Daniel,
On Tue, Feb 16, 2010 at 3:07 PM, Daniel Gaddis
<[email protected]> wrote:
> After first batch(?) of requests w3af appears to hang running windows xp
> sp3, Python 2.5.4, and w3af
What version of w3af are you using?
>
>
> Here are the settings…
>
>
>
> misc-settings
>
> set maxThreads 4
>
> back
>
> plugins
>
> audit sqli, xss
>
> audit config xss
>
> set numberOfChecks 1
>
> back
>
> back
>
> plugins
>
> output htmlFile, textFile, console, xmlFile
>
> back
>
> plugins
>
> discovery webSpider
>
> back
>
> target
>
> set target http://www.test.senate.state.tx.us/
>
> back
>
>
>
> Here is output.txt
>
>
>
> [ 02/16/10 11:08:48 - debug ] Exiting setOutputPlugins()
>
> [ 02/16/10 11:08:48 - information ] Auto-enabling plugin: grep.error500
>
> [ 02/16/10 11:08:48 - information ] Auto-enabling plugin:
> grep.httpAuthDetect
>
> [ 02/16/10 11:08:48 - debug ] Called w3afCore.start()
>
> [ 02/16/10 11:08:48 - Enabled plugins ] plugins
>
> [ 02/16/10 11:08:48 - Enabled plugins ] audit sqli, xss
>
> [ 02/16/10 11:08:48 - Enabled plugins ] audit config xss
>
> [ 02/16/10 11:08:48 - Enabled plugins ] set checkStored True
>
> [ 02/16/10 11:08:48 - Enabled plugins ] set numberOfChecks 1
>
> [ 02/16/10 11:08:48 - Enabled plugins ] back
>
> [ 02/16/10 11:08:48 - Enabled plugins ] back
>
> [ 02/16/10 11:08:48 - Enabled plugins ] plugins
>
> [ 02/16/10 11:08:48 - Enabled plugins ] grep error500, httpAuthDetect
>
> [ 02/16/10 11:08:48 - Enabled plugins ] back
>
> [ 02/16/10 11:08:48 - Enabled plugins ] plugins
>
> [ 02/16/10 11:08:48 - Enabled plugins ] output htmlFile, xmlFile,
> textFile, console
>
> [ 02/16/10 11:08:48 - Enabled plugins ] back
>
> [ 02/16/10 11:08:48 - Enabled plugins ] plugins
>
> [ 02/16/10 11:08:48 - Enabled plugins ] discovery webSpider
>
> [ 02/16/10 11:08:48 - Enabled plugins ] back
>
> [ 02/16/10 11:08:48 - Enabled plugins ] target
>
> [ 02/16/10 11:08:48 - Enabled plugins ] set target
> http://www.test.senate.state.tx.us/
>
> [ 02/16/10 11:08:48 - Enabled plugins ] back
>
> [ 02/16/10 11:08:48 - debug ] Called buildOpeners
>
> [ 02/16/10 11:08:48 - debug ] keepalive: The connection manager has 0 active
> connections.
>
> [ 02/16/10 11:08:48 - debug ] keepalive: added one connection,
> len(self._hostmap["www.test.senate.state.tx.us"]): 1
>
> [ 02/16/10 11:08:48 - debug ] DNS response from DNS server for domain:
> www.test.senate.state.tx.us
>
> [ 02/16/10 11:08:48 - debug ] GET http://www.test.senate.state.tx.us/
> returned HTTP code "200" - id: 1
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43096264"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Starting grepWorker for response: <
> httpResponse | 200 | http://www.test.senate.state.tx.us/ | id:1 >
>
> [ 02/16/10 11:08:48 - debug ] Finished grepWorker for response: <
> httpResponse | 200 | http://www.test.senate.state.tx.us/ | id:1 >
>
> [ 02/16/10 11:08:48 - debug ] Called _discoverWorker()
>
> [ 02/16/10 11:08:48 - debug ] Starting plugin: webSpider
>
> [ 02/16/10 11:08:48 - debug ] webSpider plugin is testing:
> http://www.test.senate.state.tx.us/
>
> [ 02/16/10 11:08:48 - debug ] GET http://www.test.senate.state.tx.us/
> returned HTTP code "200" - id: 2 - from cache.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43164056"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Starting grepWorker for response: <
> httpResponse | 200 | http://www.test.senate.state.tx.us/ | id:2 |
> fromCache:True >
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43163696"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43138344"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43147016"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] keepalive: The connection manager has 1 active
> connections.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43164576"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] keepalive: The connection manager has 1 active
> connections.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43164936"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] keepalive: The connection manager has 1 active
> connections.
>
> [ 02/16/10 11:08:48 - debug ] keepalive: added one connection,
> len(self._hostmap["www.test.senate.state.tx.us"]): 2
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43174248"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] keepalive: added one connection,
> len(self._hostmap["www.test.senate.state.tx.us"]): 3
>
> [ 02/16/10 11:08:48 - debug ] Cached DNS response for domain:
> www.test.senate.state.tx.us
>
> [ 02/16/10 11:08:48 - debug ] Cached DNS response for domain:
> www.test.senate.state.tx.us
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43174568"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43165056"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43174288"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43738496"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43738736"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43738856"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43165296"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43739096"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43739136"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43739336"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] GET
> http://www.test.senate.state.tx.us/favicon.ico returned HTTP code "200" -
> id: 3
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43164696"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] GET
> http://www.test.senate.state.tx.us/75r/Senate/Commit.htm returned HTTP code
> "200" - id: 4
>
> [ 02/16/10 11:08:48 - debug ] Finished grepWorker for response: <
> httpResponse | 200 | http://www.test.senate.state.tx.us/ | id:2 |
> fromCache:True >
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43144376"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] keepalive: The connection manager has 3 active
> connections.
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43739776"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] GET
> http://www.test.senate.state.tx.us/75r/Senate/New.htm returned HTTP code
> "200" - id: 5
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43165656"
> to a thread in the thread pool.
>
> [ 02/16/10 11:08:48 - debug ] GET
> http://www.test.senate.state.tx.us/75r/Senate/commit/c540/c540.htm returned
> HTTP code "200" - id: 6
>
> [ 02/16/10 11:08:48 - debug ] Assigning function object with id: "43164096"
> to a thread in the thread pool.
>
> [ 02/16/10 11:12:49 - console ] User hitted Ctrl+C, stopping scan.
>
> [ 02/16/10 11:12:50 - debug ] The user stopped the core.
>
> [ 02/16/10 11:12:50 - debug ] Cleared urllib2 local cache.
>
> [ 02/16/10 11:12:50 - debug ] Enabling _dnsCache()
>
>
>
> Any suggestions?
>
>
>
> Thanks,
>
> Daniel
>
> ------------------------------------------------------------------------------
> SOLARIS 10 is the OS for Data Centers - provides features such as DTrace,
> Predictive Self Healing and Award Winning ZFS. Get Solaris 10 NOW
> http://p.sf.net/sfu/solaris-dev2dev
> _______________________________________________
> W3af-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/w3af-users
>
>
--
Andrés Riancho
Founder, Bonsai - Information Security
http://www.bonsai-sec.com/
http://w3af.sf.net/
------------------------------------------------------------------------------
SOLARIS 10 is the OS for Data Centers - provides features such as DTrace,
Predictive Self Healing and Award Winning ZFS. Get Solaris 10 NOW
http://p.sf.net/sfu/solaris-dev2dev
_______________________________________________
W3af-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/w3af-users