tag:support.arachni-scanner.com,2012-07-01:/discussions/problems/171-issue-with-scanning-primefaces-application
Arachni: Discussion
2013-11-11T21:21:31Z
tag:support.arachni-scanner.com,2012-07-01:Comment/29454936
2013-10-17T15:42:01Z
2013-10-17T15:42:01Z
Issue with Scanning primefaces application.
<div><p>Hi Madhusudhan,</p>
<p>I'm afraid I'll disappoint you.</p>
<p>It's generally hard enough to figure out how Arachni went wrong
without having access to the target website, it's pretty much
impossible to know how the targeted website went wrong while
Arachni was scanning it.</p>
<p>I suggest you ask the PrimeFaces folk for help as the issue
occurred at the server-side.</p>
<p>Cheers</p></div>
Tasos Laskos
tag:support.arachni-scanner.com,2012-07-01:Comment/29454936
2013-10-18T06:05:24Z
2013-10-18T06:05:24Z
Issue with Scanning primefaces application.
<div><p>Hi,</p>
<p>First Thanks for your replay,<br>
We used PrimeFaces for the View layer.<br>
Actually in my web application we are using Ldap for authentication
process.<br>
In login page we have two text fields to enter user name and
password.<br>
After entering the values we are clicking on login button. So when
the user clicks on login button the appropriate configured java
method will execute on server side and perfumes the authentication
and return to welcome page.<br>
Now my question is how to achieve / login in to my website through
Arachni Tool.</p>
<p>My intention is when I gave the website URL to Arachni Tool.
Arachni Tool needs to login automatically and needs to scan all the
pages.</p>
<p>Note: I tried with auto login Plug-in but it does not work.</p>
<p>Could you please help me out to over come this.</p>
<p>Thanks & Regards,<br>
Madhusudhan T.</p></div>
talari.madhusudhan
tag:support.arachni-scanner.com,2012-07-01:Comment/29454936
2013-10-18T20:29:30Z
2013-10-18T20:29:30Z
Issue with Scanning primefaces application.
<div><p>Could you show me how you configured the autologin plugin and
the HTML code of the login form please?</p></div>
Tasos Laskos
tag:support.arachni-scanner.com,2012-07-01:Comment/29454936
2013-10-23T14:44:32Z
2013-10-23T14:47:34Z
Issue with Scanning primefaces application.
<div><p>Hi Tasos Laskos,</p>
<p>I have configure the auto login as follows and also you can see
in the attached screen shot.<br>
URl: http://:8080/Webapp/login.html (Like this url)<br>
Parameters :
frmLogin:txtLoginUser=CVDMTEST34&frmLogin:txtPassword=welcome123<br>
Check : Seleccionar Sistema (My welcome page contains this
string)</p>
<p>Here is the my login form html code snippet</p>
<pre>
<code><h:form id="frmLogin">
<div id="general-login-content">
<div id="center-login">
<table id="tblLogin" style="margin-right: auto;">
<tr>
<td ><h:outputText value="#{msgs['login.lbl.user']}" id="idOtxtLoginUser"/></td>
<td >
<p:inputText id="txtLoginUser" value="#{loginBean.loginUser}" maxlength="20" autocomplete="off">
<pe:keyFilter regEx="#{cons['exp.regular.alphanumeric.not.space']}"/>
</p:inputText>
</td>
<td >
<p:message for="txtLoginUser" display="icon" id="idMsgLoginUser"/>
</td>
</tr>
<tr>
<td >
<h:outputText value="#{msgs['login.lbl.password']}" id="idOtxtLoginPwd"/>
</td>
<td >
<p:password id="txtPassword" value="#{loginBean.password}" maxlength="20" />
</td>
<td >
<p:message for="txtPassword" display="icon" id="idMsgLoginPwd"/>
</td>
</tr>
<tr>
<td colspan="3" align="left">
<p:commandButton id="cmdLogin" value="#{msgs['btn.accept']}" update="@form :opnlDialogosGenerales"
action="#{loginBean.loginAction}" ajax="false"/>
</td>
</tr>
<tr>
<td colspan="3" align="left">
<p:message for="cmdLogin" display="text" id="idMsgCmdLogin"/>
</td>
</tr>
</table>
</div>
<table id="tblFooter" width="100%">
<tr>
<td width="20%" align="center">#{msgs['lbl.devlope.version']}</td>
<td width="25%" lign="center">#{msgs['lbl.devlope.version.date']}</td>
<td width="20%" align="center"> #{msgs['lbl.devlope.env']}</td>
<td width="15%" align="left"><h:selectOneMenu id="language1"
style="font-family:''Lucida Sans Unicode','Lucida Grande',Geneva,Verdana,Arial,sans-serif;font-size:11px;"
value="#{sessionScope.locale}" immediate="true">
<f:selectItem itemLabel="#{msgs['lbl.footer.Espanol']}" itemValue="es" id="idCboItemEsponol"/>
<f:selectItem itemLabel="#{msgs['lbl.footer.Ingles']}" itemValue="en" id="idCboItemIngles"/>
<!-- <f:selectItem itemLabel="Francés " itemValue="fr" /> -->
<p:ajax event="change" listener="#{loginBean.localeCodeChanged}" update="@form"/>
</h:selectOneMenu></td>
<td width="15%" align="right">
<ui:include src="/template/includes/logo.xhtml" width="200" height="60"/>
</td>
</tr>
</table>
</div>
</h:form></code>
</pre>
<p>Thanks in Advance<br>
Madhusudhan T</p></div>
talari.madhusudhan
tag:support.arachni-scanner.com,2012-07-01:Comment/29454936
2013-10-23T14:50:33Z
2013-10-23T14:50:33Z
Issue with Scanning primefaces application.
<div><p>Thanks for the info Talari, but could you show me the form code
as it appears in the "View source" option of your browser? Because
that's the HTML code Arachni will be seeing.</p>
<p>Cheers</p></div>
Tasos Laskos
tag:support.arachni-scanner.com,2012-07-01:Comment/29454936
2013-10-24T14:09:26Z
2013-10-24T14:09:26Z
Issue with Scanning primefaces application.
<div><p>Your options seem correct. I noticed that the form action points
to a real URL, are the credentials you pasted in your earlier reply
supposed to work?</p>
<p>Because I just get an error when I submit the form.</p>
<p>As a second to last resort, could you try using the CLI to login
with the autologin plugin? The CLI interface is more verbose and
can help debugging.</p>
<p>If that fails, the last resort would be to give me temporary
access to the web application so that I can debug it myself.</p>
<p>Cheers</p></div>
Tasos Laskos
tag:support.arachni-scanner.com,2012-07-01:Comment/29454936
2013-10-24T15:47:24Z
2013-10-24T15:47:24Z
Issue with Scanning primefaces application.
<div><p>Thanks for replay , Here I attached the login page html code (
login.html).<br>
Could you please find it.</p>
<p>Please let me know, if you have any additional information.</p>
<p>Thanks in Advance<br>
Madhusudhan T</p></div>
talari.madhusudhan
tag:support.arachni-scanner.com,2012-07-01:Comment/29454936
2013-10-24T16:06:05Z
2013-10-24T16:06:05Z
Issue with Scanning primefaces application.
<div><p>I'm afraid I can't debug this without access to the web
application.</p></div>
Tasos Laskos