{"repo":"Hackmanit/Web-Cache-Vulnerability-Scanner","free":true,"listed":false,"github":"https://github.com/Hackmanit/Web-Cache-Vulnerability-Scanner","clone":"git clone https://github.com/Hackmanit/Web-Cache-Vulnerability-Scanner.git","description":"Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).","language":"Go","stars":1196,"topics":["vulnerability-scanners","web-cache","security-tools","security-scanner","security","security-audit","pentesting","penetration-testing-tools","penetration-testing","bugbounty"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Web Cache Vulnerability Scanner (WCVS) is a fast and versatile CLI scanner for web cache poisoning and web cache deception developed by Hackmanit and Maximilian Hildebrand. The scanner supports many different web cache poisoning and web cache deception techniques, includes a crawler to identify further URLs to test, and can adapt to a specific web cache for more efficient testing. It is highly customizable and can be easily integrated into existing CI/CD pipelines. - Features - Installation - Option 1: Pre-built Binary - Option 2: Kali Linux / BlackArch Repository - Option 3: Install Using Go - Option 4: Docker - Usage - Specify Headers, Parameters, Cookies, and More - Generate a JSON Report - Crawl for URLs - Use a Proxy - Throttle or Accelerate - Further Flags - Background Information - License Features - Support for 10 web cache poisoning techniques: 1. Unkeyed header poisoning 2. Unkeyed parameter poisoning 3. Parameter cloaking 4. Fat GET 5. HTTP response splitting 6. HTTP request smuggling 7. HTTP header oversize (HHO) 8. HTTP meta character (HMC) 9. HTTP method override (HMO) 10. Parameter pollution - Support for multiple web cache deception techniques: 1. Path Parameter 2. Path Traversal (.css file, /static directory and /robots.txt) 3. Appended special characters (both encoded and not encoded) - Analyzing a web cache before testing and adapting to it for more efficient testing - Generating a report in JSON format - Crawling websites for further URLs to scan - Routing","default_branch":null,"files":null,"tree":[],"storefront":"/r/Hackmanit","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Hackmanit/Web-Cache-Vulnerability-Scanner/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}