External reconnaissance
In this section, we'll cover a number of tools for external reconnaissance. Let's begin by looking at the server scanning tool, Webshag.
Webshag
This is a server scanning tool that can evade detection by intrusion detection systems (IDS). Many IDS tools work by blocking suspicious traffic from specific IP addresses. Webshag can send random requests to a server through proxies, thereby evading the IP address blocking mechanism of an IDS.
Therefore, the IDS will hardly be able to protect the target from being probed. Webshag can find the open ports on a server and the services running on them. It has a more aggressive mode called Spider, which can list all the directories in the server to allow a hacker to dig deeper and find any loosely kept sensitive files or backups. It can also find emails and external links posted on the site. The main advantage of Webshag is that it can scan both HTTP and HTTPS protocols.
Webshag can be used in GUI...