WHATWEB
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
WhatWeb identifies websites and recognizes web technologies including CMS, blogging platforms, JS libraries, web servers, embedded devices, version numbers, email addresses, and more. It has over 1800 plugins.
BASIC USAGE#
whatweb <url> # Basic fingerprint whatweb -v <url> # Verbose output whatweb -a 3 <url> # Aggressive scan
AGGRESSION LEVELS (-a)#
whatweb -a 1 <url> # Stealthy (1 HTTP request) whatweb -a 2 <url> # Unused (reserved) whatweb -a 3 <url> # Aggressive (additional requests) whatweb -a 4 <url> # Heavy (many requests, brute force)
TARGET OPTIONS#
whatweb <url> # Single URL whatweb <url1> <url2> <url3> # Multiple URLs whatweb -i urls.txt # URLs from file whatweb --input-file=urls.txt # URLs from file (alt) whatweb 192.168.1.0/24 # Scan IP range whatweb 192.168.1.1-192.168.1.50 # Scan IP range
OUTPUT OPTIONS#
whatweb --log-brief=out.txt <url> # Brief text output whatweb --log-verbose=out.txt <url> # Verbose text output whatweb --log-json=out.json <url> # JSON output whatweb --log-xml=out.xml <url> # XML output whatweb --log-csv=out.csv <url> # CSV output whatweb --log-magictree=out.xml <url> # MagicTree XML whatweb --log-sql=out.sql <url> # SQL insert statements whatweb --log-sql-create <url> # SQL CREATE + INSERT whatweb --log-errors=errors.txt <url> # Error log
AUTHENTICATION & PROXY#
whatweb --user=<user> --password=<pass> <url>
# HTTP Basic Auth
whatweb --proxy=<host:port> <url>
# HTTP proxy
whatweb --proxy-user=<u:p> <url> # Proxy authentication
whatweb -U <user-agent> <url> # Custom User-Agent
whatweb --cookie=<cookie> <url> # Set cookies
whatweb --header="X-Custom: val" <url>
# Custom header
PERFORMANCE#
whatweb --max-threads=10 <url> # Set max threads (default: 25) whatweb --open-timeout=10 <url> # Connection timeout (seconds) whatweb --read-timeout=20 <url> # Read timeout (seconds) whatweb --wait=<seconds> <url> # Wait between connections whatweb --max-redirects=5 <url> # Max HTTP redirects to follow
PLUGIN OPTIONS#
whatweb -l # List all plugins
whatweb --info-plugins=<name> # Plugin details
whatweb -p <plugin1,plugin2> <url>
# Use specific plugins only
whatweb --grep=<regex> <url> # Custom grep plugin
whatweb --custom-plugin="..." <url>
# Inline custom plugin
EXAMPLES#
# Quick website fingerprint whatweb example.com # Verbose scan with JSON output whatweb -v --log-json=results.json example.com # Aggressive scan with all details whatweb -a 3 -v example.com # Scan subnet for web servers whatweb 192.168.1.0/24 # Scan with authentication whatweb --user=admin --password=secret http://192.168.1.1/admin # Scan through proxy whatweb --proxy=127.0.0.1:8080 https://example.com # Multiple targets from file whatweb -i targets.txt --log-json=results.json # Search for specific technology whatweb -p WordPress example.com
DETECTED TECHNOLOGIES#
# Web Servers: Apache, Nginx, IIS, LiteSpeed # CMS: WordPress, Drupal, Joomla, Magento # Frameworks: Ruby on Rails, Django, Laravel, ASP.NET # JS Libraries: jQuery, React, Angular, Vue.js # Analytics: Google Analytics, Matomo, Hotjar # Security: WAF indicators, security headers # Server Info: PHP version, OS hints, headers # And 1800+ more plugins...
NOTES#
- Ruby-based tool - 1800+ recognition plugins - Aggression level 1 is stealthy (single request) - Level 3+ sends additional requests per technology - Great for initial web application reconnaissance - Can scan IP ranges and CIDR networks - JSON output useful for automation and reporting - Actively maintained