Releases: c0dejump/wcDetect
Releases · c0dejump/wcDetect
Release list
v1.7
- 1.7
- New -r/--request option: load a raw HTTP request from a file
(Burp "Copy to file" style). Extracts the URL (Host + path),
method, headers, cookies, User-Agent and body automatically.
Scheme defaults to https; use --http to force http.
- 1.6
New payload families (modules/wcd.py):
- normalization_confusion: cache-vs-origin URL normalization discrepancy
(delimiter pivot %23/%3b/%3f + dot-segment, both directions) — maps a
personalized path under a static directory cache key.
- exact_file_rule: map the sensitive path to named cache rules
(robots.txt, favicon.ico, sitemap.xml, ...) via delimiter/traversal.
- selector_confusion: alternate representations that return the same session
data in a static-looking format (.json/.xml/.ics/.vcf, AEM .infinity.json/
.model.json, Remix ?_data=routes/<page> ).
Tech-specific known endpoints (modules/frameworks.py):
- Remix (?_data= loaders) and Gatsby (page-data.json) path injection.
- CMS detection + known cacheable/personal endpoints: WordPress, Drupal,
Magento/Adobe Commerce, Shopify, AEM.
- Generic REST "me" endpoints added to the default wordlist.
- 1.5
New:
- Concurrent scanning with -t/--threads (default 10) — major speed boost.
Automatically falls back to 1 worker when -hu/--human delay is active.
Updated:
- Reuse a persistent verify session (HTTP keep-alive) instead of a fresh
connection per verify request.
- Thread-safe request handling (per-request User-Agent, no shared-session mutation).
- Code cleanup: deduplicated the KNOWN_PATHS/DEFAULT_PATHS branches and the
payload-generator loops, removed dead code and duplicate imports.