Web App Scanner

Authorized web application testing from the CLI. Subdomain enumeration (crt.sh / subfinder / DNS brute) with dangling-CNAME subdomain-takeover detection to map the whole estate, per-host passive recon (security headers / cookies / TLS / advanced CORS bypass tests), non-destructive active vulnerability checks (exposed .git/.env, reflected XSS, open redirect, path traversal, header injection, SSTI, SSRF-to-metadata, directory listing) with link crawling, optional nuclei & ffuf, and guarded sqlmap SQL injection testing — one orchestrated whole-system scan into a severity-ranked findings report.

ptn1411 549e1ac 7 files · 71.9 KB Updated

File contents

ptn1411/skill/tree/main/web-app-scanner commit 549e1acbd4

Frequently asked questions

npx skillmds@latest add ptn1411/web-app-scanner