Re: [W3af-users] most painless way of installing w3af

2011-01-02 Thread Brad Causey
Thanks Drexx!! Also, for new w3af users, they need to "sudo apt-get install python-lxml" if they are on debian. -Brad Causey CISSP, MCSE, C|EH, CIFI, CGSP http://www.owasp.org -- "Si vis pacem, para bellum" -- On Sun, Jan 2, 2011 at 4:04 AM, Drexx Laggui [personal] wrot

Re: [W3af-users] W3AF XML Output

2010-12-09 Thread Brad Causey
her works for me! > > Cheers, > Adrien > > -- > ___ > W3af-users mailing list > W3af-users@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/w3af-users > -- Sent from my mobile device -Brad Causey CISSP, MCSE,

[W3af-users] custom profile

2010-11-17 Thread Brad Causey
How can this be exported from W3AF? I am currently creating a standardized profile for use across a whole dept of security analysts. -Brad Causey CISSP, MCSE, C|EH, CIFI, CGSP http://www.owasp.org -- "Si vis pacem, para b

Re: [W3af-users] W3AF XML Output

2010-11-17 Thread Brad Causey
Agree. DTD will offer the most flexibility, IMO. I'll work on a parser for the XML output. -Brad Causey CISSP, MCSE, C|EH, CIFI, CGSP http://www.owasp.org -- "Si vis pacem, para bellum" -- On Wed, Nov 17, 2010 at 6:41 AM, Adrien de Beaupre wrote: > Hi Andrés, > >

Re: [W3af-users] W3AF XML Output

2010-11-16 Thread Brad Causey
ng and rewriting code and more time creating great > experiences on the web. Be a part of the beta today > http://p.sf.net/sfu/msIE9-sfdev2dev > ___ > W3af-users mailing list > W3af-users@lists.sourceforge.net > https://lists.sourceforge.net/list

Re: [W3af-users] error in 1.0 rc3

2010-03-31 Thread Brad Causey
Sounds good, thanks for the quick feedback! I'll keep an ear to the ground for the update to 2.6. -Brad Causey CISSP, MCSE, C|EH, CIFI, CGSP http://www.owasp.org -- "Si vis pacem, para bellum" -- On Wed, Mar 31, 2010 at 8:25 AM, Andres Riancho wrote: > Ahh, and w3af w

[W3af-users] error in 1.0 rc3

2010-03-31 Thread Brad Causey
ng plugin "'+ moduleName + '". Exception: ' + str(e) ) w3afException: Error while loading plugin "plugins.discovery.fingerGoogle". Exception: name 'Types' is not defined -Brad Causey CISSP, MCSE, C|EH, CIFI, CGSP http://www.owasp.org -- "Si

Re: [W3af-users] Light Topic

2009-10-05 Thread Brad Causey
ometimes I lose. =) This is not related to using the W3AF Tool, but a generalization of reviews in general. -Brad Causey CISSP, MCSE, C|EH, CIFI, CGSP http://www.owasp.org -- Never underestimate the time, expense, and effort an opponent will expend to break a code. (Robert Morris) -- On Mon, Oct

Re: [W3af-users] Errors after svn install

2008-12-11 Thread Brad Causey
traef06, I would also suggest wiping out any previous attempts at getting W3AF to work pre-python 2.4, just to eliminate any residual issues. Just delete the W3AF dir and start over. If that doesn't work, please send each command, step, etc, along with any error output so we can get a good idea

Re: [W3af-users] Errors after svn install

2008-12-11 Thread Brad Causey
Ok, If this is your first time running it, read the install instructions and make sure that you have all of the dependencies met. If you wish to use a previous revision, Use a command like the following, from the w3af folder: /w3af$ 'svn update -r 2160' where the 2160 is the revision you wish

Re: [W3af-users] Objectives

2008-11-11 Thread Brad Causey
Andres, > Something that I forgot to mention, and is one of the most important > features (it's simple, but VERY powerfull) that I'm going to code > whenever I've got some minutes is a "report false positive" / "report > false negative" button in the GUI, just below the vulnerability > descripti

Re: [W3af-users] Objectives

2008-11-11 Thread Brad Causey
Andres, > > The main goal is to be able to gather the same usefulness from saved > > information as from viewing it in the UI. At this point, after you close > > w3af, you lose much the detail and linking between raw data and > > vulnerability identification. Here is the thread we discussed previ

Re: [W3af-users] Objectives

2008-11-11 Thread Brad Causey
Andres, Brad, > > 2008/11/10 Brad Causey <[EMAIL PROTECTED]>: > > Enable session saving from GUI? > > Saving the KB objects to disk, or "pause a scan" and resume it later? > (second option is way more complicated and impossible to code with my > short free

Re: [W3af-users] Objectives

2008-11-10 Thread Brad Causey
Enable session saving from GUI? 2008/11/10 Viktor Gazdag <[EMAIL PROTECTED]> > 2008/11/10 Andres Riancho <[EMAIL PROTECTED]> > >> List, >> >>This is a simple email that aims to set some objectives for the >> project near future, it's not definitive, you can contribute by adding >> or rem

Re: [W3af-users] Fwd: Saving W3AF GUI session

2008-10-28 Thread Brad Causey
>> Agreed. However, once you close out of W3AF, you loose that direct >> correlation. Ideally, one of the output plug ins would correlate that >> complete data set for later use. In one case, while testing, we had to >> leave the W3AF window open for days because we forgot to enable the >> text plu

Re: [W3af-users] Fwd: Saving W3AF GUI session

2008-10-28 Thread Brad Causey
Viktor, > In the Results->KB Browser, at the Request window you can see what data was > sent. Yo can copy paste this to the browser. w3af has also a manual request, > like a pure web browser. > Agreed. However, once you close out of W3AF, you loose that direct correlation. Ideally, one of the o

Re: [W3af-users] Saving W3AF GUI session

2008-10-28 Thread Brad Causey
2008/10/28 Viktor Gazdag <[EMAIL PROTECTED]>: > 2008/10/28 Brad Causey <[EMAIL PROTECTED]> >> >> I have done a good bit of research, but I can't find a way to save a >> GUI session to file? >> > > I think the urls are saved by default. I mean you

[W3af-users] Saving W3AF GUI session

2008-10-28 Thread Brad Causey
I have done a good bit of research, but I can't find a way to save a GUI session to file? -Brad Cauzey - This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based application