapping
use web/apache_users             # Apache user enumeration
use web/cloudflare_resolver      # Cloudflare IP resolver

NETWORK MODULES#

use network/arp_dos              # ARP denial of service
use network/mitmf                # Man-in-the-middle framework
use network/mitm                 # MITM attack
use network/mlitm                # Multi-layer MITM
use network/sniffer              # Network sniffer

EXPLOIT MODULES#

use exploit/autopwn              # Auto exploitation
use exploit/browser_autopwn      # Browser auto-pwn

WIFI MODULES#

use wifi/wifi_jammer             # WiFi jamming
use wifi/wifi_dos                # WiFi denial of service
use wifi/wifi_honeypot           # Rogue access point

BLUETOOTH MODULES#

use bluetooth/bluetooth_pod      # Bluetooth ping of death

MODULE USAGE WORKFLOW#

# 1. Select module
use web/dir_scanner

# 2. View options
show options

# 3. Set required options
set TARGET http://target.com
set WORDLIST /usr/share/wordlists/dirb/common.txt

# 4. Run the module
run

# 5. Review results
# 6. Return to menu
back

EXAMPLES#

# Directory brute force:
use web/dir_scanner
set TARGET http://target.com
set WORDLIST /usr/share/wordlists/dirb/common.txt
run

# ARP DoS attack:
use network/arp_dos
set INTERFACE eth0
set TARGET 192.168.1.100
run

# Cloudflare resolver:
use web/cloudflare_resolver
set TARGET example.com
run

# phpMyAdmin scanner:
use web/pma_scanner
set TARGET http://target.com
run

NOTES#

- Python-based framework
- Metasploit-like console interface
- Combines web and network attack tools
- Modular architecture
- Some modules require root privileges
- Network modules can disrupt services
- Use in controlled environments only
- Not as comprehensive as Metasploit
- Good for quick web/network testing
- Only for authorized security testing