Skipfish is a web application. The way it works is by creating an interactive sitemap for the website being analyzed using dictionary crawls and probes. The resulting map also includes the results of additional security checks it performs. The final report produced by Skipfish can be used as a basis for professional security assessments of web applications.
Its main features are summarized below:
- High speed: written in C language, excellent HTTP, can easily perform 2000 requests per second against targets/machines to be analyzed.
- Ease of use
- Innovative security logic: high quality, few false positives, security check, capable of detecting even the most subtle security issues.
How to install it
Skipfish installation is only supported in Linux. You will find it pre-installed in the well-known distro, Kali Linux.
Ubuntu & Debian
To install Skipfish in an Ubuntu or Debian environment, open a terminal and type the following commands:
| sudo apt-get update -y sudo apt-get install -y skipfish |
CentOS
To install Skipfish in a CentOs , open a terminal and type the following command:
| yum install skipfish |
How to use it
To see the different parameters we can use in this tool we will open a terminal and run the following command:
| skipfish –help |
The result is shown below.
root@kali-elena:~# skipfish --help skipfish web application scanner - version 2.10b Usage: skipfish [ options ... ] -W wordlist -o output_dir start_url [ start_url2 ... ] Authentication and access options: -A user:pass - use specified HTTP authentication credentials -F host=IP - pretend that 'host' resolves to 'IP' -C name=val - append a custom cookie to all requests -H name=val - append a custom HTTP header to all requests -b (i|f|p) - use headers consistent with MSIE / Firefox / iPhone -N - do not accept any new cookies --auth-form url - form authentication URL --auth-user user - form authentication user --auth-pass pass - form authentication password --auth-verify-url - URL for in-session detection Crawl scope options: -d max_depth - maximum crawl tree depth (16) -c max_child - maximum children to index per node (512) -x max_desc - maximum descendants to index per branch (8192) -r r_limit - max total number of requests to send (100000000) -p crawl% - node and link crawl probability (100%) -q hex - repeat probabilistic scan with given seed -I string - only follow URLs matching 'string' -X string - exclude URLs matching 'string' -K string - do not fuzz parameters named 'string' -D domain - crawl cross-site links to another domain -B domain - trust, but do not crawl, another domain -Z - do not descend into 5xx locations -O - do not submit any forms -P - do not parse HTML, etc, to find new links Reporting options: -o dir - write output to specified directory (required) -M - log warnings about mixed content / non-SSL passwords -E - log all HTTP/1.0 / HTTP/1.1 caching intent mismatches -U - log all external URLs and e-mails seen -Q - completely suppress duplicate nodes in reports -u - be quiet, disable realtime progress stats -v - enable runtime logging (to stderr) Dictionary management options: -W wordlist - use a specified read-write wordlist (required) -S wordlist - load a supplemental read-only wordlist -L - do not auto-learn new keywords for the site -Y - do not fuzz extensions in directory brute-force -R age - purge words hit more than 'age' scans ago -T name=val - add new form auto-fill rule -G max_guess - maximum number of keyword guesses to keep (256) -z sigfile - load signatures from this file Performance settings: -g max_conn - max simultaneous TCP connections, global (40) -m host_conn - max simultaneous connections, per target IP (10) -f max_fail - max number of consecutive HTTP errors (100) -t req_tmout - total request response timeout (20 s) -w rw_tmout - individual network I/O timeout (10 s) -i idle_tmout - timeout on idle HTTP connections (10 s) -s s_limit - response size limit (400000 B) -e - do not keep binary responses for reporting Other settings: -l max_req - max requests per second (0.000000) -k duration - stop scanning after the given duration h:m:s --config file - load the specified configuration file Send comments and complaints to<heinenn@google.com> . |
Let's start the scan on the site we have created just for this purpose (IP: 192.168.142.29). To do this and “write” the result to a directory we must use the -o parameter and execute the following command:
| skipfish -o skip https://192.168.142.129 |
While the scan is running, it saves the results in the skip folder and we see something like the one shown below on our screen:

When the scan is complete, we will see something on the screen that looks like the following:

Let's go see the crawl results in the index.html file in the skip folder.

So we see a very nice report that emerged after evaluating the application and shows us all the vulnerabilities that skipfish identified during the scan. We can click on each finding to see more information, such as where exactly it was found.

By selecting “show trace” we will see the evidence related to the specific vulnerability. For the “Shell injection vector” we selected above, the trace related to it is shown below:
=== REQUEST === GET /login.php/`true` HTTP/1.1 Host: 192.168.142.129 Accept-Encoding: gzip Connection: keep-alive User-Agent: Mozilla/5.0 SF/2.10b Range: bytes=0-399999 Referer: https://192.168.142.129/ Cookie: PHPSESSID=94lthp20g1r5iu32anumr9e0o1; security=high === RESPONSE === HTTP/1.1 200 Partial Content Date: Thu, 21 Nov 2019 21:47:19 GMT Server: Apache/2.2.14 (Unix) DAV/2 mod_ssl/2.2.14 OpenSSL/0.9.8l PHP/5.3.1 mod_apreq2-20090110/2.7.1 mod_perl/2.0.4 Perl/v5.10.1 X-Powered-By: PHP/5.3.1 Expires: Tue, 23 Jun 2009 12:00:00 GMT Cache-Control: no-cache, must-revalidate Pragma: no-cache Content-Range: bytes 0-1223/1224 Content-Length: 1224 Keep-Alive: timeout=5, max=95 Connection: Keep-Alive Content-Type: text/html; charset=utf-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "https://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xmlns="https://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /><title> Damn Vulnerable Web App (DVWA) - Login </title><link rel="stylesheet" type="text/css" href="dvwa/css/login.css" /></head><body><div align="center"><br /><p><img src="dvwa/images/login_logo.png" /></p><br /><form action="login.php" method="post"><fieldset> <label for="user">Username</label><input type="text" class="loginInput" size="20" name="username"><br /> <label for="pass">Password</label> <input type="password" class="loginInput" AUTOCOMPLETE="off" size="20" name="password"><br /><p class="submit"><input type="submit" value="Login" name="Login"></p></fieldset></form><br /><br /><br /><br /><br /><br /><br /><br /><br /><!-- <img src="dvwa/images/RandomStorm.png" /> --><p> Damn Vulnerable Web Application (DVWA) is a RandomStorm OpenSource project</p></div><!-- end align div --></body></html> === END OF DATA === |
We look forward to your feedback on Skipfish…

