Re: [W3af-users] symfony plugin

2011-11-16 Thread Carlos Pantelides
Andres: >    Sorry for the very very late response, but I've been working a lot on other things No problem. In a few weeks I'll have the opportunity of testing w3af against some sites and generate some feedback. No need to ack   Carlos Pantelides - http://seguridad-agile.

Re: [W3af-users] symfony plugin

2011-11-15 Thread Andres Riancho
Carlos, On Thu, Sep 29, 2011 at 4:21 PM, Carlos Pantelides wrote: > Andres: > > As I promise you at ekoparty, here is a version of the plugin that can be > told to skip symfony detection. Sorry for the very very late response, but I've been working a lot on other things > There is a commen

Re: [W3af-users] symfony plugin

2011-09-29 Thread Carlos Pantelides
Andres: As I promise you at ekoparty, here is a version of the plugin that can be told to skip symfony detection. There is a comment: "The next two tests are broken. Don't really know why." I think that only the last test is broken, do you know why there are two marked as broken? Carlos Pa

Re: [W3af-users] symfony plugin

2011-09-15 Thread Andres Riancho
last test, at line 125. > > Carlos Pantelides > > - > > http://seguridad-agile.blogspot.com/ > > > --- On Tue, 7/19/11, Andres Riancho wrote: > >> From: Andres Riancho >> Subject: Re: [W3af-users] symfony plugin >> To: "Carlos Pante

Re: [W3af-users] symfony plugin

2011-09-12 Thread Carlos Pantelides
ct: Re: [W3af-users] symfony plugin > To: "Carlos Pantelides" > Cc: [email protected], "w3af" > Date: Tuesday, July 19, 2011, 4:19 PM > Carlos, > > On Tue, Jul 19, 2011 at 11:28 AM, Carlos Pantelides > > wrote: > >> > How can I ask if a

Re: [W3af-users] symfony plugin

2011-08-06 Thread Carlos Pantelides
Andrés: >> ok, in august I'll spend some time. I've attached >> a new version with cosmetic changes. > Ahá! I remembered this email! :) [0] . Were you able to > spend some > quality time with the plugin? ;) Not yet, I am still dealing with eci2011 (haskell+python) and "seminario de ingeniería"

Re: [W3af-users] symfony plugin

2011-08-06 Thread Andres Riancho
Carlos, On Tue, Jul 19, 2011 at 4:19 PM, Andres Riancho wrote: > Carlos, > > On Tue, Jul 19, 2011 at 11:28 AM, Carlos Pantelides > wrote: >>> > How can I ask if a cookie is set? >>> >>> Not sure if there is a "clean" way of asking xUrllib >>> if in the next request it will send a cookie or not >

Re: [W3af-users] symfony plugin

2011-07-19 Thread Andres Riancho
Carlos, On Tue, Jul 19, 2011 at 11:28 AM, Carlos Pantelides wrote: >> > How can I ask if a cookie is set? >> >> Not sure if there is a "clean" way of asking xUrllib >> if in the next request it will send a cookie or not >> (also, it depends on the request you make, since cookies >> might be restr

Re: [W3af-users] symfony plugin

2011-07-19 Thread Carlos Pantelides
> > How can I ask if a cookie is set? > > Not sure if there is a "clean" way of asking xUrllib > if in the next request it will send a cookie or not > (also, it depends on the request you make, since cookies > might be restricted to a path). > What you could do, is to have two parts of the plugin

Re: [W3af-users] symfony plugin

2011-07-19 Thread Andres Riancho
Carlos, On Tue, Jul 19, 2011 at 10:20 AM, Carlos Pantelides wrote: > Andres: > >> - From reading the plugin I understand that the symfony framework >> will send a Set-Cookie in each HTTP response that contains >> a form. Is that correct? > > I thought so, but for the tone of your question... I'm

Re: [W3af-users] symfony plugin

2011-07-19 Thread Carlos Pantelides
Andres: > - From reading the plugin I understand that the symfony framework > will send a Set-Cookie in each HTTP response that contains > a form. Is that correct? I thought so, but for the tone of your question... I'm not sure. Let me ask wireshark... no, only in the first connection. I don't k

Re: [W3af-users] symfony plugin

2011-07-19 Thread Andres Riancho
Carlos, On Tue, Jul 19, 2011 at 8:20 AM, Carlos Pantelides wrote: > Hello: > > I've been working on a symfony !csrf protection plugin. I owe you the > testing, next month I'll have some spare time to make it. Meanwhile, I want to > share it with you. Great! Thanks again for contributing. >

[W3af-users] symfony plugin

2011-07-19 Thread Carlos Pantelides
Hello: I've been working on a symfony !csrf protection plugin. I owe you the testing, next month I'll have some spare time to make it. Meanwhile, I want to share it with you. Symfony has csrf protection activated by default in the forms, but sometimes the devs disable it either by need or ig