Nmap Web Discovery
# common web ports
nmap -p 80,443,8000,8080,8180,8888,10000 --open -oA web_discovery -iL scope_listEyeWitness
EyeWitness is superseded by the actively maintained
gowitness— prefer it for new work.
Can take an XML output from Nmap or Nessus and create a report with screenshots of each web application present on the various ports using Selenium. Will also try categorizing the applications, fingerprint them and suggest default credentials.
# take screenshots using nmap xml output
eyewitness --web -x web_discovery.xml -d inlanefreight_eyewitnessgowitness
Maintained successor to EyeWitness/Nessus-style screenshotting. Uses headless Chrome, so it respects /etc/hosts entries — useful for screenshotting vhosts that all resolve to one IP. Input files expect one URL per line; include the scheme to be explicit.
# save discovered vhosts to a file, one URL per line
cat > vhosts.txt << 'EOF'
http://inlanefreight.local
http://blog.inlanefreight.local
http://careers.inlanefreight.local
http://dev.inlanefreight.local
http://gitlab.inlanefreight.local
http://support.inlanefreight.local
http://tracking.inlanefreight.local
EOF
# screenshot each vhost, full page (-F), and write results to the local db for the report server
gowitness scan file -f vhosts.txt --screenshot-fullpage --write-db
# browse results in the gallery at http://localhost:7171
gowitness report serverOn gowitness v2 the syntax is
gowitness file -f vhosts.txt. Duplicate lines withhttps://for hosts serving TLS.
Aquatone
Similar to EyeWitness.
cat web_discovery.xml | ./aquatone -nmap