wapiti - Web application vulnerability scanner

Wapiti allows you to audit the security of your web applications.
It performs "black-box" scans, i.e. it does not study the source code of the
application but will scans the web pages of the deployed web applications,
looking for scripts and forms where it can inject data.
Once it gets this list, Wapiti acts like a fuzzer, injecting payloads to see
if a script is vulnerable.
Wapiti can detect the following vulnerabilities:
- File Handling Errors (Local and remote include/require, fopen, ...)
- Database Injection (PHP/JSP/ASP SQL Injections and XPath Injections)
- XSS (Cross Site Scripting) Injection
- LDAP Injection
- Command Execution detection (eval(), system(), passtru()...)
- CRLF Injection (HTTP Response Splitting, session fixation...)


Install Howto

  1. Update the package index:
    # sudo apt-get update
  2. Install wapiti deb package:
    # sudo apt-get install wapiti




2012-04-06 - Arthur de Jong <adejong@debian.org>
wapiti (1.1.6-4) unstable; urgency=low
* Team upload.
[ Jakub Wilk ]
* Remove unused Provides field from debian/control.
[ Jari Aalto ]
* Remove deprecated dpatch and upgrade to packaging format "3.0 quilt"
(Closes: #664377).
* Update to Standards-Version to 3.9.3 and debhelper to 9.
[ Arthur de Jong ]
* Switch to dh_python2 (Closes: #617144).
* Switch to dh command sequencer and install file with dh_install instead
of a custom setup.py.
* Update Vcs-Browser field.
* Fix spelling error and small wording change in manual page (thanks
* Switch to machine-readable debian/copyright format.
2008-04-26 - Thomas Bläsing <thomasbl@pool.math.tu-berlin.de>
wapiti (1.1.6-3) unstable; urgency=low
* Closes: #477034
-> restructured debian/rules
* changing some rules in debian/rules
* watch-file added
* patches now handled by dpatch
* new Uploader: Python Applications Packaging Team
2007-07-30 - Thomas Bläsing <thomasbl@pool.math.tu-berlin.de>
wapiti (1.1.6-2) unstable; urgency=low
* changed description ( Closes: #434804 )
* modified man-page.
* debianized warning output, if python-utidylib and python-ctypes are not installed.
2007-06-28 - Thomas Bläsing <thomasbl@pool.math.tu-berlin.de>
wapiti (1.1.6-1) unstable; urgency=low
* Initial release (Closes: #381418)

