BWASP - BoB Web Application Security Project

5 days ago 5

The BoB Web Application Security Project (BWASP) is an open-source, analysis tool to support for Web Vulnerability Manual Analysis hackers.

The BWASP tool basically provides predicted information through vulnerability analysis without proceeding with an attack.

BWASP supports performing automated analysis and manual analysis.

The BWASP Project supports:

Find Attack vector automatically. (e.g. SQL Injection, Cross-site Scripting) Detect website technology. Log4J vulnerability scan (Partially supports java language) HTTP REST API GuideLine Result Test payload option(attack test)

Getting started

pip3 install -r requirements.txt


BWASP Tool Guide

guide-ko-documentation guide-en-documentation


Add OSINT feature (find subdomains)


Web Infra Environment Analysis: wappalyzer(


[email protected]


Dohun Koo (@dohunny) Sanghyeon Lee (@isanghyeon) Joowon Kim (@arrester) Jongmin Kim (@Universe1122) Joonyoung Jeong (@jeongjy0317) Joomyeong Lee (@PecentZero) PL: Jiheon Choi (@jiheon-dev) Mentor: Gangseok Lee (@codeengn), Sehan Park (@combab0)


This work was supported by Korea Information Technology Research Institute (KITRI) Best of the Best (BoB) Program 10th vulnerability analysis track.

[Project Name: BoB Web Application Security Project]

BWASP - BoB Web Application Security Project BWASP - BoB Web Application Security Project Reviewed by Zion3R on 8:30 AM Rating: 5

Read Entire Article