whack.sh: The Multi-Egress URL Scanner by Tuxxin
Software & Apps

whack.sh: The Multi-Egress URL Scanner by Tuxxin

Tuxxin · · 3 min read
Share: Twitter Facebook LinkedIn

Introducing whack.sh: The URL Scanner That Sees Everything

Hey there, security enthusiasts and tech-savvy pros! We've got some seriously exciting news to drop today. Here at Tuxxin, we're always looking for ways to make the internet a safer, more transparent place, and we're thrilled to announce the public launch of something we've been working hard on: whack.sh.

Think of it as your new best friend in the fight against sneaky online threats. whack.sh is the first multi-egress URL threat scanner, designed to expose the hidden dangers that traditional scanners completely miss. We're talking about malware, phishing, and targeted attacks that only show themselves to specific users.

The Problem with "Standard" Scanners

You see, most URL scanners out there? They're running from datacenter IPs – think AWS, Google Cloud, Azure. And here's the kicker: the bad guys know this. They've figured out which IP ranges belong to these scanners. So, what happens when a scanner comes knocking? The cloakers, those clever pieces of code designed to hide malicious content, serve up a perfectly clean decoy page. Maybe it's a parked domain, a harmless redirect, or a login form that goes nowhere. Your scanner happily reports 'all clear,' and the real threat stays hidden, waiting for a real user.

It's like a bouncer at a club letting a detective in through the back door while the real party (and all the shady stuff) is happening out front with the regular crowd. This isn't just theoretical; it's how sophisticated attacks operate:

  • Malicious payloads are usually reserved for real residential and mobile IPs – the exact kind of traffic a datacenter scanner can't simulate.
  • Some bad actors fingerprint your organization's ASN (that's your Autonomous System Number, basically your network's ID) and serve up a *highly* targeted payload. Imagine a request from a bank's corporate network getting a pixel-perfect fake employee re-validation screen, designed to steal credentials. Nasty stuff.
  • A single URL can be a chameleon: a clean page for a scanner, generic malware for a home user, something entirely different for a mobile user, and a targeted corporate login lure for an employee at a specific company.

Standard scanners are totally blind to this multi-faceted deception.

How whack.sh Changes the Game

This is where whack.sh steps in and whacks those threats right out of the shadows. We close this massive gap by looking at a given URL from *every* angle, all at once. We load the URL through datacenter, residential, and mobile egress points simultaneously. Then, we don't just give you one result; we 'diff' the captures. That's right, we compare what each egress point saw.

If there's a difference – if the datacenter saw a clean page but a residential IP saw a malware download – that's the cloak slipping. We score this divergence from 0-100, giving you a clear indicator of how much the site is trying to hide. But we go even further. whack.sh logs exactly which payload deploys to which ASN. This isn't just about 'is this URL bad?' anymore; it's about 'who is this campaign targeting, and what credentials is it after?' You'll be able to spot the organizations in the blast radius *before* those VPN logins start leaking.

We've seen these cloaking techniques firsthand, and trust us, they're getting smarter. whack.sh is built from the ground up to outsmart them, giving you a comprehensive view of the real threats.

Get Started for Free!

Ready to give it a spin? You can start using whack.sh today! We offer free scanning from datacenter egress for the first 5 MB per scan – perfect for getting a feel for how it works. And for those who want to integrate this powerful scanning into their own tools or workflows, our robust curl API drives every tier, whether you're on the free plan or one of our paid options.

Stop letting threats hide in plain sight. Head over to https://whack.sh and start seeing the internet as the bad guys see it. Your security posture will thank you.

Share: 𝕏 Twitter Facebook LinkedIn