
A virtual host scanner with the ability to detect catch-all scenarios, aliases, and dynamic default pages, presented at SecTalks BNE in September 2017.

A virtual host scanner with the ability to detect catch-all scenarios, aliases, and dynamic default pages, presented at SecTalks BNE in September 2017.
VHostScan is a Penetration Testing product. Pricing is free.
A virtual host scanner that can be used with pivot tools, detect catch-all scenarios, aliases, and dynamic default pages. First presented at SecTalks BNE in September 2017 (slidedeck). Key Benefits: - Quickly highlight unique content in catch-all scenarios - Locate the outliers in catch-all scenarios where results have dynamic content on the page (such as the time) - Identify aliases by tweaking the unique depth of matches - Wordlist supports standard words and a variable to input a base hostname (for e.g. dev.%s from the wordlist would be run as dev.BASE_HOST) - Works over HTTP and HTTPS - Ability to set the real port of the webserver to use in headers when pivoting through ssh/nc - Add simple response headers to bypass some WAF products - Identify new targets by using reverse lookups and append to wordlist Product Comparisons: - Install on docker (recommended) - git clone https://github.com/codingo/VHostScan.git - cd VHostScan - docker build -t vhostscan . - Then run application `docker run --rm -it vhostscan -t` - Install Requirements: - Install using: $ python3 setup.py install - Dependencies will then be installed and VHostScan will be added to your path. - If there is an issue regarding running py
Common questions about VHostScan including features, pricing, alternatives, and user reviews.
VHostScan is A virtual host scanner with the ability to detect catch-all scenarios, aliases, and dynamic default pages, presented at SecTalks BNE in September 2017. It is a Offensive Security solution designed to help security teams with Red Team, Open Source.
VHostScan is built for security teams handling Red Team, Open Source. Teams typically adopt VHostScan when they need to offensive security capabilities integrated into their existing stack. Explore similar tools at https://cybersectools.com/alternatives/vhostscan
VHostScan is a free Offensive Security tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://github.com/codingo/VHostScan/ for download and installation instructions.
Popular alternatives to VHostScan include:
Compare all VHostScan alternatives at https://cybersectools.com/alternatives/vhostscan
VHostScan is for security teams and organizations that need Red Team, Open Source. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Offensive Security tools can be found at https://cybersectools.com/categories/offensive-security-testing
Head-to-head feature, pricing, and rating breakdowns.
WeirdAAL is an open-source framework that provides tools and libraries for simulating attacks and testing security vulnerabilities in AWS environments.
An open-source attack surface management platform for identifying and managing vulnerabilities
AI-powered automated pen testing & continuous red teaming platform