w3af-users Mailing List for w3af (Page 4)
Status: Beta
Brought to you by:
andresriancho
You can subscribe to this list here.
2007 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(6) |
Jul
(11) |
Aug
|
Sep
(9) |
Oct
(40) |
Nov
(20) |
Dec
(10) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2008 |
Jan
(77) |
Feb
(36) |
Mar
(54) |
Apr
(142) |
May
(37) |
Jun
(37) |
Jul
(71) |
Aug
(44) |
Sep
(15) |
Oct
(85) |
Nov
(61) |
Dec
(68) |
2009 |
Jan
(44) |
Feb
(41) |
Mar
(55) |
Apr
(18) |
May
(52) |
Jun
(51) |
Jul
(32) |
Aug
(21) |
Sep
(22) |
Oct
(28) |
Nov
(30) |
Dec
(11) |
2010 |
Jan
(6) |
Feb
(39) |
Mar
(28) |
Apr
(13) |
May
(29) |
Jun
(14) |
Jul
(28) |
Aug
(25) |
Sep
(19) |
Oct
(38) |
Nov
(40) |
Dec
(31) |
2011 |
Jan
(34) |
Feb
(36) |
Mar
(23) |
Apr
(27) |
May
(32) |
Jun
(48) |
Jul
(17) |
Aug
(25) |
Sep
(13) |
Oct
(16) |
Nov
(42) |
Dec
(39) |
2012 |
Jan
(15) |
Feb
(32) |
Mar
(37) |
Apr
(49) |
May
(10) |
Jun
(14) |
Jul
(9) |
Aug
(31) |
Sep
(27) |
Oct
(15) |
Nov
(24) |
Dec
(10) |
2013 |
Jan
(4) |
Feb
(33) |
Mar
(33) |
Apr
(31) |
May
(16) |
Jun
(31) |
Jul
(12) |
Aug
(43) |
Sep
(6) |
Oct
(21) |
Nov
(24) |
Dec
(15) |
2014 |
Jan
(8) |
Feb
(9) |
Mar
(42) |
Apr
(40) |
May
(37) |
Jun
(15) |
Jul
(30) |
Aug
(8) |
Sep
(20) |
Oct
(7) |
Nov
(1) |
Dec
(1) |
2015 |
Jan
(3) |
Feb
(11) |
Mar
(2) |
Apr
|
May
(3) |
Jun
(4) |
Jul
|
Aug
(5) |
Sep
(4) |
Oct
(4) |
Nov
(12) |
Dec
(11) |
2016 |
Jan
(5) |
Feb
|
Mar
|
Apr
|
May
(2) |
Jun
(2) |
Jul
(2) |
Aug
|
Sep
(17) |
Oct
(16) |
Nov
(7) |
Dec
|
2017 |
Jan
|
Feb
|
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
|
Aug
|
Sep
(2) |
Oct
|
Nov
|
Dec
|
2018 |
Jan
|
Feb
|
Mar
(2) |
Apr
(6) |
May
(4) |
Jun
|
Jul
|
Aug
(2) |
Sep
(2) |
Oct
|
Nov
|
Dec
|
2019 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(3) |
Jun
(4) |
Jul
|
Aug
|
Sep
(2) |
Oct
(3) |
Nov
|
Dec
|
2020 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: Andres R. <and...@gm...> - 2016-06-13 15:01:32
|
I believe you can't fix this issue by changing any settings. If possible follow these [0] steps to report a bug. [0] http://docs.w3af.org/en/latest/report-a-bug.html On Mon, Jun 13, 2016 at 1:02 AM, Kazuo Fukukawa <k-f...@uf...> wrote: > To Whom It May Concern: > > Thank you so much for this. Just Now I do w3af first time. > I checked Mailing Lists of w3af-users, but I could not find any Informations about this. > > I have tried to check my Web site (include Japanese characters) with w3af spider_man proxy using Firefox. > But I met that Japanese Characters are changed, English Characters are not changed. > So I could NOT access all pages in my Web site (include Japanese characters) correctly. > I would like to know how I should do w3af_gui settings (spider_man or other) to avoid this issue. > > Of course, Japanese Characters are NOT changed without w3af spider_man proxy. > > w3af in ubuntu 14.04 > Version: 1.7.6 > Revision: 5aaef986c5-17 > Branch: master > Local changes:No > > Best Regards, > Fukukawa > > > ------------------------------------------------------------------------------ > What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic > patterns at an interface-level. Reveals which users, apps, and protocols are > consuming the most bandwidth. Provides multi-vendor support for NetFlow, > J-Flow, sFlow and other flows. Make informed decisions using capacity > planning reports. https://ad.doubleclick.net/ddm/clk/305295220;132659582;e > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Kazuo F. <k-f...@uf...> - 2016-06-13 05:00:38
|
To Whom It May Concern: Thank you so much for this. Just Now I do w3af first time. I checked Mailing Lists of w3af-users, but I could not find any Informations about this. I have tried to check my Web site (include Japanese characters) with w3af spider_man proxy using Firefox. But I met that Japanese Characters are changed, English Characters are not changed. So I could NOT access all pages in my Web site (include Japanese characters) correctly. I would like to know how I should do w3af_gui settings (spider_man or other) to avoid this issue. Of course, Japanese Characters are NOT changed without w3af spider_man proxy. w3af in ubuntu 14.04 Version: 1.7.6 Revision: 5aaef986c5-17 Branch: master Local changes:No Best Regards, Fukukawa |
From: Andres R. <and...@gm...> - 2016-05-16 14:44:42
|
Luciano, Thank you so much for this! I hated that outdated w3af package in debian :) Now all debian users will be able to "apt-get install w3af" and get the latest and greatest; which fixes 3 years (OMG!) of bugs :) On Fri, May 13, 2016 at 5:12 PM, Luciano Bello <lu...@de...> wrote: > Hi w3af'ers, > I just uploaded a new w3af Debian package, updating the (literary) three- > year-old version that was in the repo. The new upload it's the current git > head, so it should include all the features. > > It might take some minutes to be in your nearest mirror. When there, go > and take a look to it. Use it and report the bugs (to > https://bugs.debian.org/src:w3af) and contribute with patches. > > Now, the Debian package is co-maintained by a small group of peopl. this > time, we hope to it in good shape. If you are interested, let us know! > > Cheers, luciano > > ------------------------------------------------------------------------------ > Mobile security can be enabling, not merely restricting. Employees who > bring their own devices (BYOD) to work are irked by the imposition of MDM > restrictions. Mobile Device Manager Plus allows you to control only the > apps on BYO-devices by containerizing them, leaving personal data untouched! > https://ad.doubleclick.net/ddm/clk/304595813;131938128;j > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Luciano B. <lu...@de...> - 2016-05-13 20:36:39
|
Hi w3af'ers, I just uploaded a new w3af Debian package, updating the (literary) three- year-old version that was in the repo. The new upload it's the current git head, so it should include all the features. It might take some minutes to be in your nearest mirror. When there, go and take a look to it. Use it and report the bugs (to https://bugs.debian.org/src:w3af) and contribute with patches. Now, the Debian package is co-maintained by a small group of peopl. this time, we hope to it in good shape. If you are interested, let us know! Cheers, luciano |
From: Andres R. <and...@gm...> - 2016-01-13 20:22:21
|
Been there, done that, not so easy as it sounds. See these repos with tools I created to analyze w3af performance issues: https://github.com/andresriancho/collector/ https://github.com/andresriancho/w3af-performance-analysis/ You (and anyone else on the list) is more than welcome to run these tools, collect memory usage data and help me find the problem :) On Fri, Jan 8, 2016 at 9:17 PM, Andrew King <aki...@gm...> wrote: > Here's a thought... Install some memory dumping tool and dump the process > memory to see what is actually in it? Might be faster than trial and error > and looking at each individual plugin and whittling away at features. > > On Fri, Jan 8, 2016 at 6:51 AM, Vojtěch Polášek <kr...@gm...> wrote: >> >> Hi, >> okay and can I offer any help with this? I have chosen W3AF as part of >> my bachelor thesis and this presents a big problem for me, because I >> can't test the provided application. Offcourse this is not the only >> reason. >> Best regards, >> Vojta >> >> >> Dne 8.1.2016 v 12:41 Andres Riancho napsal(a): >> > On Fri, Jan 8, 2016 at 6:40 AM, Vojtěch Polášek <kr...@gm...> >> > wrote: >> >> Greetings, >> >> I am testing a web application with lots of Javascript with W3AF. I use >> >> spider_man to gather starting information and I use almost all audit >> >> plugins but no other crawling plugins. >> >> I browsed just through two pages and submitted one form with spider_man >> >> to get some starting data. >> >> Unfortunatelly W3AF scans the application for terribly long time. It >> >> goes from for example 300 requests per minute to 10 per minute and >> >> still >> >> going lower. >> >> When I press enter during scanning it is showing still the same >> >> crawling >> >> and auditing url, just the number of requests is dropping. >> >> I can post you some more information about used plugins if you need it. >> >> Why is this happening? >> > I've seen this issue too, not sure why it happens, might be related >> > with [0] but I'm unsure. >> > >> > [0] https://github.com/andresriancho/w3af/issues/12505 >> > >> >> Thanks and best regards, >> >> Vojta >> >> >> >> >> >> >> >> ------------------------------------------------------------------------------ >> >> _______________________________________________ >> >> W3af-users mailing list >> >> W3a...@li... >> >> https://lists.sourceforge.net/lists/listinfo/w3af-users >> > >> > >> >> >> >> ------------------------------------------------------------------------------ >> _______________________________________________ >> W3af-users mailing list >> W3a...@li... >> https://lists.sourceforge.net/lists/listinfo/w3af-users > > > > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Andrew K. <aki...@gm...> - 2016-01-09 00:17:20
|
Here's a thought... Install some memory dumping tool and dump the process memory to see what is actually in it? Might be faster than trial and error and looking at each individual plugin and whittling away at features. On Fri, Jan 8, 2016 at 6:51 AM, Vojtěch Polášek <kr...@gm...> wrote: > Hi, > okay and can I offer any help with this? I have chosen W3AF as part of > my bachelor thesis and this presents a big problem for me, because I > can't test the provided application. Offcourse this is not the only reason. > Best regards, > Vojta > > > Dne 8.1.2016 v 12:41 Andres Riancho napsal(a): > > On Fri, Jan 8, 2016 at 6:40 AM, Vojtěch Polášek <kr...@gm...> > wrote: > >> Greetings, > >> I am testing a web application with lots of Javascript with W3AF. I use > >> spider_man to gather starting information and I use almost all audit > >> plugins but no other crawling plugins. > >> I browsed just through two pages and submitted one form with spider_man > >> to get some starting data. > >> Unfortunatelly W3AF scans the application for terribly long time. It > >> goes from for example 300 requests per minute to 10 per minute and still > >> going lower. > >> When I press enter during scanning it is showing still the same crawling > >> and auditing url, just the number of requests is dropping. > >> I can post you some more information about used plugins if you need it. > >> Why is this happening? > > I've seen this issue too, not sure why it happens, might be related > > with [0] but I'm unsure. > > > > [0] https://github.com/andresriancho/w3af/issues/12505 > > > >> Thanks and best regards, > >> Vojta > >> > >> > >> > ------------------------------------------------------------------------------ > >> _______________________________________________ > >> W3af-users mailing list > >> W3a...@li... > >> https://lists.sourceforge.net/lists/listinfo/w3af-users > > > > > > > > ------------------------------------------------------------------------------ > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > |
From: Vojtěch P. <kr...@gm...> - 2016-01-08 11:52:04
|
Hi, okay and can I offer any help with this? I have chosen W3AF as part of my bachelor thesis and this presents a big problem for me, because I can't test the provided application. Offcourse this is not the only reason. Best regards, Vojta Dne 8.1.2016 v 12:41 Andres Riancho napsal(a): > On Fri, Jan 8, 2016 at 6:40 AM, Vojtěch Polášek <kr...@gm...> wrote: >> Greetings, >> I am testing a web application with lots of Javascript with W3AF. I use >> spider_man to gather starting information and I use almost all audit >> plugins but no other crawling plugins. >> I browsed just through two pages and submitted one form with spider_man >> to get some starting data. >> Unfortunatelly W3AF scans the application for terribly long time. It >> goes from for example 300 requests per minute to 10 per minute and still >> going lower. >> When I press enter during scanning it is showing still the same crawling >> and auditing url, just the number of requests is dropping. >> I can post you some more information about used plugins if you need it. >> Why is this happening? > I've seen this issue too, not sure why it happens, might be related > with [0] but I'm unsure. > > [0] https://github.com/andresriancho/w3af/issues/12505 > >> Thanks and best regards, >> Vojta >> >> >> ------------------------------------------------------------------------------ >> _______________________________________________ >> W3af-users mailing list >> W3a...@li... >> https://lists.sourceforge.net/lists/listinfo/w3af-users > > |
From: Andres R. <and...@gm...> - 2016-01-08 11:41:48
|
On Fri, Jan 8, 2016 at 6:40 AM, Vojtěch Polášek <kr...@gm...> wrote: > Greetings, > I am testing a web application with lots of Javascript with W3AF. I use > spider_man to gather starting information and I use almost all audit > plugins but no other crawling plugins. > I browsed just through two pages and submitted one form with spider_man > to get some starting data. > Unfortunatelly W3AF scans the application for terribly long time. It > goes from for example 300 requests per minute to 10 per minute and still > going lower. > When I press enter during scanning it is showing still the same crawling > and auditing url, just the number of requests is dropping. > I can post you some more information about used plugins if you need it. > Why is this happening? I've seen this issue too, not sure why it happens, might be related with [0] but I'm unsure. [0] https://github.com/andresriancho/w3af/issues/12505 > Thanks and best regards, > Vojta > > > ------------------------------------------------------------------------------ > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Vojtěch P. <kr...@gm...> - 2016-01-08 09:40:17
|
Greetings, I am testing a web application with lots of Javascript with W3AF. I use spider_man to gather starting information and I use almost all audit plugins but no other crawling plugins. I browsed just through two pages and submitted one form with spider_man to get some starting data. Unfortunatelly W3AF scans the application for terribly long time. It goes from for example 300 requests per minute to 10 per minute and still going lower. When I press enter during scanning it is showing still the same crawling and auditing url, just the number of requests is dropping. I can post you some more information about used plugins if you need it. Why is this happening? Thanks and best regards, Vojta |
From: Vojtěch P. <kr...@gm...> - 2015-12-17 08:36:31
|
Hi, thank you very much for your suggestions. Could you please give me some hint, why Webgoat is not a good solution for measuring of successes/failures of W3AF? Thank you, Vojta Dne 1.12.2015 v 17:50 Matt Tesauro napsal(a): > Vojtech, > > I'd suggest you look at this project: > https://www.owasp.org/index.php/OWASP_Vulnerable_Web_Applications_Directory_Project > > In the "Off-line" tab, there's a list of apps and the technology used > to create then. > > For instance, Bodgeit Store is a Java based vulnerable app: > https://github.com/psiinon/bodgeit > > Best of luck! > > -- > -- Matt Tesauro > OWASP AppSec Pipeline Lead > https://www.owasp.org/index.php/OWASP_AppSec_Pipeline > OWASP WTE Project Lead > _https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project_ > http://AppSecLive.org - Community and Download site > > > On Tue, Dec 1, 2015 at 7:42 AM, Vojtěch Polášek <kr...@gm... > <mailto:kr...@gm...>> wrote: > > Hi, > I would like to run W3AF against a commercial web application > which uses > similar technologies as Webgoat. Do you think that applications, which > you mentioned, will be able to provide some baseline for comparing of > results? > I need to find if W3AF can correctly detect vulnerabilities in > deliberately vulnerable applications before running it against the > commercial application. > Vulnerable application should be as close as possible to the > commercial > one in terms of used technologies. > Thank you, > Vojtěch Polášek > > > Dne 1.12.2015 v 14:19 Andres Riancho napsal(a): > > webgoat is not usually a good target for testing scanners. I would > > recommend other applications such as: > > * http://testphp.acunetix.com/ > > * https://github.com/andresriancho/django-moth > > > > On Mon, Nov 30, 2015 at 3:41 PM, Vojtěch Polášek > <kr...@gm... <mailto:kr...@gm...>> wrote: > >> Greetings, > >> thanks for reply, i will try it out. > >> To be exact, I am running W3Af against Owasp Webgoat, which > runs on Tomcat. > >> Best regards, > >> Vojta > >> > >> Dne 30.11.2015 v 18:54 Andres Riancho napsal(a): > >>> Vojtěch, > >>> > >>> Questions are welcome :) > >>> > >>> I assume you wanted to say JavaScript instead of Java, if > JS is > >>> heavily used, then yes the web_spider is "almost useless". > >>> > >>> Well, the scan of the target URL can't be prevented, but > if you > >>> set the URL to http://target.com/ and disable web_spider, then > w3af > >>> won't have any parameters to find vulnerabilities in and the > target is > >>> "ignored" (most likely, haven't tested it). > >>> > >>> Regards, > >>> > >>> On Mon, Nov 30, 2015 at 2:48 PM, Vojtěch Polášek > <kr...@gm... <mailto:kr...@gm...>> wrote: > >>>> Greetings, > >>>> my name is Vojtěch Polášek and I am a blind IT student from > Czech Republic. > >>>> As a part of my bachelor thesis, I am researching some tools for > >>>> security analysis of web applications. One of those tools is > W3AF, so > >>>> expect some questions in near time :-) > >>>> I need to perform analysis of Java application, where > web_spider is > >>>> useless. Therefore I use spider_man plugin. My question is; > would it be > >>>> possible to prevent initial scan of the URL set as target? > >>>> Because it does not make much sense, as all needed input is > facilitated > >>>> through spider_man. > >>>> Thank you for your response and best regards, > >>>> Vojtěch Polášek > >>>> > >>>> > ------------------------------------------------------------------------------ > >>>> Go from Idea to Many App Stores Faster with Intel(R) XDK > >>>> Give your users amazing mobile app experiences with Intel(R) XDK. > >>>> Use one codebase in this all-in-one HTML5 development > environment. > >>>> Design, debug & build mobile apps & 2D/3D high-impact games > for multiple OSs. > >>>> http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 > >>>> _______________________________________________ > >>>> W3af-users mailing list > >>>> W3a...@li... > <mailto:W3a...@li...> > >>>> https://lists.sourceforge.net/lists/listinfo/w3af-users > >>> > >> > >> > ------------------------------------------------------------------------------ > >> Go from Idea to Many App Stores Faster with Intel(R) XDK > >> Give your users amazing mobile app experiences with Intel(R) XDK. > >> Use one codebase in this all-in-one HTML5 development environment. > >> Design, debug & build mobile apps & 2D/3D high-impact games for > multiple OSs. > >> http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 > >> _______________________________________________ > >> W3af-users mailing list > >> W3a...@li... > <mailto:W3a...@li...> > >> https://lists.sourceforge.net/lists/listinfo/w3af-users > > > > > > > ------------------------------------------------------------------------------ > Go from Idea to Many App Stores Faster with Intel(R) XDK > Give your users amazing mobile app experiences with Intel(R) XDK. > Use one codebase in this all-in-one HTML5 development environment. > Design, debug & build mobile apps & 2D/3D high-impact games for > multiple OSs. > http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 > _______________________________________________ > W3af-users mailing list > W3a...@li... > <mailto:W3a...@li...> > https://lists.sourceforge.net/lists/listinfo/w3af-users > > |
From: Andres R. <and...@gm...> - 2015-12-14 12:25:25
|
I believe you'll have to use something like Celery or Python RQ [0] to queue the job and run it in workers. The worker will receive the URL as parameter and run (almost) the same steps as start() in console UI. [0] http://python-rq.org/ On Sun, Dec 13, 2015 at 1:15 PM, Luigino <ar...@gm...> wrote: > Hello all, > I'm a newbie. I'm making test for learn w3af. > I want to create a form in a website with a field for send an url. > My goal is to perform a w3af scan against the url received from the form. > I can't found any resources about it. > Can someone give a little help? > Thank you in advanced. > > > ------------------------------------------------------------------------------ > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Luigino <ar...@gm...> - 2015-12-13 16:30:15
|
Hello all, I'm a newbie. I'm making test for learn w3af. I want to create a form in a website with a field for send an url. My goal is to perform a w3af scan against the url received from the form. I can't found any resources about it. Can someone give a little help? Thank you in advanced. |
From: Vojtěch P. <kr...@gm...> - 2015-12-11 17:45:22
|
Hi, Thanks for replies. One more question: which address to configure for spider_man? I think that I should use the address of the ethernet interface of the container, not the localhost, right? Thanks, Vojta Dne 10.12.2015 v 13:47 Andres Riancho napsal(a): > Vojta, > > Please read answers inline: > > On Wed, Dec 9, 2015 at 12:46 PM, Vojtěch Polášek <kr...@gm...> wrote: >> Greetings, >> I need to use spider_man plugin for my testing. I am running W3AF within >> Docker on Windows server 2012. > Awesome! > >> I run something like >> docker run -p 44444:44444: ... andresriancho/w3af > That sounds like the right way to run the program to get the port > to be exposed. > >> But I can't get the proxy to work properly. I tried every possible >> combination. In W3AF's config, I used container localhost and container >> IP address. In my browser, I used host's localhost and also IP address >> of the docker machine. Nothing works. Does the port need to be exposed >> in the docker file to get this working? > I never tried it myself, but once you start the scan, and if > -p44444:44444 is used, you should be able to connect from your windows > host to 127.0.0.1:44444 > >> Could you please help me? I can not continue without using spider_man. >> Thanks, >> Vojta >> >> ------------------------------------------------------------------------------ >> _______________________________________________ >> W3af-users mailing list >> W3a...@li... >> https://lists.sourceforge.net/lists/listinfo/w3af-users > > |
From: Andres R. <and...@gm...> - 2015-12-10 12:47:57
|
Vojta, Please read answers inline: On Wed, Dec 9, 2015 at 12:46 PM, Vojtěch Polášek <kr...@gm...> wrote: > Greetings, > I need to use spider_man plugin for my testing. I am running W3AF within > Docker on Windows server 2012. Awesome! > I run something like > docker run -p 44444:44444: ... andresriancho/w3af That sounds like the right way to run the program to get the port to be exposed. > But I can't get the proxy to work properly. I tried every possible > combination. In W3AF's config, I used container localhost and container > IP address. In my browser, I used host's localhost and also IP address > of the docker machine. Nothing works. Does the port need to be exposed > in the docker file to get this working? I never tried it myself, but once you start the scan, and if -p44444:44444 is used, you should be able to connect from your windows host to 127.0.0.1:44444 > Could you please help me? I can not continue without using spider_man. > Thanks, > Vojta > > ------------------------------------------------------------------------------ > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Vojtěch P. <kr...@gm...> - 2015-12-09 15:46:29
|
Greetings, I need to use spider_man plugin for my testing. I am running W3AF within Docker on Windows server 2012. I run something like docker run -p 44444:44444: ... andresriancho/w3af But I can't get the proxy to work properly. I tried every possible combination. In W3AF's config, I used container localhost and container IP address. In my browser, I used host's localhost and also IP address of the docker machine. Nothing works. Does the port need to be exposed in the docker file to get this working? Could you please help me? I can not continue without using spider_man. Thanks, Vojta |
From: Vojtěch P. <kr...@gm...> - 2015-12-02 16:37:49
|
Hi, I have managed to get W3AF running in Docker under Windows. If I understand it right, in default Docker configuration, you mount /root/.w3af and /root/w3af-shared as volumes, which are connected with some directories located on the host file system. But when I run python w3af_console W3AF's configuration is saved in /home/w3af/.w3af Is this correct? Why is then there a mounted volume in /root/.w3af? when I mount the volume under /home/w3af/.w3af, I get segmentation fault when starting w3af_console. Thanks, Vojta Dne 14.11.2015 v 22:56 Carlos Perez napsal(a): > I though that containers in Windows 2016 are windows instances you manage with poershell remoting > > Sent from my iPhone > >> On Nov 14, 2015, at 4:48 PM, Vojtěch Polášek <kr...@gm...> wrote: >> >> HI, >> well, I couldn't get ssh to work, but I can connect through following >> command >> docker exec -ti <container_id> bash >> Thanks for that link. >> Vojta >> >> Dne 13.11.2015 v 13:14 Andres Riancho napsal(a): >>>> On Thu, Nov 12, 2015 at 6:16 PM, Vojtěch Polášek <kr...@gm...> wrote: >>>> Hi, >>>> it is Openssh running on Windows, so it should work. >>>> I am passing the .prv file as an argument, I hope it is right. >>> You shouldn't hope, use -v (verbose) to debug the ssh connection, this >>> will tell you if the ssh client is sending the key, etc. >>> >>>> Is there >>>> any other possibility to enter commands into the running container? >>> https://docs.docker.com/engine/reference/commandline/exec/ >>> >>>> Thanks, >>>> Vojta >>>> >>>> Dne 12.11.2015 v 16:05 Andres Riancho napsal(a): >>>>> Vojtěch, >>>>> >>>>>> On Thu, Nov 12, 2015 at 8:47 AM, Vojtěch Polášek <kr...@gm...> wrote: >>>>>> Greetings, >>>>>> still no luck. Is it important to mount w3af and w3af-shared volmues to >>>>>> be able to at least log in? >>>>> The volumes [0] AFAIK are not required. If you don't set them w3af >>>>> will create the /root/.w3af inside the docker file system. >>>>> >>>>> [0] https://github.com/andresriancho/w3af/blob/master/extras/docker/scripts/common/docker_helpers.py#L10-L11 >>>>> >>>>>> It would be greate if someone, who is more experienced with docker, >>>>>> could try this. I am running following commands in Powershell: >>>>>> docker-machine start mytest >>>>>> docker-machine env --shell=powershell mytest | Invoke-expression >>>>>> docker run -d andresriancho/w3af >>>>>> docker ps works correctly and displays running sshd daemon on port 22 >>>>> Looks good. >>>>> >>>>>> docker logs <container_id> does not show anything >>>>>> docker top ,container_id> shows only sshd running >>>>> Ok >>>>> >>>>>> When I try to run command posted in the previous mail, still receiving >>>>>> password prompt and w3af as a password does not work. >>>>>> Any ideas? >>>>> Yes, I already asked: Are you sure your SSH client expects the private >>>>> key to be set using -i ? >>>>> >>>>>> Thank you very much, >>>>>> Vojta >>>>>> >>>>>> Dne 2.11.2015 v 21:34 Andres Riancho napsal(a): >>>>>>> I've never done that in Windows, but it should work. You should try to >>>>>>> follow the same steps which are outlined for Linux here [0]. I suspect >>>>>>> you already did most of those since you found the ssh private key. >>>>>>> It's strange that the docker image is asking you for a password if >>>>>>> you're providing a SSH key; maybe -i is not the right flag in your ssh >>>>>>> client? >>>>>>> >>>>>>> [0] https://github.com/andresriancho/w3af/blob/master/extras/docker/scripts/w3af_console_docker >>>>>>> >>>>>>>> On Mon, Nov 2, 2015 at 2:28 PM, Vojtěch Polášek <kr...@gm...> wrote: >>>>>>>> Hi, >>>>>>>> does anyone here have experience running W3AF within Docker on Windows. >>>>>>>> I installed docker, downloaded W3AF and ran it, but I had a problem >>>>>>>> while connecting through ssh. Within w3af/extras/docker/scripts/common I >>>>>>>> ran: >>>>>>>> ssh -i w3af-docker.prv -t -t -oStrictHostKeyChecking=no ro...@xx... >>>>>>>> where xxx.xxx.xxx.xxx was the IP address of my docker machine running. >>>>>>>> I connected to the server and tried password w3af, but no success. >>>>>>>> Has anything changed? >>>>>>>> Thanks, >>>>>>>> Vojta >>>>>>>> >>>>>>>> >>>>>>>> ------------------------------------------------------------------------------ >>>>>>>> _______________________________________________ >>>>>>>> W3af-users mailing list >>>>>>>> W3a...@li... >>>>>>>> https://lists.sourceforge.net/lists/listinfo/w3af-users >>>>>> ------------------------------------------------------------------------------ >>>>>> _______________________________________________ >>>>>> W3af-users mailing list >>>>>> W3a...@li... >>>>>> https://lists.sourceforge.net/lists/listinfo/w3af-users >>>> ------------------------------------------------------------------------------ >>>> _______________________________________________ >>>> W3af-users mailing list >>>> W3a...@li... >>>> https://lists.sourceforge.net/lists/listinfo/w3af-users >> >> ------------------------------------------------------------------------------ >> _______________________________________________ >> W3af-users mailing list >> W3a...@li... >> https://lists.sourceforge.net/lists/listinfo/w3af-users |
From: Vojtěch P. <kr...@gm...> - 2015-12-02 09:05:41
|
Greetings, thanks for resources. But why do you think that Webgoat is not a good web app for testing W3AF? Do you think that it contains too much vulnerabilities, which need manual investigation? Thanks, Vojta Dne 1.12.2015 v 17:50 Matt Tesauro napsal(a): > Vojtech, > > I'd suggest you look at this project: > https://www.owasp.org/index.php/OWASP_Vulnerable_Web_Applications_Directory_Project > > In the "Off-line" tab, there's a list of apps and the technology used > to create then. > > For instance, Bodgeit Store is a Java based vulnerable app: > https://github.com/psiinon/bodgeit > > Best of luck! > > -- > -- Matt Tesauro > OWASP AppSec Pipeline Lead > https://www.owasp.org/index.php/OWASP_AppSec_Pipeline > OWASP WTE Project Lead > _https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project_ > http://AppSecLive.org - Community and Download site > > > On Tue, Dec 1, 2015 at 7:42 AM, Vojtěch Polášek <kr...@gm... > <mailto:kr...@gm...>> wrote: > > Hi, > I would like to run W3AF against a commercial web application > which uses > similar technologies as Webgoat. Do you think that applications, which > you mentioned, will be able to provide some baseline for comparing of > results? > I need to find if W3AF can correctly detect vulnerabilities in > deliberately vulnerable applications before running it against the > commercial application. > Vulnerable application should be as close as possible to the > commercial > one in terms of used technologies. > Thank you, > Vojtěch Polášek > > > Dne 1.12.2015 v 14:19 Andres Riancho napsal(a): > > webgoat is not usually a good target for testing scanners. I would > > recommend other applications such as: > > * http://testphp.acunetix.com/ > > * https://github.com/andresriancho/django-moth > > > > On Mon, Nov 30, 2015 at 3:41 PM, Vojtěch Polášek > <kr...@gm... <mailto:kr...@gm...>> wrote: > >> Greetings, > >> thanks for reply, i will try it out. > >> To be exact, I am running W3Af against Owasp Webgoat, which > runs on Tomcat. > >> Best regards, > >> Vojta > >> > >> Dne 30.11.2015 v 18:54 Andres Riancho napsal(a): > >>> Vojtěch, > >>> > >>> Questions are welcome :) > >>> > >>> I assume you wanted to say JavaScript instead of Java, if > JS is > >>> heavily used, then yes the web_spider is "almost useless". > >>> > >>> Well, the scan of the target URL can't be prevented, but > if you > >>> set the URL to http://target.com/ and disable web_spider, then > w3af > >>> won't have any parameters to find vulnerabilities in and the > target is > >>> "ignored" (most likely, haven't tested it). > >>> > >>> Regards, > >>> > >>> On Mon, Nov 30, 2015 at 2:48 PM, Vojtěch Polášek > <kr...@gm... <mailto:kr...@gm...>> wrote: > >>>> Greetings, > >>>> my name is Vojtěch Polášek and I am a blind IT student from > Czech Republic. > >>>> As a part of my bachelor thesis, I am researching some tools for > >>>> security analysis of web applications. One of those tools is > W3AF, so > >>>> expect some questions in near time :-) > >>>> I need to perform analysis of Java application, where > web_spider is > >>>> useless. Therefore I use spider_man plugin. My question is; > would it be > >>>> possible to prevent initial scan of the URL set as target? > >>>> Because it does not make much sense, as all needed input is > facilitated > >>>> through spider_man. > >>>> Thank you for your response and best regards, > >>>> Vojtěch Polášek > >>>> > >>>> > ------------------------------------------------------------------------------ > >>>> Go from Idea to Many App Stores Faster with Intel(R) XDK > >>>> Give your users amazing mobile app experiences with Intel(R) XDK. > >>>> Use one codebase in this all-in-one HTML5 development > environment. > >>>> Design, debug & build mobile apps & 2D/3D high-impact games > for multiple OSs. > >>>> http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 > >>>> _______________________________________________ > >>>> W3af-users mailing list > >>>> W3a...@li... > <mailto:W3a...@li...> > >>>> https://lists.sourceforge.net/lists/listinfo/w3af-users > >>> > >> > >> > ------------------------------------------------------------------------------ > >> Go from Idea to Many App Stores Faster with Intel(R) XDK > >> Give your users amazing mobile app experiences with Intel(R) XDK. > >> Use one codebase in this all-in-one HTML5 development environment. > >> Design, debug & build mobile apps & 2D/3D high-impact games for > multiple OSs. > >> http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 > >> _______________________________________________ > >> W3af-users mailing list > >> W3a...@li... > <mailto:W3a...@li...> > >> https://lists.sourceforge.net/lists/listinfo/w3af-users > > > > > > > ------------------------------------------------------------------------------ > Go from Idea to Many App Stores Faster with Intel(R) XDK > Give your users amazing mobile app experiences with Intel(R) XDK. > Use one codebase in this all-in-one HTML5 development environment. > Design, debug & build mobile apps & 2D/3D high-impact games for > multiple OSs. > http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 > _______________________________________________ > W3af-users mailing list > W3a...@li... > <mailto:W3a...@li...> > https://lists.sourceforge.net/lists/listinfo/w3af-users > > |
From: Matt T. <mte...@gm...> - 2015-12-01 16:50:32
|
Vojtech, I'd suggest you look at this project: https://www.owasp.org/index.php/OWASP_Vulnerable_Web_Applications_Directory_Project In the "Off-line" tab, there's a list of apps and the technology used to create then. For instance, Bodgeit Store is a Java based vulnerable app: https://github.com/psiinon/bodgeit Best of luck! -- -- Matt Tesauro OWASP AppSec Pipeline Lead https://www.owasp.org/index.php/OWASP_AppSec_Pipeline OWASP WTE Project Lead *https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project <https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project>* http://AppSecLive.org - Community and Download site On Tue, Dec 1, 2015 at 7:42 AM, Vojtěch Polášek <kr...@gm...> wrote: > Hi, > I would like to run W3AF against a commercial web application which uses > similar technologies as Webgoat. Do you think that applications, which > you mentioned, will be able to provide some baseline for comparing of > results? > I need to find if W3AF can correctly detect vulnerabilities in > deliberately vulnerable applications before running it against the > commercial application. > Vulnerable application should be as close as possible to the commercial > one in terms of used technologies. > Thank you, > Vojtěch Polášek > > > Dne 1.12.2015 v 14:19 Andres Riancho napsal(a): > > webgoat is not usually a good target for testing scanners. I would > > recommend other applications such as: > > * http://testphp.acunetix.com/ > > * https://github.com/andresriancho/django-moth > > > > On Mon, Nov 30, 2015 at 3:41 PM, Vojtěch Polášek <kr...@gm...> > wrote: > >> Greetings, > >> thanks for reply, i will try it out. > >> To be exact, I am running W3Af against Owasp Webgoat, which runs on > Tomcat. > >> Best regards, > >> Vojta > >> > >> Dne 30.11.2015 v 18:54 Andres Riancho napsal(a): > >>> Vojtěch, > >>> > >>> Questions are welcome :) > >>> > >>> I assume you wanted to say JavaScript instead of Java, if JS is > >>> heavily used, then yes the web_spider is "almost useless". > >>> > >>> Well, the scan of the target URL can't be prevented, but if you > >>> set the URL to http://target.com/ and disable web_spider, then w3af > >>> won't have any parameters to find vulnerabilities in and the target is > >>> "ignored" (most likely, haven't tested it). > >>> > >>> Regards, > >>> > >>> On Mon, Nov 30, 2015 at 2:48 PM, Vojtěch Polášek <kr...@gm...> > wrote: > >>>> Greetings, > >>>> my name is Vojtěch Polášek and I am a blind IT student from Czech > Republic. > >>>> As a part of my bachelor thesis, I am researching some tools for > >>>> security analysis of web applications. One of those tools is W3AF, so > >>>> expect some questions in near time :-) > >>>> I need to perform analysis of Java application, where web_spider is > >>>> useless. Therefore I use spider_man plugin. My question is; would it > be > >>>> possible to prevent initial scan of the URL set as target? > >>>> Because it does not make much sense, as all needed input is > facilitated > >>>> through spider_man. > >>>> Thank you for your response and best regards, > >>>> Vojtěch Polášek > >>>> > >>>> > ------------------------------------------------------------------------------ > >>>> Go from Idea to Many App Stores Faster with Intel(R) XDK > >>>> Give your users amazing mobile app experiences with Intel(R) XDK. > >>>> Use one codebase in this all-in-one HTML5 development environment. > >>>> Design, debug & build mobile apps & 2D/3D high-impact games for > multiple OSs. > >>>> http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 > >>>> _______________________________________________ > >>>> W3af-users mailing list > >>>> W3a...@li... > >>>> https://lists.sourceforge.net/lists/listinfo/w3af-users > >>> > >> > >> > ------------------------------------------------------------------------------ > >> Go from Idea to Many App Stores Faster with Intel(R) XDK > >> Give your users amazing mobile app experiences with Intel(R) XDK. > >> Use one codebase in this all-in-one HTML5 development environment. > >> Design, debug & build mobile apps & 2D/3D high-impact games for > multiple OSs. > >> http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 > >> _______________________________________________ > >> W3af-users mailing list > >> W3a...@li... > >> https://lists.sourceforge.net/lists/listinfo/w3af-users > > > > > > > > ------------------------------------------------------------------------------ > Go from Idea to Many App Stores Faster with Intel(R) XDK > Give your users amazing mobile app experiences with Intel(R) XDK. > Use one codebase in this all-in-one HTML5 development environment. > Design, debug & build mobile apps & 2D/3D high-impact games for multiple > OSs. > http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users > |
From: Vojtěch P. <kr...@gm...> - 2015-12-01 13:42:15
|
Hi, I would like to run W3AF against a commercial web application which uses similar technologies as Webgoat. Do you think that applications, which you mentioned, will be able to provide some baseline for comparing of results? I need to find if W3AF can correctly detect vulnerabilities in deliberately vulnerable applications before running it against the commercial application. Vulnerable application should be as close as possible to the commercial one in terms of used technologies. Thank you, Vojtěch Polášek Dne 1.12.2015 v 14:19 Andres Riancho napsal(a): > webgoat is not usually a good target for testing scanners. I would > recommend other applications such as: > * http://testphp.acunetix.com/ > * https://github.com/andresriancho/django-moth > > On Mon, Nov 30, 2015 at 3:41 PM, Vojtěch Polášek <kr...@gm...> wrote: >> Greetings, >> thanks for reply, i will try it out. >> To be exact, I am running W3Af against Owasp Webgoat, which runs on Tomcat. >> Best regards, >> Vojta >> >> Dne 30.11.2015 v 18:54 Andres Riancho napsal(a): >>> Vojtěch, >>> >>> Questions are welcome :) >>> >>> I assume you wanted to say JavaScript instead of Java, if JS is >>> heavily used, then yes the web_spider is "almost useless". >>> >>> Well, the scan of the target URL can't be prevented, but if you >>> set the URL to http://target.com/ and disable web_spider, then w3af >>> won't have any parameters to find vulnerabilities in and the target is >>> "ignored" (most likely, haven't tested it). >>> >>> Regards, >>> >>> On Mon, Nov 30, 2015 at 2:48 PM, Vojtěch Polášek <kr...@gm...> wrote: >>>> Greetings, >>>> my name is Vojtěch Polášek and I am a blind IT student from Czech Republic. >>>> As a part of my bachelor thesis, I am researching some tools for >>>> security analysis of web applications. One of those tools is W3AF, so >>>> expect some questions in near time :-) >>>> I need to perform analysis of Java application, where web_spider is >>>> useless. Therefore I use spider_man plugin. My question is; would it be >>>> possible to prevent initial scan of the URL set as target? >>>> Because it does not make much sense, as all needed input is facilitated >>>> through spider_man. >>>> Thank you for your response and best regards, >>>> Vojtěch Polášek >>>> >>>> ------------------------------------------------------------------------------ >>>> Go from Idea to Many App Stores Faster with Intel(R) XDK >>>> Give your users amazing mobile app experiences with Intel(R) XDK. >>>> Use one codebase in this all-in-one HTML5 development environment. >>>> Design, debug & build mobile apps & 2D/3D high-impact games for multiple OSs. >>>> http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 >>>> _______________________________________________ >>>> W3af-users mailing list >>>> W3a...@li... >>>> https://lists.sourceforge.net/lists/listinfo/w3af-users >>> >> >> ------------------------------------------------------------------------------ >> Go from Idea to Many App Stores Faster with Intel(R) XDK >> Give your users amazing mobile app experiences with Intel(R) XDK. >> Use one codebase in this all-in-one HTML5 development environment. >> Design, debug & build mobile apps & 2D/3D high-impact games for multiple OSs. >> http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 >> _______________________________________________ >> W3af-users mailing list >> W3a...@li... >> https://lists.sourceforge.net/lists/listinfo/w3af-users > > |
From: Andres R. <and...@gm...> - 2015-12-01 13:19:49
|
webgoat is not usually a good target for testing scanners. I would recommend other applications such as: * http://testphp.acunetix.com/ * https://github.com/andresriancho/django-moth On Mon, Nov 30, 2015 at 3:41 PM, Vojtěch Polášek <kr...@gm...> wrote: > Greetings, > thanks for reply, i will try it out. > To be exact, I am running W3Af against Owasp Webgoat, which runs on Tomcat. > Best regards, > Vojta > > Dne 30.11.2015 v 18:54 Andres Riancho napsal(a): >> Vojtěch, >> >> Questions are welcome :) >> >> I assume you wanted to say JavaScript instead of Java, if JS is >> heavily used, then yes the web_spider is "almost useless". >> >> Well, the scan of the target URL can't be prevented, but if you >> set the URL to http://target.com/ and disable web_spider, then w3af >> won't have any parameters to find vulnerabilities in and the target is >> "ignored" (most likely, haven't tested it). >> >> Regards, >> >> On Mon, Nov 30, 2015 at 2:48 PM, Vojtěch Polášek <kr...@gm...> wrote: >>> Greetings, >>> my name is Vojtěch Polášek and I am a blind IT student from Czech Republic. >>> As a part of my bachelor thesis, I am researching some tools for >>> security analysis of web applications. One of those tools is W3AF, so >>> expect some questions in near time :-) >>> I need to perform analysis of Java application, where web_spider is >>> useless. Therefore I use spider_man plugin. My question is; would it be >>> possible to prevent initial scan of the URL set as target? >>> Because it does not make much sense, as all needed input is facilitated >>> through spider_man. >>> Thank you for your response and best regards, >>> Vojtěch Polášek >>> >>> ------------------------------------------------------------------------------ >>> Go from Idea to Many App Stores Faster with Intel(R) XDK >>> Give your users amazing mobile app experiences with Intel(R) XDK. >>> Use one codebase in this all-in-one HTML5 development environment. >>> Design, debug & build mobile apps & 2D/3D high-impact games for multiple OSs. >>> http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 >>> _______________________________________________ >>> W3af-users mailing list >>> W3a...@li... >>> https://lists.sourceforge.net/lists/listinfo/w3af-users >> >> > > > ------------------------------------------------------------------------------ > Go from Idea to Many App Stores Faster with Intel(R) XDK > Give your users amazing mobile app experiences with Intel(R) XDK. > Use one codebase in this all-in-one HTML5 development environment. > Design, debug & build mobile apps & 2D/3D high-impact games for multiple OSs. > http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Vojtěch P. <kr...@gm...> - 2015-11-30 18:41:33
|
Greetings, thanks for reply, i will try it out. To be exact, I am running W3Af against Owasp Webgoat, which runs on Tomcat. Best regards, Vojta Dne 30.11.2015 v 18:54 Andres Riancho napsal(a): > Vojtěch, > > Questions are welcome :) > > I assume you wanted to say JavaScript instead of Java, if JS is > heavily used, then yes the web_spider is "almost useless". > > Well, the scan of the target URL can't be prevented, but if you > set the URL to http://target.com/ and disable web_spider, then w3af > won't have any parameters to find vulnerabilities in and the target is > "ignored" (most likely, haven't tested it). > > Regards, > > On Mon, Nov 30, 2015 at 2:48 PM, Vojtěch Polášek <kr...@gm...> wrote: >> Greetings, >> my name is Vojtěch Polášek and I am a blind IT student from Czech Republic. >> As a part of my bachelor thesis, I am researching some tools for >> security analysis of web applications. One of those tools is W3AF, so >> expect some questions in near time :-) >> I need to perform analysis of Java application, where web_spider is >> useless. Therefore I use spider_man plugin. My question is; would it be >> possible to prevent initial scan of the URL set as target? >> Because it does not make much sense, as all needed input is facilitated >> through spider_man. >> Thank you for your response and best regards, >> Vojtěch Polášek >> >> ------------------------------------------------------------------------------ >> Go from Idea to Many App Stores Faster with Intel(R) XDK >> Give your users amazing mobile app experiences with Intel(R) XDK. >> Use one codebase in this all-in-one HTML5 development environment. >> Design, debug & build mobile apps & 2D/3D high-impact games for multiple OSs. >> http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 >> _______________________________________________ >> W3af-users mailing list >> W3a...@li... >> https://lists.sourceforge.net/lists/listinfo/w3af-users > > |
From: Andres R. <and...@gm...> - 2015-11-30 17:54:42
|
Vojtěch, Questions are welcome :) I assume you wanted to say JavaScript instead of Java, if JS is heavily used, then yes the web_spider is "almost useless". Well, the scan of the target URL can't be prevented, but if you set the URL to http://target.com/ and disable web_spider, then w3af won't have any parameters to find vulnerabilities in and the target is "ignored" (most likely, haven't tested it). Regards, On Mon, Nov 30, 2015 at 2:48 PM, Vojtěch Polášek <kr...@gm...> wrote: > Greetings, > my name is Vojtěch Polášek and I am a blind IT student from Czech Republic. > As a part of my bachelor thesis, I am researching some tools for > security analysis of web applications. One of those tools is W3AF, so > expect some questions in near time :-) > I need to perform analysis of Java application, where web_spider is > useless. Therefore I use spider_man plugin. My question is; would it be > possible to prevent initial scan of the URL set as target? > Because it does not make much sense, as all needed input is facilitated > through spider_man. > Thank you for your response and best regards, > Vojtěch Polášek > > ------------------------------------------------------------------------------ > Go from Idea to Many App Stores Faster with Intel(R) XDK > Give your users amazing mobile app experiences with Intel(R) XDK. > Use one codebase in this all-in-one HTML5 development environment. > Design, debug & build mobile apps & 2D/3D high-impact games for multiple OSs. > http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 |
From: Vojtěch P. <kr...@gm...> - 2015-11-30 17:48:44
|
Greetings, my name is Vojtěch Polášek and I am a blind IT student from Czech Republic. As a part of my bachelor thesis, I am researching some tools for security analysis of web applications. One of those tools is W3AF, so expect some questions in near time :-) I need to perform analysis of Java application, where web_spider is useless. Therefore I use spider_man plugin. My question is; would it be possible to prevent initial scan of the URL set as target? Because it does not make much sense, as all needed input is facilitated through spider_man. Thank you for your response and best regards, Vojtěch Polášek |
From: Carlos P. <cpe...@gm...> - 2015-11-14 21:56:34
|
I though that containers in Windows 2016 are windows instances you manage with poershell remoting Sent from my iPhone > On Nov 14, 2015, at 4:48 PM, Vojtěch Polášek <kr...@gm...> wrote: > > HI, > well, I couldn't get ssh to work, but I can connect through following > command > docker exec -ti <container_id> bash > Thanks for that link. > Vojta > > Dne 13.11.2015 v 13:14 Andres Riancho napsal(a): >>> On Thu, Nov 12, 2015 at 6:16 PM, Vojtěch Polášek <kr...@gm...> wrote: >>> Hi, >>> it is Openssh running on Windows, so it should work. >>> I am passing the .prv file as an argument, I hope it is right. >> You shouldn't hope, use -v (verbose) to debug the ssh connection, this >> will tell you if the ssh client is sending the key, etc. >> >>> Is there >>> any other possibility to enter commands into the running container? >> https://docs.docker.com/engine/reference/commandline/exec/ >> >>> Thanks, >>> Vojta >>> >>> Dne 12.11.2015 v 16:05 Andres Riancho napsal(a): >>>> Vojtěch, >>>> >>>>> On Thu, Nov 12, 2015 at 8:47 AM, Vojtěch Polášek <kr...@gm...> wrote: >>>>> Greetings, >>>>> still no luck. Is it important to mount w3af and w3af-shared volmues to >>>>> be able to at least log in? >>>> The volumes [0] AFAIK are not required. If you don't set them w3af >>>> will create the /root/.w3af inside the docker file system. >>>> >>>> [0] https://github.com/andresriancho/w3af/blob/master/extras/docker/scripts/common/docker_helpers.py#L10-L11 >>>> >>>>> It would be greate if someone, who is more experienced with docker, >>>>> could try this. I am running following commands in Powershell: >>>>> docker-machine start mytest >>>>> docker-machine env --shell=powershell mytest | Invoke-expression >>>>> docker run -d andresriancho/w3af >>>>> docker ps works correctly and displays running sshd daemon on port 22 >>>> Looks good. >>>> >>>>> docker logs <container_id> does not show anything >>>>> docker top ,container_id> shows only sshd running >>>> Ok >>>> >>>>> When I try to run command posted in the previous mail, still receiving >>>>> password prompt and w3af as a password does not work. >>>>> Any ideas? >>>> Yes, I already asked: Are you sure your SSH client expects the private >>>> key to be set using -i ? >>>> >>>>> Thank you very much, >>>>> Vojta >>>>> >>>>> Dne 2.11.2015 v 21:34 Andres Riancho napsal(a): >>>>>> I've never done that in Windows, but it should work. You should try to >>>>>> follow the same steps which are outlined for Linux here [0]. I suspect >>>>>> you already did most of those since you found the ssh private key. >>>>>> It's strange that the docker image is asking you for a password if >>>>>> you're providing a SSH key; maybe -i is not the right flag in your ssh >>>>>> client? >>>>>> >>>>>> [0] https://github.com/andresriancho/w3af/blob/master/extras/docker/scripts/w3af_console_docker >>>>>> >>>>>>> On Mon, Nov 2, 2015 at 2:28 PM, Vojtěch Polášek <kr...@gm...> wrote: >>>>>>> Hi, >>>>>>> does anyone here have experience running W3AF within Docker on Windows. >>>>>>> I installed docker, downloaded W3AF and ran it, but I had a problem >>>>>>> while connecting through ssh. Within w3af/extras/docker/scripts/common I >>>>>>> ran: >>>>>>> ssh -i w3af-docker.prv -t -t -oStrictHostKeyChecking=no ro...@xx... >>>>>>> where xxx.xxx.xxx.xxx was the IP address of my docker machine running. >>>>>>> I connected to the server and tried password w3af, but no success. >>>>>>> Has anything changed? >>>>>>> Thanks, >>>>>>> Vojta >>>>>>> >>>>>>> >>>>>>> ------------------------------------------------------------------------------ >>>>>>> _______________________________________________ >>>>>>> W3af-users mailing list >>>>>>> W3a...@li... >>>>>>> https://lists.sourceforge.net/lists/listinfo/w3af-users >>>>> ------------------------------------------------------------------------------ >>>>> _______________________________________________ >>>>> W3af-users mailing list >>>>> W3a...@li... >>>>> https://lists.sourceforge.net/lists/listinfo/w3af-users >>> >>> ------------------------------------------------------------------------------ >>> _______________________________________________ >>> W3af-users mailing list >>> W3a...@li... >>> https://lists.sourceforge.net/lists/listinfo/w3af-users > > > ------------------------------------------------------------------------------ > _______________________________________________ > W3af-users mailing list > W3a...@li... > https://lists.sourceforge.net/lists/listinfo/w3af-users |
From: Vojtěch P. <kr...@gm...> - 2015-11-14 20:48:33
|
HI, well, I couldn't get ssh to work, but I can connect through following command docker exec -ti <container_id> bash Thanks for that link. Vojta Dne 13.11.2015 v 13:14 Andres Riancho napsal(a): > On Thu, Nov 12, 2015 at 6:16 PM, Vojtěch Polášek <kr...@gm...> wrote: >> Hi, >> it is Openssh running on Windows, so it should work. >> I am passing the .prv file as an argument, I hope it is right. > You shouldn't hope, use -v (verbose) to debug the ssh connection, this > will tell you if the ssh client is sending the key, etc. > >> Is there >> any other possibility to enter commands into the running container? > https://docs.docker.com/engine/reference/commandline/exec/ > >> Thanks, >> Vojta >> >> Dne 12.11.2015 v 16:05 Andres Riancho napsal(a): >>> Vojtěch, >>> >>> On Thu, Nov 12, 2015 at 8:47 AM, Vojtěch Polášek <kr...@gm...> wrote: >>>> Greetings, >>>> still no luck. Is it important to mount w3af and w3af-shared volmues to >>>> be able to at least log in? >>> The volumes [0] AFAIK are not required. If you don't set them w3af >>> will create the /root/.w3af inside the docker file system. >>> >>> [0] https://github.com/andresriancho/w3af/blob/master/extras/docker/scripts/common/docker_helpers.py#L10-L11 >>> >>>> It would be greate if someone, who is more experienced with docker, >>>> could try this. I am running following commands in Powershell: >>>> docker-machine start mytest >>>> docker-machine env --shell=powershell mytest | Invoke-expression >>>> docker run -d andresriancho/w3af >>>> docker ps works correctly and displays running sshd daemon on port 22 >>> Looks good. >>> >>>> docker logs <container_id> does not show anything >>>> docker top ,container_id> shows only sshd running >>> Ok >>> >>>> When I try to run command posted in the previous mail, still receiving >>>> password prompt and w3af as a password does not work. >>>> Any ideas? >>> Yes, I already asked: Are you sure your SSH client expects the private >>> key to be set using -i ? >>> >>>> Thank you very much, >>>> Vojta >>>> >>>> Dne 2.11.2015 v 21:34 Andres Riancho napsal(a): >>>>> I've never done that in Windows, but it should work. You should try to >>>>> follow the same steps which are outlined for Linux here [0]. I suspect >>>>> you already did most of those since you found the ssh private key. >>>>> It's strange that the docker image is asking you for a password if >>>>> you're providing a SSH key; maybe -i is not the right flag in your ssh >>>>> client? >>>>> >>>>> [0] https://github.com/andresriancho/w3af/blob/master/extras/docker/scripts/w3af_console_docker >>>>> >>>>> On Mon, Nov 2, 2015 at 2:28 PM, Vojtěch Polášek <kr...@gm...> wrote: >>>>>> Hi, >>>>>> does anyone here have experience running W3AF within Docker on Windows. >>>>>> I installed docker, downloaded W3AF and ran it, but I had a problem >>>>>> while connecting through ssh. Within w3af/extras/docker/scripts/common I >>>>>> ran: >>>>>> ssh -i w3af-docker.prv -t -t -oStrictHostKeyChecking=no ro...@xx... >>>>>> where xxx.xxx.xxx.xxx was the IP address of my docker machine running. >>>>>> I connected to the server and tried password w3af, but no success. >>>>>> Has anything changed? >>>>>> Thanks, >>>>>> Vojta >>>>>> >>>>>> >>>>>> ------------------------------------------------------------------------------ >>>>>> _______________________________________________ >>>>>> W3af-users mailing list >>>>>> W3a...@li... >>>>>> https://lists.sourceforge.net/lists/listinfo/w3af-users >>>> ------------------------------------------------------------------------------ >>>> _______________________________________________ >>>> W3af-users mailing list >>>> W3a...@li... >>>> https://lists.sourceforge.net/lists/listinfo/w3af-users >>> >> >> ------------------------------------------------------------------------------ >> _______________________________________________ >> W3af-users mailing list >> W3a...@li... >> https://lists.sourceforge.net/lists/listinfo/w3af-users > > |