O'Reilly logo

Penetration Testing Bootcamp by Jason Beltrame

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Using Skipfish for web application recon

Skipfish is an extremely fast web application reconnaissance tool. It is all written in C, so it's extremely fast and highly optimized. Because of this, it can perform many tests against hosts to generate impressive reports.

In my lab, I scanned my target host, and it took about 7 hours or so. But the information that came from the report was impressive. Make sure you take into account the time frame. Hardware also plays a key role in this. I was running my scan from a Raspberry Pi. For my test, I ran the following command via the CLI:

root@pi-kali:~# skipfish -o 202 http://192.168.33.31/dvwa

The number of requests per second that are being done will dictate how long the test will take. If that number ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required