Acunetix WVS 8 Released Candidate Now Available!
releases

Acunetix Web Vulnerability Scanner Product Releases

docs & FAQs

Acunetix technical documentation and FAQ

news

Acunetix Company and Web Security news, & Press Releases

events

Acunetix Webinars, Events and Training around the world

web security zone

Everything you need to know about Web Security

Home » docs & FAQs

FAQ: Is it possible to crawl a site manually?

Submitted by on August 10, 2010 – 6:06 pmNo Comment

It is possible to manually crawl your website with Acunetix WVS using a web browser. Using the resultant — and manually crawled — links, it is then possible to build a website structure that will be targeted during the security scan.  This is useful for scanning specific web applications that cannot be automatically crawled due to some strange coding ambiguities. The following procedure offers a reliable workaround:

1. Configure the web browser


Configure your web browser of choice to proxy all the traffic through the Acunetix WVS HTTP Sniffer tool, as shown in the above screen shot.  Presuming that the web browser is running on the same machine where Acunetix WVS is installed, set the proxy server IP to 127.0.0.1 and the proxy server port to 8080.

2. Start the HTTP Sniffer and browse the website using the previously configured web browser.

HTTP Sniffer captured traffic

3. Once ready, stop the HTTP sniffer. Save captured data by selecting ‘Save Logs’ from the Actions drop down menu.

4. Import Logs to Crawler


In the Site Crawler node, click the ‘Build Structure from HTTP Sniffer log’ button (highlighted in the above screen shot) to import the captured data into the Site Crawler.

5. Save the crawler import results by selecting ‘Save Results’ from the Actions drop down menu.

6. Launch the Scan


Click on the New Scan button to launch the scan wizard.  In the first step of the Scan Wizard select the option ‘Scan using saved crawling results’ as highlighted in the above screen shot.  Proceed with completing the scan wizard to launch the automated scan against the manually browsed website.

Note: Only the links you’ve manually crawled will be automatically scanned.  Other pages in the website, even those linked from manually crawled pages will not be crawled or scanned.

Leave a comment!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.