1TWA(1)                           User Commands                          TWA(1)
2
3
4

NAME

6       twa - tiny web auditor with strong opinions
7
8

SYNOPSIS

10       twa [-wvcsdV] DOMAIN
11
12

DESCRIPTION

14       twa  takes  a  DOMAIN  hosting  a website and performs a short security
15       audit.  It can be used to detect HTTP(S) issues, missing security head‐
16       ers, information-leaking headers, and other potential security hazards.
17
18       twa  takes  only  one  DOMAIN  at a time. If you need to audit multiple
19       sites, run the program again.
20
21

OPTIONS

23       -v     Verbose mode.
24
25       -w     Perform the audit on the main DOMAIN and the www.  subdomain.
26
27       -c     Emit output in CSV.
28
29       -s     Run testssl-based checks (skipped by default)
30
31       -d     Disable scanning common development ports
32
33       -V     Print the version and exit.
34
35       -h     Print a help message and exit.
36
37

ENVIRONMENT

39       NO_COLOR
40              Don't colorize output, even when on a TTY.
41
42       TWA_TIMEOUT
43              The maximum length, in seconds, for internal curl calls.
44
45       TWA_USER_AGENT
46              The User-Agent to use for all curl calls.
47
48       TWA_CURLOPTS
49              Any additional options to pass to curl calls.
50
51

TEST RESULTS

53       Each line of output describes the result of a single test, and  follows
54       the  "RESULT(DOMAIN):  explanation"  format, where RESULT is one of the
55       following:
56
57       PASS   The test passed with flying colors.
58
59       MEH    The test passed, but with one  or  more  things  that  could  be
60              improved.
61
62       FAIL   The test failed, and should be fixed.
63
64       UNK    The server gave us something we didn't understand.
65
66       SKIP   The  server  gave  us something we understood, but that we don't
67              handle yet.
68
69       FATAL  A really important test failed, and should be fixed immediately.
70
71

BUGS

73       None known. File issues at: https://github.com/trailofbits/twa
74
75

AUTHOR

77       twa is maintained by William Woodruff (<william @ trailofbits.com>).
78
79
80
811.10.0                            2019-02-17                            TWA(1)
Impressum