Andres Riancho wrote:
> blscrown Zakk,
> 
> On Wed, Apr 28, 2010 at 11:23 AM, Taras <[email protected]> wrote:
>> Hi, blscrown Zakk!
>>
>> "userDir" discovery plugin depends on these plugins.
>> You can disable it.
>>
>>> Hello, i have a question about the discovery phase.
>>> When i'm testing a intranet web application with all discovery plugins, but
>>> without fingerMSN, fingerGoogle or fingerPKS, w3af enable this plugins
>>> automatically.
>>> Why happens that???
> 
>     Taras is completely right, the userDir plugin depends on those
> plugins. But dependency only makes sense for online applications, not
> for intranet ones. I think that maybe we should perform some checks in
> the fingerMSN, fingerGoogle and fingerPKS to verify if the target is
> internal or not... hmm... I'm going to add this as a Trac task.
> 
> Regards,

Please make this a manual config option, if possible.
It is not uncommon for us to do remote testing of applications that are 
not publicly available, either through VPNs or firewalls only allowing 
certain IPs through.  We don't use these plugins on purpose, and would 
like to be able to avoid their accidental use as automatic depends if 
possible..

Steve
>>> Thanks.-
>>
>> --
>> Taras
>>
>> ------------------------------------------------------------------------------
>> _______________________________________________
>> W3af-users mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/w3af-users
>>
> 
> 
> 


-- 
  | Steven Pinkham, Security Researcher    |
  | http://www.mavensecurity.com           |
  | GPG public key ID CD31CAFB             |

------------------------------------------------------------------------------

_______________________________________________
W3af-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/w3af-users

Reply via email to