WEBSPLOIT
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
WebSploit is an open-source project for remote scanning and analysis of network and web application vulnerabilities. It provides a Metasploit-like console interface for various attack modules.
LAUNCHING#
websploit # Launch interactive console
BASIC COMMANDS#
help # Show available commands show modules # List all modules use <module> # Load a module show options # Show module options set <option> <value> # Set option value run # Execute module back # Return to main menu exit # Exit websploit update # Update framework
WEB MODULES#
use web/dir_scanner # Directory brute force use web/pma_scanner # phpMyAdmin scanner use web/wmap # Web mapping use web/apache_users # Apache user enumeration use web/cloudflare_resolver # Cloudflare IP resolver
NETWORK MODULES#
use network/arp_dos # ARP denial of service use network/mitmf # Man-in-the-middle framework use network/mitm # MITM attack use network/mlitm # Multi-layer MITM use network/sniffer # Network sniffer
EXPLOIT MODULES#
use exploit/autopwn # Auto exploitation use exploit/browser_autopwn # Browser auto-pwn
WIFI MODULES#
use wifi/wifi_jammer # WiFi jamming use wifi/wifi_dos # WiFi denial of service use wifi/wifi_honeypot # Rogue access point
BLUETOOTH MODULES#
use bluetooth/bluetooth_pod # Bluetooth ping of death
MODULE USAGE WORKFLOW#
# 1. Select module use web/dir_scanner # 2. View options show options # 3. Set required options set TARGET http://target.com set WORDLIST /usr/share/wordlists/dirb/common.txt # 4. Run the module run # 5. Review results # 6. Return to menu back
EXAMPLES#
# Directory brute force: use web/dir_scanner set TARGET http://target.com set WORDLIST /usr/share/wordlists/dirb/common.txt run # ARP DoS attack: use network/arp_dos set INTERFACE eth0 set TARGET 192.168.1.100 run # Cloudflare resolver: use web/cloudflare_resolver set TARGET example.com run # phpMyAdmin scanner: use web/pma_scanner set TARGET http://target.com run
NOTES#
- Python-based framework - Metasploit-like console interface - Combines web and network attack tools - Modular architecture - Some modules require root privileges - Network modules can disrupt services - Use in controlled environments only - Not as comprehensive as Metasploit - Good for quick web/network testing - Only for authorized security testing