A fast Python tool to detect Web Cache Deception vulnerabilities on web apps by appending fake static extensions (like .css, .jpg, etc.) to sensitive endpoints.
- Scans multiple sensitive endpoints
- Appends various payload extensions (
.css,.jpg,;style.css, etc.) - Checks:
- HTTP status codes
- Response size
Cache-Controlheader- Signs of personal info leaks (
name,email,wallet, etc.)
- Multithreaded for fast scanning
- Python 3.x
- Install dependencies:
pip install requests
pip install requests
python wcd_scanner.py https://www.target.com