WhatWeb: Web Technology Identifier
WhatWeb is a next-generation web scanner that identifies websites and recognizes a vast array of web technologies. It uses over 1700 plugins, each designed to detect specific components, including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, embedded devices, and much more. This makes it an invaluable tool for reconnaissance in web application security assessments.
Key Features
- Extensive Plugin Database: Over 1700 plugins for identifying diverse technologies.
- Flexible Output: Supports various output formats, including JSON.
- Aggressiveness Levels: Allows users to control the invasiveness of scans.
- Customization: Supports custom headers and other request modifications.
Installation
WhatWeb can be installed using RubyGems, or by cloning its Git repository.
Using RubyGems
This is the simplest way to install WhatWeb if you have Ruby installed.
gem install whatwebFrom Git Repository
For the latest development version or if you prefer a source installation:
git clone https://github.com/urbanadventurer/WhatWeb.git
cd WhatWeb
bundle installCommon Commands and Options
Scan a Single Target
whatweb <target_url_or_domain>
# Example:
whatweb example.comScan Multiple Targets
whatweb <target1_url> <target2_url>
# Example:
whatweb example.com example.orgScan from a File
Provide a file containing a list of target URLs, one per line.
whatweb -i target_list.txtAggressiveness Levels (-a)
WhatWeb offers different levels of aggressiveness, controlling how intrusive the checks are.
-a 1: Stealthy (default) - Performs basic, passive checks.-a 3: Aggressive - Includes more intrusive checks, potentially revealing more information but also increasing the chance of detection.-a 4: Full - Attempts all plugins and checks, maximizing information gathering.
Verbose Output (-v)
Increases the verbosity of the output, showing more details about the scanning process.
whatweb -v example.comOutput to JSON (--log-json)
Exports the scan results into a JSON file, which is useful for programmatic processing or integration with other tools.
whatweb --log-json output.json example.comAdvanced Example Usage
Here’s a comprehensive example demonstrating various WhatWeb options for an aggressive scan, suppressing errors, disabling colored output, logging to JSON, and including a custom HTTP header:
whatweb -a 4 -q --no-errors --colour=never --log-json=/dev/stdout --header "X-Bug-Bounty: portal-username=l0l4da" https://<target_url>-a 4: Sets the aggressiveness level to 4 (Full scan).-q: Suppresses verbose output (quiet mode).--no-errors: Hides error messages in the console.--colour=never: Disables colored output, useful for scripting or logging.--log-json=/dev/stdout: Outputs results in JSON format directly to standard output.--header "X-Bug-Bounty: portal-username=l0l4da": Adds a customX-Bug-Bountyheader to all requests.https://<target_url>: The URL of the target web application.
Testing WhatWeb Requests with mendhak/http-https-echo
To verify that WhatWeb is sending requests with specific headers or in a particular way, you can direct it to an HTTP echo server. The mendhak/http-https-echo Docker container is excellent for this purpose, as it reflects back all the request information it receives.
-
Run the
http-https-echocontainer: Start the echo server, mapping a host port to its internal port.docker run -it --rm -p 443:8443 mendhak/http-https-echoThis command maps port 443 on your host to port 8443 (HTTPS) on the container. The
--rmflag ensures the container is removed when you stop it. -
Point WhatWeb to your local echo server: Now, execute your
WhatWebcommand, targetinglocalhost(or the IP of your Docker host) on the mapped port.whatweb -a 1 -q --no-errors --colour=never --log-json=/dev/stdout --header "X-Custom-Header: test-value" https://localhostNote: When testing HTTPS locally with
http-https-echo, you might need to usecurl -k(or equivalent) for the client sending requests tolocalhostto ignore self-signed certificate warnings. IfWhatWebhas issues with self-signed certs, try usinghttp://localhostif the echo server is configured for HTTP on that port.The console output of your
docker runcommand will display the exact requestWhatWebsent, including all headers, paths, and methods. This helps confirm that yourWhatWebcommand is constructed correctly.
Disclaimer: WhatWeb is a reconnaissance tool. Its use should be restricted to legal and ethical purposes, such as authorized penetration testing, bug bounty hunting on explicitly allowed scopes, or security research on systems you own or have explicit permission to test. Unauthorized scanning of web applications is illegal and unethical.