EyeWitness – A Rapid Web Application Triage Tool

We, at ehacking
used to share
tools that can make the penetration testing process easy
and effective. You might have seen EH Tools shared before and you will witness
the tools that we will share later, but today I have an interesting tool to
discuss; it’s called EyeWitness. Chris Truncer is the man behind this tool; it
has been designed to run on Kali Linux.








EyeWitness is
designed to take screenshots of websites, provide some server header info, and
identify default credentials if possible.

 EyeWitness is designed to take a file, parse
out the URLs, take a screenshot of the web pages, and generate a report of the
screenshot along with some server header information.  EyeWitness is able
to parse three different types of files, a general text file with each url on a
new line, the xml output from a NMap scan, or a .nessus file.  Jason Hill (
@jasonhillva)
worked on creating the XML parsing code for EyeWitness, and provided a lot of
feedback throughout writing it. 

In addition to
providing the file name, you can also optionally provide a maximum timeout
value.  The timeout value is the maximum amount of time EyeWitness waits
for a web page to render, before moving on to the next URL in the list.

Image Credit

Supported Linux Distros:
Debian
7+ (at least stable, looking into testing) (Thanks to @themightyshiv)
CentOS
6.5+ (Thanks to @themightyshiv)
Setup:
1.   
Navigate into the setup
directory
2.   
Run the setup.sh script
Usage:
./EyeWitness.py
-f filename -t optionaltimeout –open (Optional)
Examples:
./EyeWitness
-f urls.txt
./EyeWitness
-f urls.xml -t 8 –open

Ehacking Staff
With more than 50 global partners, we are proud to count the world’s leading cybersecurity training provider. EH Academy is the brainchild of Ehacking, which has been involved in the field of training since the past Five years and continues to help in creating professional IT experts.

Most Popular

Top 5 Techniques Hackers Use to hack Social Media Accounts

These days, Social Media have become a significant need in our everyday life. It encourages us to associate and connect with anyone over the...

5 Top Programming Languages for Hacking

We live in the 21st century, which is very fast-changing. This is a century of competition for information and computing resources. Every year the...

OSINT Tutorial to Track An Aircraft And Flight Information In Real-Time

No doubt Internet is said to be the world's largest repository of data and information. It contains an enormous amount of data related to...

Preventing SQL Injection in PHP Applications

SQL injection is one of the most common cybersecurity threats and as the name suggests, it is a form of injection attack. Injection attacks, on...