12.07.2015 Views

w3af Guide de l'Utilisateur - Exploit Database

w3af Guide de l'Utilisateur - Exploit Database

w3af Guide de l'Utilisateur - Exploit Database

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The extensions parameter is a comma separated list of extensionsthat this plugin will try to upload. Many web applicationsverify the extension of the file being uploa<strong>de</strong>d, if specialextensions are required, they can be ad<strong>de</strong>d here.Some web applications check the contents of the files beinguploa<strong>de</strong>d to see if they are really what their extensionis telling. To bypass this check, this plugin uses filetemplates located at "plugins/audit/fileUpload/", this templatesare valid files for each extension that have a section ( thecomment field in a gif file for example ) that can be replacedby scripting co<strong>de</strong> ( PHP, ASP, etc ).After uploading the file, this plugin will try to find it oncommon directories like "upload" and "files" on every knowdirectory. If the file is found, a vulnerability exists.<strong>w3af</strong>/plugins>>>Maintenant nous savons ce que fait ce plugin, mais voyons ce qu'il a dans leventre:<strong>w3af</strong>/plugins>>> audit config xss<strong>w3af</strong>/plugins/audit/config:xss>>> view|------------------------------------------------------------|| Setting | Value | Description ||------------------------------------------------------------|| checkPersistent | True | Search persistent XSS || numberOfChecks | 2 | Set the amount of checks to || | | perform for each fuzzable || | | parameter. Valid numbers: 1 to || | | 10 ||------------------------------------------------------------|<strong>w3af</strong>/plugin/xss>>> set checkPersistent False<strong>w3af</strong>/plugin/xss>>> back<strong>w3af</strong>/plugins>>> audit config sqli<strong>w3af</strong>/plugins/audit/config:sqli>>> view

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!