|
Title: Mapping the Application Post by: Seen on November 05, 2012, 04:06:24 PM I typically use Burp Spider and the BuiltWith Chrome Extension to map websites I'm testing. Does anyone use anything else? I'm always looking for new things to play around with.
Title: Re: Mapping the Application Post by: MaXe on November 05, 2012, 05:06:07 PM I use Burp (the spider) as well, but Burp has several features, i.e. Discover Content, and even the Intruder, can be used to launch the wordlists DirBuster has. The OWASP DirBuster is however, quite fast most of the time for discovering well known content.
Nikto, is another web scanner that's good at finding common vulnerabilities, misconfigurations and even some content. (DirBuster is a lot more efficient.) Title: Re: Mapping the Application Post by: Dark_Knight on November 05, 2012, 09:01:12 PM @MaXe what settings do you typically use for Dirbuster? Are you also using the raft wordlist
Wordlist: http://code.google.com/p/raft/downloads/detail?name=raft-wordlists-20110803.7z Title: Re: Mapping the Application Post by: Seen on November 06, 2012, 01:29:04 AM I've only used Dirbuster once, I'll have to play around with it some more.
How accurate is nikto? I've used it on 2 different servers and got a lot of false positives (PHP related issues on sites not running PHP!) Title: Re: Mapping the Application Post by: ambient on November 06, 2012, 11:11:39 AM For me, I am working with
1. BurpSuite for web application crawling and mapping. 2. DirBuster for directory or file name enumeration. 3. HTTrack for saving some web contents in order to extract interesting metadata. 4. nikto for checking web server configuration 5. w3af for quick web application scanning These activities pave a way to the next step. Title: Re: Mapping the Application Post by: Dark_Knight on November 06, 2012, 01:13:41 PM For me, I am working with ......have you had issues doing authenticated scans with w3af?1. BurpSuite for web application crawling and mapping. 2. DirBuster for directory or file name enumeration. 3. HTTrack for saving some web contents in order to extract interesting metadata. 4. nikto for checking web server configuration 5. w3af for quick web application scanning These activities pave a way to the next step. Title: Re: Mapping the Application Post by: ambient on November 07, 2012, 01:49:43 AM Quote ......have you had issues doing authenticated scans with w3af? What does it mean? If you meant the problem, my w3af often crashed during the scan.
Powered by SMF 1.1.18 |
SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com |