w3af (Web Application Attack and Audit Framework) adalah software yang bisa Anda gunakan untuk memeriksa keamanan aplikasi / website Anda.
Cara instalasi & penggunaannya sangat mudah, silakan ikuti panduan ini :
sudo apt-get update ; sudo apt-get -y install python-pip git
git clone https://github.com/andresriancho/w3af.git
cd w3af/
./w3af_console
# install semua paket yang diminta, lalu
./tmp/w3af_dependency_install.sh
Maka kini w3af & semua paket software yang dibutuhkannya telah terpasang.
Lalu buat file bernama MyScript.w3af, dengan isi sbb :
(CATATAN : jangan gunakan dulu plugin “redos” – terakhir saya gunakan, plugin redos ini berjalan selama 2 hari dan menghabiskan disk space di server saya. Hati-hati)
# -----------------------------------------------------------------------------------------------------------
# W3AF AUDIT SCRIPT FOR WEB APPLICATION
# -----------------------------------------------------------------------------------------------------------
#Configure HTTP settings
http-settings
set timeout 30
back
#Configure scanner global behaviors
http-settings
set timeout 20
set max_requests_per_second 100
back
misc-settings
set max_discovery_time 20
set fuzz_cookies True
set fuzz_form_files True
set fuzz_url_parts True
set fuzz_url_filenames True
back
plugins
#Configure entry point (CRAWLING) scanner
crawl web_spider
crawl config web_spider
set only_forward False
set ignore_regex (?i)(logout|disconnect|signout|exit)+
back
#Configure vulnerability scanners
##Specify list of AUDIT plugins type to use
audit blind_sqli, buffer_overflow, cors_origin, csrf, eval, file_upload, ldapi, lfi, os_commanding, phishing_vector, response_splitting, sqli, xpath, xss, xst
##Customize behavior of each audit plugin when needed
audit config file_upload
set extensions jsp,php,php2,php3,php4,php5,asp,aspx,pl,cfm,rb,py,sh,ksh,csh,bat,ps,exe
back
##Specify list of GREP plugins type to use (grep plugin is a type of plugin that can find also vulnerabilities or informations disclosure)
grep analyze_cookies, click_jacking, code_disclosure, cross_domain_js, csp, directory_indexing, dom_xss, error_500, error_pages,
html_comments, objects, path_disclosure, private_ip, strange_headers, strange_http_codes, strange_parameters, strange_reason, url_session, xss_protection_header
##Specify list of INFRASTRUCTURE plugins type to use (infrastructure plugin is a type of plugin that can find informations disclosure)
infrastructure server_header, server_status, domain_dot, dot_net_errors
#Configure target authentication
#Configure reporting in order to generate an HTML report
output console, html_file
output config html_file
set output_file /tmp/W3afReport.html
set verbose False
back
output config console
set verbose False
back
back
#Set target informations, do a cleanup and run the scan
target
###### GANTI DENGAN SITUS YANG INGIN ANDA TES ###############
set target https://google.com
set target_os unix
set target_framework php
back
cleanup
start
Simpan file tersebut, lalu jalankan perintah sbb :
./w3af_console Â-s MyScript.w3af
Kini tinggal Anda tunggu sampai selesai, dan setelah itu laporannya bisa dilihat di /tmp/W3afReport.html
Enjoy !
Maaf gan. Mau nanya. W3af bisa gak di pasang di host blogspot.
Kalau bisa. Mau saya coba pasang di
http://www.ilmubeton.com/
Yerimakasih
Websitemu keren bro. Cek juga web Rendang Tambuah Ciek kami ya http://tambuahciek.com
ikutan nyimak aja Gan, Terima Kasih dan salam kenal
A special theme worth commenting
sangat bermanfaat.. terima kasih!
thanks udah sharing ya
artikel bagus
mampir ke Blog saya
Cipto Rental Mobil
Terima kasih atas ilmunya yang bermanfaat mas
kunjungan ke dua…..
manfaat banget website/Blog nya…..
keep posting yang positif gan/sist..
ijin lihat-lihat blog/website nya ya…..
jangan lupa kunjungi website nya ya 🙂
cluster murah bekasi
info rumah murah bekasi
rumah murah bekasi
Secret Tips Making Money From Photography
keren..
Cara Mengatasi Custom Domain Blogger Tidak Bisa Diakses Tanpa WWW
interesting information …. good luck to you
Panduan Togel Online
Promo Member Baru
Prediksi Togel Online Terupdate
Hasil Togel Online
Prediksi Togel Hongkong
Prediksi 9 Pasaran
bilgileriniz özgünlügünüz ile beni fazlasıyla memnun etti
başarılarınd devamını dilerim
Terima kasih atas informasinya yang sangat bagus dan jelas sekali. Sangat menginspirasi sekali bagi saya. Semoga informasi ini bisa bermanfaat buat pembaca semuanya.
paket wisata karimunjawa
wisata karimunjawa
paket karimunjawa
paket wisata pulau karimunjawa
wisata pulau karimunjawa
paket tour karimunjawa
tour karimunjawa
karimunjawa
pulau karimunjawa
hotel karimunjawa
Sgp 45
sangat membantu sekali, thank
nice info,
The Presidents Executive karaoke Karaoke Purwokerto
The Presidents Executive Karaoke Purwokerto
Terimakasih atas infonya gan
http://iroskesehatanherbal.blogspot.com/p/cara-pembelian-qnc-jelly-gamat.html
Prediksi bola hari ini dan terupdate , bola Hari Ini Terupdate Hanya di http://prediksibola712.blogspot.com/
makasih udah share codingannya, klo bisa dtambahin lagi thx min
terimakasih ilmunya gan
Daftar Situs Game Online Terbaru 2018, mudah menang, aman dan terpercaya.
Asian Online Games real money, free chips for new member, register here!!
PLAY NOW !!!
SmsQQ
aseanqq
canduqq
dominobetqq
ajoqq
waletqq
liga99
dewadominoqq
danamonqq
prediksi bola malam ini dan terupdate ,
Bola Malam Ini Terupdate Hanya di http://prediksibola717.blogspot.com/
lumayan susah dalam pengaplikasiannya ternyata gan
wow mantap gan
mantullll untuk artikel dan infonya gan……
wah, artikelnya bikin nambah wawasan semakin luas nih. semangat terus gan …
thanks boss sudah mau berbagi info menariknya…..
lanjutkan gan untuk terus membuat artikel bagus seperti ini…
Mantap gan. keren
thanks boss sudah mau berbagi info menariknya…..
รถรับจ้าง ชลบุรี
akan saya coba arahan nya soalnya suka problem di Framework nya..
Informasi yang sangat bagus dan berguna. Ditunggu untuk update selanjutnya gan
Volcano Run
Volcano Run 2019
Mantap gan artikelnya. Selamat Datang di Sewa Bis Pariwisata Penyedia Jasa Sewa Bus Pariwisata, Paket Wisata dan Study Tour.
Wah sayang sekali gan saya platformnya blogspot, coba kalau wordpress pasti sudah saya coba gan. Terimakasih atas infonya, semangat terus gan
Felix Andika
I was really enjoyed to read this topic and I Got some good idea by reading this topic. Thank you for your positive post.- dentist in hartford ct
luar biasa blog ini, sejak ane pakai domain pribadi sampai sekarang pakai domain https://kantri.or.id
blog ini masih ada….salut euy…
Terima kasih infonya, itu bisa untuk semua versi redos ya ?
Wonderful site. Plenty of helpful info here. I am sending it to some pals ans additionally sharing in delicious. And obviously, thank you for your effort!
Great ?V I should certainly pronounce, impressed with your website. I had no trouble navigating through all tabs as well as related info ended up being truly simple to do to access. I recently found what I hoped for before you know it in the least. Reasonably unusual. Is likely to appreciate it for those who add forums or anything, web site theme . a tones way for your customer to communicate. Nice task.
mantul bosku
kerenn
Kunjungi kami di https://kriptova.com untuk artikel-artikel teknis tentang blockchain dan cryptocurrency
Look through this Just CBD gummies peach rings review to get to know more about interesting offers. If you don’t like peach flavor, it isn’t the right thing for you)
Nyeri otot yang diakibatkan benturan memang sangat sakit, bahkan dapat menyebabkan pembengkakan, serta mengganggu aktivitas sehari-hari. Untuk itu, disini saya mempunyai sebuah Cara Mengatasi Nyeri Otot Akibat Benturan yang dijamin sembuh dengan cepat, tanpa perlu khawatir akan adanya efek samping.
Khasiat Ricalinu Untuk Nyeri Otot Kaki
Cara Mengatasi Nyeri Otot Akibat Benturan
Kalo dah Pake Bahasa program gini dah pushing euy. Mending klik videonya
Menarik, tapi Saya tidak terlalu mengerti bahasanya. Kayaknya ini tingkat tinggi ya
Nice info. This is a very impressive post, Very useful information, it clarified things a lot for us. Thanks for sharing valuable tips. – Chennai to Shirdi Tour Package
Bachelor of Commerce Semester wise Exam Result 2020 now available online. Check 1st 2nd 3rd Year BCom Result 2020-2021.
Mysore University Sem Result
Mysore University B.Com Sem Result 2019-20
terima kasih sangat bermanfaat buat sya pemula
Printers are the source of creating the file and we attach more importance to it. We provide high-quality printers such as Canon Printer setup services. For more information you can check our official website.
We are the top service provider in the UK. We offer support for printer, set up printer, uninstall programs, remove viruses, update drivers and much more.
Here is introduced MetaMask Support Number as regards to the rise in usage of METAMASK it is important for the METAMASK users to have the MetaMask Support Number USA/CA: +1(808)800-9965 because no matter if you are newbie or experienced it is normal to have issues while using METAMASK like issues in sending, receiving or swapping which can be resolved by the help of MetaMask Support Number as the customer service of MetaMask Support Number is there to help METAMASK users to take get rid of the all the errors in using features of the METAMASK so for that all you need to do is contact MetaMask Support Number for resolving any errors in METAMASK you can always speak to MetaMask Support Number and explain the problem to MetaMask Support Number representative to help you in a sorted way.
nice info
How to enable the numeric keypad as a mouse on Windows 11
Fitness apps on your phone
Kindle Support Number covers all the issues related to any model of kindle. It covers kindle Keyboard, Kindle Touch, Kindle Fire and kindle Paper white. So call on Kindle Technical Support Number +1-877-855-0855 and get Help for more.
If you face any Metamask issue, just call on +1 808-800-9965 MetaMask Support Number. Our professional technician solve your problem in few minutes. Feel free to call anytime.
Hi sufehmi.com webmaster, Excellent work!
To the sufehmi.com administrator, Thanks for the great post!
Hello sufehmi.com webmaster, Your posts are always on point.
Hello sufehmi.com owner, You always provide clear explanations and step-by-step instructions.
Hi sufehmi.com webmaster, Keep it up!
Hello sufehmi.com webmaster, Great content!
To the sufehmi.com administrator, Your posts are always well researched.
Hi sufehmi.com webmaster, Your posts are always informative and well-explained.
Dear sufehmi.com owner, Good job!
Hello sufehmi.com owner, Your posts are always informative and well-explained.
Hi sufehmi.com owner, Your posts are always well-supported by facts and figures.
Hello sufehmi.com webmaster, You always provide clear explanations and definitions.
Dear sufehmi.com admin, You always provide great examples and real-world applications.
Dear sufehmi.com administrator, Great content!
Hi sufehmi.com owner, Keep the good content coming!
To the sufehmi.com webmaster, You always provide great information and insights.
Hi sufehmi.com webmaster, Your posts are always well structured and easy to follow.
Hi sufehmi.com admin, Your posts are always well structured and easy to follow.
Hello sufehmi.com admin, Nice post!
Hi sufehmi.com owner, Your posts are always a great source of knowledge.
To the sufehmi.com webmaster, Your posts are always well-received and appreciated.
To the sufehmi.com owner, Nice post!
To the sufehmi.com admin, Thanks for the well-researched and well-written post!