Skip to content

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

🕷️ SpyWeb - Web Security Analysis Tool

SpyWeb Banner

🔎 Overview

SpyWeb is a lightweight web security analysis tool written in Bash.
It crawls and scans files (local or remote) to detect sensitive information leaks such as:

  • API keys & tokens
  • Cloud provider keys
  • Social media tokens
  • Database credentials
  • JWT tokens
  • Private keys & certificates
  • Emails, passwords, IP addresses, credit cards
  • URLs & endpoints

⚡ Features

  • Crawl and download remote files (.js, .php, .py, .json, .env, etc.)
  • Scan local files directly without needing to download them
  • Detect sensitive data patterns using enhanced regex rules
  • Highlight findings with colored output
  • Summarized security report at the end of the scan
  • Supports both curl and wget for remote files

🛠️ Usage

# Scan a remote URL
./spyweb.sh -u <URL>

# Scan a local file
./spyweb.sh -l <FILE>

Examples

./spyweb.sh -u example.com/js/script.js
./spyweb.sh -u https://example.com/config.php
./spyweb.sh -l /var/www/html/config.php
./spyweb.sh -f http://site.com/app.py  # Backwards compatible

📂 Supported File Types

  • Web Files: .js, .php, .html, .css
  • Data Files: .json, .xml, .yaml, .csv
  • Config Files: .env, .ini, .conf, .cfg, .toml
  • Programming: .py, .java, .ts, .swift, .kt, .dart
  • DevOps & Build: Dockerfiles, CI/CD files, .sh, .ps1, .tf
  • Databases: .sql, .db, .sqlite
  • Security: .pem, .crt, .p12

🚀 Installation

git clone https://github.com/medjahdi/spyweb.git
cd spyweb
chmod +x spyweb.sh

# Test it out!
./spyweb.sh -u https://target.com/file.js
./spyweb.sh -l ./spyweb.sh

⚠️ Disclaimer

This tool is for educational and security research purposes only. Do not use it against systems without explicit authorization. The author is not responsible for any misuse.

👤 Author: @medjahdi

About

A lightning-fast, Bash-based web security analysis tool. SpyWeb crawls and scans remote URLs or local files to detect leaked API keys, cloud tokens, passwords, and sensitive information using highly optimized regex patterns.

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages