Information Gathering Report
Title: Network Information Gathering Tools Report
Teams in Competition: Gamma Vs Delta
Prepared by:Mahnoor
Submitted To: ITSOLERA Cybersecurity Team Leads
Submitted By: Team Theta
1
Date: June 30, 2024
Table of Contents
1. Introduction
2. Purpose of the Report
3. Scope
4. Methodology
5. Network Scanner Tool - WhatWeb
Description
Language and Platform
Installation and Setup
Features and Capabilities
Use Cases
6. Network Analysis
Data Collection
Analysis Process
Findings
7. Strengths and Weaknesses
8. Conclusion
2
Whats Web Tool
● Introduction
The purpose of this report is to provide a comprehensive analysis of WhatsWeb, a
network analysis tool used for gathering network information. This report will evaluate
the effectiveness of WhatsWeb in identifying network details such as the number of
servers, DHCP status, running services, and other relevant network information.
● . Purpose of the Report
The purpose of this report is to provide a comprehensive analysis of various
cybersecurity tools used for network analysis and to evaluate their effectiveness in
gathering network information.
● Scope
This report focuses on WhatsWeb, a popular tool on GitHub, used for network
discovery and analysis. The tool's capabilities and limitations will be assessed
based on its performance on a test network.
● Methodology
WhatsWeb was selected based on its popularity and functionality. The tool was
installed and configured on a test network. Data was collected and analyzed to
assess the capabilities and limitations of WhatsWeb.
● People Search Tool - WhatsWeb
● Description
WhatsWeb is an open-source tool for network analysis and reconnaissance. It provides a
web-based interface for scanning and gathering network information.
● Language and Platform
Language: Python
Platform: Cross-platform (Windows, Linux, Mac OS)
3
● Installation and Setup
WhatsWeb can be installed using pip, the Python package manager.
● Install WhatsWeb
sudo apt install whatweb
● Features and Capabilities
● Key Features
1. Network discovery
2. Port scanning
3. Service detection
4. OS detection
5. Web application scanning
● Parameters and Options
1. --target (Specify the target IP or range)
2. --ports (Specify the ports to scan)
3. --os-detection (Enable OS detection)
4. --web-app-scan (Enable web application scanning)
● Use Cases
1. Network reconnaissance
2. Identifying open ports and services
3. Detecting operating systems and versions
4. Web application security testing
● Network Analysis
● Data Collection
WhatsWeb was used to scan a test network with the following command:
● Analysis Process
4
The collected data was analyzed to determine the number of active servers, the status of
DHCP, and the running services.
● Findings
● Strengths and Weaknesses
● Strengths
1. Easy to use web-based interface
2. Comprehensive network scanning capabilities
3. Support for web application scanning
● Weaknesses
1. Dependent on Python and its dependencies
2. May require additional setup for web application scanning
3. Limited customization options compared to other tools
● Conclusion
WhatsWeb is a powerful tool for network analysis and reconnaissance. Its web-based
interface makes it easy to use, and its comprehensive scanning capabilities provide
valuable insights into network details. However, it may require additional setup for web
application scanning, and its customization options are limited compared to other tools.