Ravindra BagaleCourses & study guides

36. More Essential Kali Tools

36.3 WhatWeb and Wappalyzer: Technology Fingerprinting

Website kontya stack var chalte – Apache ki Nginx, PHP version, WordPress, jQuery – he mahit zala tar known vulnerability (भेद्यता) shodhayla sope. He technology fingerprinting aahe.

WhatWeb (CLI, Kali madhe):

sudo apt install -y whatweb
whatweb http://192.168.56.20
whatweb -a 3 http://192.168.56.20/dvwa/     # aggression level 1-4 (lab only)
whatweb -v http://192.168.56.20             # verbose

Output madhe server header, cookies, CMS hints, framework naav distat.

Wappalyzer idea: browser extension (Chrome/Firefox) – site open kela ki sidebar madhe technologies dakhavto. Manual recon sathi handy; pentest report madhe "stack observed" section lihayla upyogi. Extension install karun lab site bagha – CLI + browser donhi shika.

Defence / harden:

  • Server ani X-Powered-By headers remove kiwa generic theva (Nginx/Apache config).
  • Version numbers public pages/error pages var dakhavu naka.
  • Default banners badla; unnecessary modules band kara.
  • Fingerprinting 100% thambat nahi – pan attacker cha time vadhavto. Lakshat theva.

Ravindra Bagale's Tip

Because WhatWeb shows "PHP 5.x", students go straight to looking for an exploit. A version is a hint, not a confirmation. False positives happen. Always cross-check with another tool (Nmap scripts, manual headers), and exploits only in the lab.

Lab

whatweb -a 3 http://192.168.56.20/dvwa/ chalaa. Server, language ani CMS hints note kara. Mag aaplya Chapter 16 reels app var same – X-Powered-By disla tar Nginx/Apache config madhun remove karun sudo service nginx reload (kiwa apache) ani punha scan – header gela ka te check kara.