Skip to main content

The YAWAST Antecedent Web Application Security Toolkit

Project description

yawast-ng

unit-tests codecov

YAWAST

The YAWAST Antecedent Web Application Security Toolkit - Next Generation

yawast-ng is an application meant to simplify initial analysis and information gathering for penetration testers and security auditors. It performs basic checks in these categories:

  • TLS/SSL - Versions and cipher suites supported; common issues.
  • Information Disclosure - Checks for common information leaks.
  • Presence of Files or Directories - Checks for files or directories that could indicate a security issue.
  • Common Vulnerabilities
  • Missing Security Headers

This is meant to provide a easy way to perform initial analysis and information discovery. It's not a full testing suite, and it certainly isn't Metasploit. The idea is to provide a quick way to perform initial data collection, which can then be used to better target further tests. It is especially useful when used in conjunction with Burp Suite (via the --proxy parameter).

Next Generation

This project is a continuation of YAWAST, as yawast-ng, to continue the project by the original author, years after the original project was ended, taking the project in a new direction.

Documentation

Please see the project website for full documentation.

Usage

The most common usage scenario is as simple as:

yawast-ng scan <url1>

Detailed usage information is available on the project web site.

Contributing

  1. Fork it (https://github.com/Numorian/yawast-ng/fork)
  2. Create your feature branch (git checkout -b my-new-feature origin/develop)
  3. Commit your changes (git commit -am 'Add some feature')
  4. Push to the branch (git push origin my-new-feature)
  5. Create a new Pull Request

Issues that are labeled as good first issue are great starting points for new contributors. These are less complex issues that will help make you familiar with working on yawast-ng.

Contributions, in the form of feature requests and pull requests are both welcome and encouraged. yawast-ng will only evolve if users are willing and able to give back, and work too make yawast-ng better for everyone.

Information on development standards, and guidelines for issues are available in our CONTRIBUTING document.

Special Thanks

  • SecLists - Various lists are based on the resources collected by this project.
  • FuzzDB Project - Various lists are based on the resources collected by this project.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

yawast_ng-0.12.0.tar.gz (8.4 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

yawast_ng-0.12.0-py3-none-any.whl (8.6 MB view details)

Uploaded Python 3

File details

Details for the file yawast_ng-0.12.0.tar.gz.

File metadata

  • Download URL: yawast_ng-0.12.0.tar.gz
  • Upload date:
  • Size: 8.4 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.12.6

File hashes

Hashes for yawast_ng-0.12.0.tar.gz
Algorithm Hash digest
SHA256 1c85b9055a40641fc4b3efe118ccb2bd3ff10cbba1d58bd5007dc39d7b466f8f
MD5 9e4f7da4ec09c6165d13e580d1029460
BLAKE2b-256 feb0cd83ba6cb108bad7769f61c593b56e81d402ae0d873e121b58518c20423c

See more details on using hashes here.

File details

Details for the file yawast_ng-0.12.0-py3-none-any.whl.

File metadata

  • Download URL: yawast_ng-0.12.0-py3-none-any.whl
  • Upload date:
  • Size: 8.6 MB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.12.6

File hashes

Hashes for yawast_ng-0.12.0-py3-none-any.whl
Algorithm Hash digest
SHA256 97fdea1dad80070f836ab1bf3d05b1eb6ff100d4965451f39404e128144c34ff
MD5 ab3a83260f1d09ceed9441420353e650
BLAKE2b-256 6d8c4eb3be3e215674bbc07440cb012ca8e67c70022f441dbb36a9a1d1594bd7

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page