QWep-Scan is a versatile and powerful web security scanning tool designed to identify common vulnerabilities in websites and web applications. It offers a range of features that help security professionals, penetration testers, and developers identify weaknesses and potential security risks in their web assets.
- Port Scanning: Scans a wide range of ports to identify open and vulnerable ports.
- HTTP Security Tests: Tests for common HTTP vulnerabilities such as SQL Injection, XSS, CSRF, RFI, and SSRF.
- Exploit Open Ports: Simulates attacks on open ports, including HTTP attacks.
- Cookie Security Check: Checks for secure cookies with the HttpOnly and Secure flags.
- Vulnerability Reports: Generates detailed reports summarizing the findings and suggesting potential fixes.
- User-Friendly Interface: The tool includes a command-line interface with a menu for easy navigation.
- SQL Injection
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Remote File Inclusion (RFI)
- Server-Side Request Forgery (SSRF)
- Directory Listing
- Cookie Security (HttpOnly and Secure flags)
- Python 3.x
requestslibrary (for HTTP requests)tqdmlibrary (for progress bars)socketlibrary (for port scanning)
- Clone the repository:
git clone https://github.com/yourusername/QWep-Scan.git - Install the necessary dependencies:
pip install -r requirements.txt - Run the tool:
python qw_scan.py - Choose options from the interactive menu to start scanning and testing for vulnerabilities.
Feel free to fork the repository, create pull requests, or report issues. Contributions are always welcome!
This project is licensed under the MIT License - see the LICENSE file for details.
This tool is intended for ethical use and security testing with the permission of the website or system owner. Unauthorized use may be illegal.
Feel free to explore, contribute, and improve the tool. Happy scanning!