Contents
ii
Acunetix Web Vulnerability Scanner
4.9
ANALYZING THE SCAN RESULTS
________________________________________________________________
50
4.9.1
Alerts Node _________________________________________________________________________
51
4.9.2
Site Structure Node __________________________________________________________________
53
4.10
SAVING THE SCAN RESULTS ___________________________________________________________________
54
4.11
GENERATING A REPORT FROM THE SCAN RESULTS
__________________________________________________
54
4.12
GOOGLE HACKING VULNERABILITIES _____________________________________________________________
55
5.
SITE CRAWLER TOOL _________________________________________________________________________
57
5.1
INTRODUCTION ____________________________________________________________________________
57
5.2
ANALYZING A WEBSITE STRUCTURE _____________________________________________________________
58
5.2.1
Starting the crawling process _________________________________________________________
58
5.2.2
Analyzing the information collected by the crawler ______________________________________
58
5.2.3
Info Tab ____________________________________________________________________________
58
5.2.4
Referrers Tab _______________________________________________________________________
59
5.2.5
HTTP Headers Tab ___________________________________________________________________
59
5.2.6
Inputs Tab __________________________________________________________________________
60
5.2.7
View Source Tab
____________________________________________________________________
60
5.2.8
View Page Tab ______________________________________________________________________
61
5.2.9
HTML Analysis Tab __________________________________________________________________
62
6.
TARGET FINDER TOOL ________________________________________________________________________
67
6.1
INTRODUCTION ____________________________________________________________________________
67
6.2
TO START A SCAN __________________________________________________________________________
67
7.
SUBDOMAIN SCANNER TOOL _________________________________________________________________
69
7.1
INTRODUCTION ____________________________________________________________________________
69
7.2
STARTING A SUBDOMAIN SCAN
________________________________________________________________
69
8.
HTTP SNIFFER TOOL __________________________________________________________________________
70
8.1
INTRODUCTION ____________________________________________________________________________
70
8.2
CONFIGURING THE HTTP SNIFFER ______________________________________________________________
71
8.3
ENABLING THE HTTP SNIFFER _________________________________________________________________
71
8.4
CREATING AN HTTP SNIFFER TRAP FILTER ________________________________________________________
72
8.5
ANALYZING And RESPONDING TO THE TRAPPED REQUESTS ____________________________________________
73
8.5.1
The Trap Form ______________________________________________________________________
74
8.6
EDITING AN HTTP REQUEST WITHOUT A TRAP _____________________________________________________
74
9.
AUTHENTICATION TESTER TOOL_______________________________________________________________
75
9.1
INTRODUCTION ____________________________________________________________________________
75
9.2
TESTING HTTP AUTHENTICATION_______________________________________________________________
75
9.2.1
What is HTTP Authentication? ________________________________________________________
75
9.2.2
Testing the Password Strength ________________________________________________________
76
9.3
TESTING HTML FORM AUTHENTICATION _________________________________________________________
76
9.3.1
What is HTML Forms Authentication?__________________________________________________
76
9.3.2
Testing Password Strength ___________________________________________________________
78
10.
HTTP EDITOR TOOL ________________________________________________________________________
80
10.1
INTRODUCTION ____________________________________________________________________________
80
10.2
EDITING A REQUEST _________________________________________________________________________
81
10.3
FIN-TUNING REQUESTS AND ANALYZING RESPONSES
________________________________________________
83
10.3.1
Response Headers and Response Data tabs_____________________________________________
84
10.3.2
Text Only Tab _______________________________________________________________________
84
10.3.3
View Page Tab ______________________________________________________________________
84
10.3.4
HTML Structure Analysis Tab
_________________________________________________________
85
11.
HTTP FUZZER TOOL ________________________________________________________________________
87
11.1
INTRODUCTION ____________________________________________________________________________
87