Example Usage
# Audit a site. $ twa google.com > FAIL(google.com): TWA-0102: HTTP redirects to HTTP (not secure) > FAIL(google.com): TWA-0205: Strict-Transport-Security missing > MEH(google.com): TWA-0206: X-Frame-Options is 'sameorigin', consider 'deny' > FAIL(google.com): TWA-0209: X-Content-Type-Options missing > PASS(google.com): X-XSS-Protection specifies mode=block > FAIL(google.com): TWA-0214: Referrer-Policy missing > FAIL(google.com): TWA-0219: Content-Security-Policy missing > FAIL(google.com): TWA-0220: Feature-Policy missing > PASS(google.com): Site sends 'Server', but probably only a vendor ID: gws > PASS(google.com): Site doesn't send 'X-Powered-By' > PASS(google.com): Site doesn't send 'Via' > PASS(google.com): Site doesn't send 'X-AspNet-Version' > PASS(google.com): Site doesn't send 'X-AspNetMvc-Version' > PASS(google.com): No SCM repository at: http://google.com/.git/HEAD > PASS(google.com): No SCM repository at: http://google.com/.hg/store/00manifest.i > PASS(google.com): No SCM repository at: http://google.com/.svn/entries > PASS(google.com): No environment file at: http://google.com/.env > PASS(google.com): No environment file at: http://google.com/.dockerenv # Audit a site
See also
BeEF
Open Source
Kali
Browser Exploitation Framework. Hooks web browsers via JavaScript and provides extensive command mod…
Aquatone
Open Source
Tool for visual inspection of websites across large numbers of hosts. Takes screenshots of web pages…
NoSQLMap
Open Source
Automated NoSQL injection and database exploitation tool. Targets MongoDB, CouchDB, Redis, and Cassa…
OWASP ZAP
Open Source
Kali
OWASP's Zed Attack Proxy — one of the world's most popular free web application security scanners. F…
Evilginx2
Open Source
Standalone man-in-the-middle attack framework that bypasses 2FA by proxying authentication sessions …
Penetration_Testing_POC
Open Source
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-ge…