Isn't it possible to use the "grep" module to look for instances of password? Perhaps that might indicate potential disclosures. It might yield a few false positives though.
Regards, Christian On Sat, Oct 3, 2009 at 3:43 AM, Andres Riancho <[email protected]> wrote: > Steve, > > Please read inline, > > On Fri, Oct 2, 2009 at 4:11 PM, steve jacobs <[email protected]> > wrote: >> Dear Seasoned w3af users - >> >> Do you know which w3af plugins could help my company identify: >> >> a) Weak SQL Server passwords for our apps that have a backend SQL DB >> b) Weak MS Access passwords for our apps that have a backend MS Access DB > > Do you mean passwords in the database connection string? > >> c) Passwords exposed in source code > > I don't think that's even possible to do. > >> d) Weak passwords on Windows Servers running IIS >> e) Missing patches on Web Servers (IIS, Apache). > > This last two are out of w3af's scope. > >> Any pointers if w3af can identify these would be great. >> >> Regards, >> Steve. >> >> ________________________________ >> View your Twitter and Flickr updates from one place – Learn more! >> ------------------------------------------------------------------------------ >> Come build with us! The BlackBerry® Developer Conference in SF, CA >> is the only developer event you need to attend this year. Jumpstart your >> developing skills, take BlackBerry mobile applications to market and stay >> ahead of the curve. Join us from November 9-12, 2009. Register now! >> http://p.sf.net/sfu/devconf >> _______________________________________________ >> W3af-users mailing list >> [email protected] >> https://lists.sourceforge.net/lists/listinfo/w3af-users >> >> > > > > -- > Andrés Riancho > Founder, Bonsai - Information Security > http://www.bonsai-sec.com/ > http://w3af.sf.net/ > > ------------------------------------------------------------------------------ > Come build with us! The BlackBerry® Developer Conference in SF, CA > is the only developer event you need to attend this year. Jumpstart your > developing skills, take BlackBerry mobile applications to market and stay > ahead of the curve. Join us from November 9-12, 2009. Register now! > http://p.sf.net/sfu/devconf > _______________________________________________ > W3af-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/w3af-users > -- Christian Frichot e: [email protected] p: 0433 490 117 w: http://un-excogitate.org ------------------------------------------------------------------------------ Come build with us! The BlackBerry® Developer Conference in SF, CA is the only developer event you need to attend this year. Jumpstart your developing skills, take BlackBerry mobile applications to market and stay ahead of the curve. Join us from November 9-12, 2009. Register now! http://p.sf.net/sfu/devconf _______________________________________________ W3af-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/w3af-users
