w3af-users Mailing List for w3af (Page 3)
Status: Beta
Brought to you by:
andresriancho
You can subscribe to this list here.
2007 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(6) |
Jul
(11) |
Aug
|
Sep
(9) |
Oct
(40) |
Nov
(20) |
Dec
(10) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2008 |
Jan
(77) |
Feb
(36) |
Mar
(54) |
Apr
(142) |
May
(37) |
Jun
(37) |
Jul
(71) |
Aug
(44) |
Sep
(15) |
Oct
(85) |
Nov
(61) |
Dec
(68) |
2009 |
Jan
(44) |
Feb
(41) |
Mar
(55) |
Apr
(18) |
May
(52) |
Jun
(51) |
Jul
(32) |
Aug
(21) |
Sep
(22) |
Oct
(28) |
Nov
(30) |
Dec
(11) |
2010 |
Jan
(6) |
Feb
(39) |
Mar
(28) |
Apr
(13) |
May
(29) |
Jun
(14) |
Jul
(28) |
Aug
(25) |
Sep
(19) |
Oct
(38) |
Nov
(40) |
Dec
(31) |
2011 |
Jan
(34) |
Feb
(36) |
Mar
(23) |
Apr
(27) |
May
(32) |
Jun
(48) |
Jul
(17) |
Aug
(25) |
Sep
(13) |
Oct
(16) |
Nov
(42) |
Dec
(39) |
2012 |
Jan
(15) |
Feb
(32) |
Mar
(37) |
Apr
(49) |
May
(10) |
Jun
(14) |
Jul
(9) |
Aug
(31) |
Sep
(27) |
Oct
(15) |
Nov
(24) |
Dec
(10) |
2013 |
Jan
(4) |
Feb
(33) |
Mar
(33) |
Apr
(31) |
May
(16) |
Jun
(31) |
Jul
(12) |
Aug
(43) |
Sep
(6) |
Oct
(21) |
Nov
(24) |
Dec
(15) |
2014 |
Jan
(8) |
Feb
(9) |
Mar
(42) |
Apr
(40) |
May
(37) |
Jun
(15) |
Jul
(30) |
Aug
(8) |
Sep
(20) |
Oct
(7) |
Nov
(1) |
Dec
(1) |
2015 |
Jan
(3) |
Feb
(11) |
Mar
(2) |
Apr
|
May
(3) |
Jun
(4) |
Jul
|
Aug
(5) |
Sep
(4) |
Oct
(4) |
Nov
(12) |
Dec
(11) |
2016 |
Jan
(5) |
Feb
|
Mar
|
Apr
|
May
(2) |
Jun
(2) |
Jul
(2) |
Aug
|
Sep
(17) |
Oct
(16) |
Nov
(7) |
Dec
|
2017 |
Jan
|
Feb
|
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
|
Aug
|
Sep
(2) |
Oct
|
Nov
|
Dec
|
2018 |
Jan
|
Feb
|
Mar
(2) |
Apr
(6) |
May
(4) |
Jun
|
Jul
|
Aug
(2) |
Sep
(2) |
Oct
|
Nov
|
Dec
|
2019 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(3) |
Jun
(4) |
Jul
|
Aug
|
Sep
(2) |
Oct
(3) |
Nov
|
Dec
|
2020 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: carlos c. <edi...@ya...> - 2016-10-07 19:45:24
|
Submit this bug here: https://sourceforge.net/apps/trac/w3af/newticket Python version: 2.6.6 (r266:84297, Aug 24 2010, 18:46:32) [MSC v.1500 32 bit (Intel)] GTK version:2.22.0 PyGTK version:2.22.0 w3af - Web Application Attack and Audit Framework Version: 1.1 (from SVN server) Revision: 4286 Author: Andres Riancho and the w3af team. Traceback (most recent call last): File "C:\Program Files\w3af\w3af\core\ui\gtkUi\reqResViewer.py", line 233, in _impactDone raise impact.exception w3afMustStopOnUrlError: No se puede establecer una conexión ya que el equipo de destino denegó expresamente dicha conexión |
From: carlos c. <edi...@ya...> - 2016-10-07 19:45:18
|
Submit this bug here: https://sourceforge.net/apps/trac/w3af/newticket Python version: 2.6.6 (r266:84297, Aug 24 2010, 18:46:32) [MSC v.1500 32 bit (Intel)] GTK version:2.22.0 PyGTK version:2.22.0 w3af - Web Application Attack and Audit Framework Version: 1.1 (from SVN server) Revision: 4286 Author: Andres Riancho and the w3af team. Traceback (most recent call last): File "C:\Program Files\w3af\w3af\core\ui\gtkUi\reqResViewer.py", line 233, in _impactDone raise impact.exception w3afMustStopOnUrlError: No se puede establecer una conexión ya que el equipo de destino denegó expresamente dicha conexión |
From: carlos c. <edi...@ya...> - 2016-10-07 19:44:57
|
Submit this bug here: https://sourceforge.net/apps/trac/w3af/newticket Python version: 2.6.6 (r266:84297, Aug 24 2010, 18:46:32) [MSC v.1500 32 bit (Intel)] GTK version:2.22.0 PyGTK version:2.22.0 w3af - Web Application Attack and Audit Framework Version: 1.1 (from SVN server) Revision: 4286 Author: Andres Riancho and the w3af team. Traceback (most recent call last): File "C:\Program Files\w3af\w3af\core\ui\gtkUi\reqResViewer.py", line 233, in _impactDone raise impact.exception w3afMustStopOnUrlError: No se puede establecer una conexión ya que el equipo de destino denegó expresamente dicha conexión |
From: carlos c. <edi...@ya...> - 2016-10-07 19:43:56
|
Submit this bug here: https://sourceforge.net/apps/trac/w3af/newticket Python version: 2.6.6 (r266:84297, Aug 24 2010, 18:46:32) [MSC v.1500 32 bit (Intel)] GTK version:2.22.0 PyGTK version:2.22.0 w3af - Web Application Attack and Audit Framework Version: 1.1 (from SVN server) Revision: 4286 Author: Andres Riancho and the w3af team. Traceback (most recent call last): File "C:\Program Files\w3af\w3af\core\ui\gtkUi\reqResViewer.py", line 233, in _impactDone raise impact.exception w3afMustStopOnUrlError: No se puede establecer una conexión ya que el equipo de destino denegó expresamente dicha conexión |
From: ad^2 <ads...@gm...> - 2016-10-05 15:45:41
|
Hello, First, it's always good to include the steps you used to reproduce the issue reported. Help us the community help you by providing more details and things you have tried. What version of w3af? GUI or Console? Your selection of plugins/profiles/exploits, etc.? (you mentioned OWASP top 10). What is the output of the scan? Try this and let me know if you find something interesting. w3af -s testfire.w3af.script [testfire script file contents] profiles use audit_high_risk plugins output html_file plugins output config html_file set output_file /root/testfire.html back plugins audit blind_sqli sqli target set target http://demo.testfire.net start Thx, ad^2 On Wed, Oct 5, 2016 at 1:59 AM, Shreyas M R <shr...@gm...> wrote: > Hi, > > I'm using w3af owasp top10 profile on http://demo.testfire.net/ which has > sqli and xss vulnerabilities. I'm not getting any vulnerabilities from w3af > scan. please anyone help me out in this. > > > > > [image: --] > > Shreyas M R > [image: http://]about.me/shreyasmrs > <http://about.me/shreyasmrs?promo=email_sig> > > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > > |
From: Shreyas M R <shr...@gm...> - 2016-10-05 06:00:07
|
Hi, I'm using w3af owasp top10 profile on http://demo.testfire.net/ which has sqli and xss vulnerabilities. I'm not getting any vulnerabilities from w3af scan. please anyone help me out in this. [image: --] Shreyas M R [image: http://]about.me/shreyasmrs <http://about.me/shreyasmrs?promo=email_sig> |
From: Andres R. <and...@gm...> - 2016-10-03 12:33:36
|
Mohsen, I've been linking to this document too often these last weeks: "How To Ask Questions The Smart Way" [0]. Sorry but based on your "question" I can only guess what your problem is. Please explain it a little bit more, follow guidelines from [0] and most likely someone will answer. [0] http://www.catb.org/esr/faqs/smart-questions.html On Fri, Sep 30, 2016 at 1:08 PM, mohsen Abbaspour <moh...@gm...> wrote: > hi > > i want to get pluggin and add this pluggin to another w3af app on > another system that cant connect to internet > how to get pluggin > > tnx > > -- > > > > > Check out my professional profile and connect with me on LinkedIn. > http://lnkd.in/RqFEqH > > ------------------------------------------------------------------------------ > > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: mohsen A. <moh...@gm...> - 2016-09-30 16:08:20
|
hi i want to get pluggin and add this pluggin to another w3af app on another system that cant connect to internet how to get pluggin tnx -- Check out my professional profile and connect with me on LinkedIn. http://lnkd.in/RqFEqH |
From: Andres R. <and...@gm...> - 2016-09-23 19:18:24
|
Please take a moment to read this document [0] and try again :) [0] http://www.catb.org/esr/faqs/smart-questions.html On Fri, Sep 23, 2016 at 5:31 AM, mohsen Abbaspour <moh...@gm...> wrote: > hi > i have a question > how many attack plugin and pattern are there in w3af?? > please introduce more about it > tnx > -- > > > > > Check out my professional profile and connect with me on LinkedIn. > http://lnkd.in/RqFEqH > > ------------------------------------------------------------------------------ > > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Andres R. <and...@gm...> - 2016-09-23 18:39:39
|
Can't repro if you don't give me the details On Thu, Sep 22, 2016 at 8:26 AM, Suhas Lalige <suh...@gm...> wrote: > I had enabled the same plugins and the target was also the same for the > second time. It was the same repetition of the first step but i'm not > getting the same result > > On 20 September 2016 at 23:52, Andres Riancho <and...@gm...> > wrote: > >> Suhas, >> >> Well... most likely the two scans had different plugins enabled. >> But if not... is there any way I can reproduce this potential issue? >> >> On Tue, Sep 20, 2016 at 11:44 AM, Suhas Lalige <suh...@gm...> >> wrote: >> > Hi all >> > I'm new to w3af. I tried running the scan by enabling crawl and audit >> > plugin, first time I got SQL injection vulnerabilities second time when >> I >> > repeated it again I could not find any vulnerabilities please help me >> out in >> > solving this issue >> > Thanks >> > Suhas >> > >> > >> > ------------------------------------------------------------ >> ------------------ >> > >> > _______________________________________________ >> > W3af-users mailing list >> > W3a...@li... >> > https://lists.sourceforge.net/lists/listinfo/w3af-users >> > >> >> >> >> -- >> Andrés Riancho >> Project Leader at w3af - http://w3af.org/ >> Web Application Attack and Audit Framework >> Twitter: @w3af >> GPG: 0x93C344F3 >> > > > ------------------------------------------------------------ > ------------------ > > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > > -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Andres R. <and...@gm...> - 2016-09-23 18:35:06
|
Ah, your initial bug report never mentioned pexpect. ^J is a control char, new line according to [0]. This doesn't seem to be a w3af problem. [0] http://www.robelle.com/smugbook/ascii.html On Fri, Sep 23, 2016 at 3:20 PM, ravi keerthi m d <rav...@gm...> wrote: > Even I tried the same way it works.. But while using pexpect python module > I'm facing issue.. > > Let's think it's a pexpect issue, but the same module works for Metasploit, > nessus, etc.. > > On Sep 23, 2016 11:45 PM, "Andres Riancho" <and...@gm...> wrote: >> >> Works on my PC (tm) >> >> [pablo:/home/pablo] 35m40s $ ssh pablo@127.0.0.1 >> The authenticity of host '127.0.0.1 (127.0.0.1)' can't be established. >> ECDSA key fingerprint is a0:6d:ef:23:e0:e0:0a:3a:63:67:cd:1d:4f:79:4d:4e. >> Are you sure you want to continue connecting (yes/no)? yes >> Warning: Permanently added '127.0.0.1' (ECDSA) to the list of known hosts. >> pablo@127.0.0.1's password: >> Welcome to Ubuntu 14.04.5 LTS (GNU/Linux 3.13.0-96-generic x86_64) >> >> * Documentation: https://help.ubuntu.com/ >> >> Last login: Mon Aug 8 13:59:49 2016 >> [pablo@eulogias:/home/pablo] 1 $ cd pch/w3af/ >> [pablo@eulogias:/home/pablo/pch/w3af] master ± ./w3af_console >> w3af>>> plugins >> w3af/plugins>>> back >> w3af>>> exit >> >> Liked it? Donate some money! >> >> [pablo@eulogias:/home/pablo/pch/w3af] master 12s ± >> >> >> >> On Thu, Sep 22, 2016 at 4:42 PM, ravi keerthi m d >> <rav...@gm...> wrote: >> > >> >> > Hi, >> >> > >> >> > Manually I am able to execute my w3af commands successfully. When >> >> > trying >> >> > to >> >> > execute same w3af commands using a ssh connection then it is >> >> > appending a >> >> > ^J, >> >> > so whatever commands I am executing it is executing like "^Jplugins". >> >> > >> >> > >> >> > Example: >> >> > root@kali# w3af_console >> >> > w3af >>> ^J >> >> > >> >> > this is the first output after executing w3af_console using ssh >> >> > connection >> >> > handler, now when I execute "plugins" command the output looks like >> >> > this >> >> > >> >> > >> >> > root@kali# w3af_console >> >> > w3af >>> ^Jplugins >> >> > >> >> > It is saying command not found. >> >> > >> >> > >> >> > Can you please help me out in this. Because using same ssh connection >> >> > handler I am able to run metasploit framework commands on msfconsole. >> >> > >> >> > >> >> > Thanks, >> >> > Ravi >> >> > >> >> > >> >> >> >> >> >> >> >> -- >> >> Andrés Riancho >> >> Project Leader at w3af - http://w3af.org/ >> >> Web Application Attack and Audit Framework >> >> Twitter: @w3af >> >> GPG: 0x93C344F3 >> > >> > >> > >> > ------------------------------------------------------------------------------ >> > >> > _______________________________________________ >> > W3af-users mailing list >> > W3a...@li... >> > https://lists.sourceforge.net/lists/listinfo/w3af-users >> > >> >> >> >> -- >> Andrés Riancho >> Project Leader at w3af - http://w3af.org/ >> Web Application Attack and Audit Framework >> Twitter: @w3af >> GPG: 0x93C344F3 -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: ravi k. m d <rav...@gm...> - 2016-09-23 18:20:45
|
Even I tried the same way it works.. But while using pexpect python module I'm facing issue.. Let's think it's a pexpect issue, but the same module works for Metasploit, nessus, etc.. On Sep 23, 2016 11:45 PM, "Andres Riancho" <and...@gm...> wrote: > Works on my PC (tm) > > [pablo:/home/pablo] 35m40s $ ssh pablo@127.0.0.1 > The authenticity of host '127.0.0.1 (127.0.0.1)' can't be established. > ECDSA key fingerprint is a0:6d:ef:23:e0:e0:0a:3a:63:67:cd:1d:4f:79:4d:4e. > Are you sure you want to continue connecting (yes/no)? yes > Warning: Permanently added '127.0.0.1' (ECDSA) to the list of known hosts. > pablo@127.0.0.1's password: > Welcome to Ubuntu 14.04.5 LTS (GNU/Linux 3.13.0-96-generic x86_64) > > * Documentation: https://help.ubuntu.com/ > > Last login: Mon Aug 8 13:59:49 2016 > [pablo@eulogias:/home/pablo] 1 $ cd pch/w3af/ > [pablo@eulogias:/home/pablo/pch/w3af] master ± ./w3af_console > w3af>>> plugins > w3af/plugins>>> back > w3af>>> exit > > Liked it? Donate some money! > > [pablo@eulogias:/home/pablo/pch/w3af] master 12s ± > > > > On Thu, Sep 22, 2016 at 4:42 PM, ravi keerthi m d > <rav...@gm...> wrote: > > > >> > Hi, > >> > > >> > Manually I am able to execute my w3af commands successfully. When > trying > >> > to > >> > execute same w3af commands using a ssh connection then it is > appending a > >> > ^J, > >> > so whatever commands I am executing it is executing like "^Jplugins". > >> > > >> > > >> > Example: > >> > root@kali# w3af_console > >> > w3af >>> ^J > >> > > >> > this is the first output after executing w3af_console using ssh > >> > connection > >> > handler, now when I execute "plugins" command the output looks like > this > >> > > >> > > >> > root@kali# w3af_console > >> > w3af >>> ^Jplugins > >> > > >> > It is saying command not found. > >> > > >> > > >> > Can you please help me out in this. Because using same ssh connection > >> > handler I am able to run metasploit framework commands on msfconsole. > >> > > >> > > >> > Thanks, > >> > Ravi > >> > > >> > > >> > >> > >> > >> -- > >> Andrés Riancho > >> Project Leader at w3af - http://w3af.org/ > >> Web Application Attack and Audit Framework > >> Twitter: @w3af > >> GPG: 0x93C344F3 > > > > > > ------------------------------------------------------------ > ------------------ > > > > _______________________________________________ > > W3af-users mailing list > > W3a...@li... > > https://lists.sourceforge.net/lists/listinfo/w3af-users > > > > > > -- > Andrés Riancho > Project Leader at w3af - http://w3af.org/ > Web Application Attack and Audit Framework > Twitter: @w3af > GPG: 0x93C344F3 > |
From: Andres R. <and...@gm...> - 2016-09-23 18:15:45
|
Works on my PC (tm) [pablo:/home/pablo] 35m40s $ ssh pablo@127.0.0.1 The authenticity of host '127.0.0.1 (127.0.0.1)' can't be established. ECDSA key fingerprint is a0:6d:ef:23:e0:e0:0a:3a:63:67:cd:1d:4f:79:4d:4e. Are you sure you want to continue connecting (yes/no)? yes Warning: Permanently added '127.0.0.1' (ECDSA) to the list of known hosts. pablo@127.0.0.1's password: Welcome to Ubuntu 14.04.5 LTS (GNU/Linux 3.13.0-96-generic x86_64) * Documentation: https://help.ubuntu.com/ Last login: Mon Aug 8 13:59:49 2016 [pablo@eulogias:/home/pablo] 1 $ cd pch/w3af/ [pablo@eulogias:/home/pablo/pch/w3af] master ± ./w3af_console w3af>>> plugins w3af/plugins>>> back w3af>>> exit Liked it? Donate some money! [pablo@eulogias:/home/pablo/pch/w3af] master 12s ± On Thu, Sep 22, 2016 at 4:42 PM, ravi keerthi m d <rav...@gm...> wrote: > >> > Hi, >> > >> > Manually I am able to execute my w3af commands successfully. When trying >> > to >> > execute same w3af commands using a ssh connection then it is appending a >> > ^J, >> > so whatever commands I am executing it is executing like "^Jplugins". >> > >> > >> > Example: >> > root@kali# w3af_console >> > w3af >>> ^J >> > >> > this is the first output after executing w3af_console using ssh >> > connection >> > handler, now when I execute "plugins" command the output looks like this >> > >> > >> > root@kali# w3af_console >> > w3af >>> ^Jplugins >> > >> > It is saying command not found. >> > >> > >> > Can you please help me out in this. Because using same ssh connection >> > handler I am able to run metasploit framework commands on msfconsole. >> > >> > >> > Thanks, >> > Ravi >> > >> > >> >> >> >> -- >> Andrés Riancho >> Project Leader at w3af - http://w3af.org/ >> Web Application Attack and Audit Framework >> Twitter: @w3af >> GPG: 0x93C344F3 > > > ------------------------------------------------------------------------------ > > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: ravi k. m d <rav...@gm...> - 2016-09-22 19:43:07
|
> > Hi, > > > > Manually I am able to execute my w3af commands successfully. When trying to > > execute same w3af commands using a ssh connection then it is appending a ^J, > > so whatever commands I am executing it is executing like "^Jplugins". > > > > > > Example: > > root@kali# w3af_console > > w3af >>> ^J > > > > this is the first output after executing w3af_console using ssh connection > > handler, now when I execute "plugins" command the output looks like this > > > > > > root@kali# w3af_console > > w3af >>> ^Jplugins > > > > It is saying command not found. > > > > > > Can you please help me out in this. Because using same ssh connection > > handler I am able to run metasploit framework commands on msfconsole. > > > > > > Thanks, > > Ravi > > > > > > > > -- > Andrés Riancho > Project Leader at w3af - http://w3af.org/ > Web Application Attack and Audit Framework > Twitter: @w3af > GPG: 0x93C344F3 |
From: Suhas L. <suh...@gm...> - 2016-09-22 11:27:00
|
I had enabled the same plugins and the target was also the same for the second time. It was the same repetition of the first step but i'm not getting the same result On 20 September 2016 at 23:52, Andres Riancho <and...@gm...> wrote: > Suhas, > > Well... most likely the two scans had different plugins enabled. > But if not... is there any way I can reproduce this potential issue? > > On Tue, Sep 20, 2016 at 11:44 AM, Suhas Lalige <suh...@gm...> > wrote: > > Hi all > > I'm new to w3af. I tried running the scan by enabling crawl and audit > > plugin, first time I got SQL injection vulnerabilities second time when I > > repeated it again I could not find any vulnerabilities please help me > out in > > solving this issue > > Thanks > > Suhas > > > > > > ------------------------------------------------------------ > ------------------ > > > > _______________________________________________ > > W3af-users mailing list > > W3a...@li... > > https://lists.sourceforge.net/lists/listinfo/w3af-users > > > > > > -- > Andrés Riancho > Project Leader at w3af - http://w3af.org/ > Web Application Attack and Audit Framework > Twitter: @w3af > GPG: 0x93C344F3 > |
From: Andres R. <and...@gm...> - 2016-09-20 18:23:23
|
Suhas, Well... most likely the two scans had different plugins enabled. But if not... is there any way I can reproduce this potential issue? On Tue, Sep 20, 2016 at 11:44 AM, Suhas Lalige <suh...@gm...> wrote: > Hi all > I'm new to w3af. I tried running the scan by enabling crawl and audit > plugin, first time I got SQL injection vulnerabilities second time when I > repeated it again I could not find any vulnerabilities please help me out in > solving this issue > Thanks > Suhas > > > ------------------------------------------------------------------------------ > > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Suhas L. <suh...@gm...> - 2016-09-20 14:44:48
|
Hi all I'm new to w3af. I tried running the scan by enabling crawl and audit plugin, first time I got SQL injection vulnerabilities second time when I repeated it again I could not find any vulnerabilities please help me out in solving this issue Thanks Suhas |
From: Andres R. <and...@gm...> - 2016-09-19 14:15:45
|
Shreyas, I believe that your question is way too open. To answer it someone would have to spend considerable time setting up the environment, running w3af, etc. If you've got the time, please read [0]: "In the world of hackers, the kind of answers you get to your technical questions depends as much on the way you ask the questions as on the difficulty of developing the answer. This guide will teach you how to ask questions in a way more likely to get you a satisfactory answer." [0] http://www.catb.org/esr/faqs/smart-questions.html Regards, On Thu, Sep 15, 2016 at 2:34 PM, Shreyas M R <shr...@gm...> wrote: > I ran w3af on owaspbwa I could not exploit the vulns. > Can anyone help me with the plugin details and configuration > > > Awaiting for reply > > Thanks and Regards > > > > Shreyas M R > about.me/shreyasmrs > > > > ------------------------------------------------------------------------------ > > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Shreyas M R <shr...@gm...> - 2016-09-15 17:34:56
|
I ran w3af on owaspbwa I could not exploit the vulns. Can anyone help me with the plugin details and configuration Awaiting for reply Thanks and Regards [image: --] Shreyas M R [image: http://]about.me/shreyasmrs <http://about.me/shreyasmrs?promo=email_sig> |
From: Andres R. <and...@gm...> - 2016-09-02 14:19:58
|
I believe the answer is in the authentication part of docs [0], most likely in [1]. Regarding 2FA, the way I would do it is to authenticate using a browser, then get the cookie and set it in w3af as explained in [1] [0] http://docs.w3af.org/en/latest/authentication.html [1] http://docs.w3af.org/en/latest/authentication.html#setting-http-cookie On Thu, Sep 1, 2016 at 9:16 PM, Vimal SRINIVASAN <onl...@gm...> wrote: > Nice point highlighted by Blaharski. I am curious what if the SSO have 2FA. > > Regards, > Vimal. > > > On Sep 1, 2016 11:11 PM, "Blaharski, Jared" <jar...@co...> > wrote: >> >> To Whom It May Concern: >> >> >> >> The website that we would like to scan has a SSO system and a HTTP >> redirect. Will your software have any trouble with handling that when doing >> the crawl through the website? >> >> >> >> ------------------------------------------------------------------------------ >> >> _______________________________________________ >> W3af-users mailing list >> W3a...@li... >> https://lists.sourceforge.net/lists/listinfo/w3af-users >> > > ------------------------------------------------------------------------------ > > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Vimal S. <onl...@gm...> - 2016-09-02 00:16:29
|
Nice point highlighted by Blaharski. I am curious what if the SSO have 2FA. Regards, Vimal. On Sep 1, 2016 11:11 PM, "Blaharski, Jared" <jar...@co...> wrote: > To Whom It May Concern: > > > > The website that we would like to scan has a SSO system and a HTTP > redirect. Will your software have any trouble with handling that when doing > the crawl through the website? > > ------------------------------------------------------------ > ------------------ > > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > > |
From: Taras <ox...@ox...> - 2016-09-01 21:02:49
|
Hi, Jared! You can try! ;) В Чт, 01/09/2016 в 14:54 +0000, Blaharski, Jared пишет: > To Whom It May Concern: > > The website that we would like to scan has a SSO system and a HTTP > redirect. Will your software have any trouble with handling that when > doing the crawl through the website? > ------------------------------------------------------------------- > ----------- > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users -- Taras https://oxdef.info |
From: Blaharski, J. <jar...@co...> - 2016-09-01 15:09:39
|
To Whom It May Concern: The website that we would like to scan has a SSO system and a HTTP redirect. Will your software have any trouble with handling that when doing the crawl through the website? |
From: Andres R. <and...@gm...> - 2016-07-25 14:31:48
|
Tiago, On Sat, Jul 23, 2016 at 12:32 PM, Tiago Vieira <tia...@no...> wrote: > Hello, > > My name is Tiago, I'm doing a master thesis in web security and I'm using > w3af to perform some tests. > > My question is related with the scan, when we select a URL to attack, does > the application performs posts on that URL? Most likely not, it depends on the plugins you enabled. If you enabled the web_spider plugin it will perform a GET to the URL, retrieve the forms, and perform POST on those forms. > I've tried manual requests and fuzzing but this does not allow simple > parametrization for multiple requests and I would prefer using the available > plugins. > > One of the applications I'm testing has several assync requests and I wanted > to test each one of them with the available plugins. You may want to read: http://docs.w3af.org/en/latest/advanced-use-cases.html > Thank you > Best regards > > > > ------------------------------------------------------------------------------ > What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic > patterns at an interface-level. Reveals which users, apps, and protocols are > consuming the most bandwidth. Provides multi-vendor support for NetFlow, > J-Flow, sFlow and other flows. Make informed decisions using capacity > planning > reports.http://sdm.link/zohodev2dev > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Tiago V. <tia...@no...> - 2016-07-23 17:06:01
|
Hello, My name is Tiago, I'm doing a master thesis in web security and I'm using w3af to perform some tests. My question is related with the scan, when we select a URL to attack, does the application performs posts on that URL? I've tried manual requests and fuzzing but this does not allow simple parametrization for multiple requests and I would prefer using the available plugins. One of the applications I'm testing has several assync requests and I wanted to test each one of them with the available plugins. Thank you Best regards? |