Arachni - Web Application Security Scanner Framework v1.4 Author: Tasos "Zapotek" Laskos (With the support of the community and the Arachni Team.) Website: http://arachni-scanner.com Documentation: http://arachni-scanner.com/wiki [~] No element audit options were specified, will audit links, forms, cookies, UI inputs, UI forms, JSONs and XMLs. [*] Initializing... [*] Preparing plugins... [*] AutoLogin: Logging in, please wait. [!!] [http/proxy_server#start_async:50] ProxyServer: Starting [!!] [http/proxy_server#start_async:63] ProxyServer: Started [!] [browser#spawn_phantomjs:1277] Browser: Spawning PhantomJS... [!] [browser#spawn_phantomjs:1290] Browser: Attempt #0, chose port number 10213 [!] [browser#spawn_phantomjs:1294] Browser: Spawning process: /home/arachni/arachni-1.4-0.5.10/bin/../system/usr/bin/phantomjs [!] [browser#spawn_phantomjs:1315] Browser: Process spawned, waiting for it to boot-up... [!] [browser#spawn_phantomjs:1329] Browser: Boot-up complete. [!] [browser#spawn_phantomjs:1337] Browser: 7693: Started PID: 7696 7693: Working 7693: Working PhantomJS is launching GhostDriver... [INFO - 2016-07-15T06:33:34.566Z] GhostDriver - Main - running on port 10213 [!] [browser#spawn_phantomjs:1341] Browser: PhantomJS is ready. [!] [session#login_from_configuration:326] Session: Logging in via configuration. [!] [session#login_from_configuration:329] Session: Logging in using browser. [!] [session#login_from_configuration:334] Session: Grabbing page at: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#goto:370] Browser: Loading http://10.0.2.15/DVWA-1.9/login.php ... [!!!] [http/proxy_server/connection#initialize:33] Connection: Starting new connection: 21780660 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/login.php [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1647] Browser: Checking: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1650] Browser: Allow: Scope enforcement disabled. [!!] [browser#request_handler:1582] Browser: Request can proceed to origin. [!!!] [http/proxy_server/connection#handle_request:99] Connection: -- Handler approves, running... [!!!] [http/proxy_server/connection#handle_request:107] Connection: -- ...completed in 0.007073: HTTP/1.1 200 OK [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#response_handler:1617] Browser: Injected custom JS. [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/polyfills.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/taint_tracer.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/dom_monitor.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#response_handler:1641] Browser: Stored. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:33] Connection: Starting new connection: 69992565520260 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/polyfills.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/polyfills.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/polyfills.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:33] Connection: Starting new connection: 69992465231220 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/taint_tracer.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#initialize:33] Connection: Starting new connection: 69992465228220 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/dom_monitor.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 21780660 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/dvwa/css/login.css [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/dvwa/css/login.css [!!] [browser#ignore_request?:1647] Browser: Checking: http://10.0.2.15/DVWA-1.9/dvwa/css/login.css [!!] [browser#ignore_request?:1650] Browser: Allow: Scope enforcement disabled. [!!] [browser#request_handler:1582] Browser: Request can proceed to origin. [!!!] [http/proxy_server/connection#handle_request:99] Connection: -- Handler approves, running... [!!!] [http/proxy_server/connection#handle_request:107] Connection: -- ...completed in 0.000652: HTTP/1.1 200 OK [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://10.0.2.15/DVWA-1.9/dvwa/css/login.css [!!] [browser#response_handler:1617] Browser: Injected custom JS. [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 21780660 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/dvwa/images/login_logo.png [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/dvwa/images/login_logo.png [!!] [browser#ignore_request?:1647] Browser: Checking: http://10.0.2.15/DVWA-1.9/dvwa/images/login_logo.png [!!] [browser#ignore_request?:1650] Browser: Allow: Scope enforcement disabled. [!!] [browser#request_handler:1582] Browser: Request can proceed to origin. [!!!] [http/proxy_server/connection#handle_request:99] Connection: -- Handler approves, running... [!!!] [http/proxy_server/connection#handle_request:107] Connection: -- ...completed in 0.000389: HTTP/1.1 304 Not Modified [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://10.0.2.15/DVWA-1.9/dvwa/images/login_logo.png [!!] [browser#response_handler:1617] Browser: Injected custom JS. [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#goto:372] Browser: ...done. [!!] [browser#wait_till_ready:409] Browser: Waiting for custom JS... [!!] [browser#wait_till_ready:411] Browser: ...done. [!!] [browser#wait_for_pending_requests:1400] Browser: Waiting for 0 requests to complete... [!!] [browser#wait_for_pending_requests:1405] Browser: ...done. [!] [session#login_from_configuration:344] Session: Got page with URL http://10.0.2.15/DVWA-1.9/login.php [!] [session#login_from_configuration:360] Session: Found login form: form:post:http://10.0.2.15/DVWA-1.9/login.php:-11861420770795514:996847763304354300 [!] [session#login_from_configuration:377] Session: Updated form inputs: {"username"=>"admin", "password"=>"password", "Login"=>"Login", "user_token"=>"f26c1daee2c027b5664b36ce963c519a"} [!] [session#login_from_configuration:381] Session: Submitting form. [!!] [browser#load_cookies:1443] Browser: Setting cookies: ["security=impossible; Path=/DVWA-1.9/; HttpOnly", "PHPSESSID=1u1dgkb9281odkm9lfqhkr06s6; Path=/"] [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 21780660 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/login.php/set-cookies-80a0bb556bcd3e845a18a306c4e3ebea [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php/set-cookies-80a0bb556bcd3e845a18a306c4e3ebea [!!] [browser#request_handler:1575] Browser: Resource has been preloaded. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#goto:370] Browser: Loading http://10.0.2.15/DVWA-1.9/login.php ... [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 21780660 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/login.php [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1647] Browser: Checking: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1650] Browser: Allow: Scope enforcement disabled. [!!] [browser#request_handler:1582] Browser: Request can proceed to origin. [!!!] [http/proxy_server/connection#handle_request:99] Connection: -- Handler approves, running... [!!!] [http/proxy_server/connection#handle_request:107] Connection: -- ...completed in 0.002814: HTTP/1.1 200 OK [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#response_handler:1617] Browser: Injected custom JS. [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/polyfills.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/taint_tracer.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/dom_monitor.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#response_handler:1641] Browser: Stored. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 69992565520260 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/polyfills.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/polyfills.js [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 69992465231220 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/taint_tracer.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/polyfills.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 69992465228220 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/dom_monitor.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#goto:372] Browser: ...done. [!!] [browser#wait_till_ready:409] Browser: Waiting for custom JS... [!!] [browser#wait_till_ready:411] Browser: ...done. [!!] [browser#wait_for_pending_requests:1400] Browser: Waiting for 0 requests to complete... [!!] [browser#wait_for_pending_requests:1405] Browser: ...done. [!] [page/dom#restore:174] Browser: Could not load snapshot by URL (http://10.0.2.15/DVWA-1.9/login.php), will load by replaying transitions. [!!] [browser#load_cookies:1443] Browser: Setting cookies: ["security=impossible; Path=/DVWA-1.9/; HttpOnly", "PHPSESSID=1u1dgkb9281odkm9lfqhkr06s6; Path=/"] [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 21780660 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/login.php/set-cookies-80a0bb556bcd3e845a18a306c4e3ebea [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php/set-cookies-80a0bb556bcd3e845a18a306c4e3ebea [!!] [browser#request_handler:1575] Browser: Resource has been preloaded. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#goto:370] Browser: Loading http://10.0.2.15/DVWA-1.9/login.php ... [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 21780660 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/login.php [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1647] Browser: Checking: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1650] Browser: Allow: Scope enforcement disabled. [!!] [browser#request_handler:1582] Browser: Request can proceed to origin. [!!!] [http/proxy_server/connection#handle_request:99] Connection: -- Handler approves, running... [!!!] [http/proxy_server/connection#handle_request:107] Connection: -- ...completed in 0.004312: HTTP/1.1 200 OK [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#response_handler:1617] Browser: Injected custom JS. [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/polyfills.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/taint_tracer.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/dom_monitor.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#response_handler:1641] Browser: Stored. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 69992565520260 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/polyfills.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/polyfills.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 69992465231220 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/taint_tracer.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/polyfills.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 69992465228220 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/dom_monitor.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#goto:372] Browser: ...done. [!!] [browser#wait_till_ready:409] Browser: Waiting for custom JS... [!!] [browser#wait_till_ready:411] Browser: ...done. [!!] [browser#wait_for_pending_requests:1400] Browser: Waiting for 0 requests to complete... [!!] [browser#wait_for_pending_requests:1405] Browser: ...done. [!!] [browser#fire_event:720] Browser: [start]: submit ({:inputs=>{"username"=>"admin", "password"=>"password", "Login"=>"Login", "user_token"=>"f26c1daee2c027b5664b36ce963c519a"}})
[!!] [browser#fill_in_form_inputs:1195] Browser: Could not fill in form input 'Login' because: Error Message => 'Element must be user-editable in order to clear it.' caused by Request => {"headers":{"Accept":"application/json","Accept-Encoding":"gzip;q=1.0,deflate;q=0.6,identity;q=0.3","Connection":"close","Content-Length":"2","Content-Type":"application/x-www-form-urlencoded","Host":"127.0.0.1:10213","User-Agent":"Ruby"},"httpVersion":"1.1","method":"POST","post":"{}","postRaw":"{}","url":"/clear","urlParsed":{"anchor":"","query":"","file":"clear","directory":"/","path":"/clear","relative":"/clear","port":"","host":"","password":"","user":"","userInfo":"","authority":"","protocol":"","source":"/clear","queryKey":{},"chunks":["clear"]},"urlOriginal":"/session/0e1bbac0-4a56-11e6-8c58-bfb95a979e51/element/%3Awdc%3A1468564416083/clear"} (ReqHand) [Selenium::WebDriver::Error::InvalidElementStateError [!!] [browser#fill_in_form_inputs:1195] Browser: Could not fill in form input 'user_token' because: Error Message => 'Element is not currently interactable and may not be manipulated' caused by Request => {"headers":{"Accept":"application/json","Accept-Encoding":"gzip;q=1.0,deflate;q=0.6,identity;q=0.3","Connection":"close","Content-Length":"2","Content-Type":"application/x-www-form-urlencoded","Host":"127.0.0.1:10213","User-Agent":"Ruby"},"httpVersion":"1.1","method":"POST","post":"{}","postRaw":"{}","url":"/clear","urlParsed":{"anchor":"","query":"","file":"clear","directory":"/","path":"/clear","relative":"/clear","port":"","host":"","password":"","user":"","userInfo":"","authority":"","protocol":"","source":"/clear","queryKey":{},"chunks":["clear"]},"urlOriginal":"/session/0e1bbac0-4a56-11e6-8c58-bfb95a979e51/element/%3Awdc%3A1468564416084/clear"} (ReqHand) [Selenium::WebDriver::Error::InvalidElementStateError [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 21780660 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:43] Connection: Got 76 bytes. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: POST http://10.0.2.15/DVWA-1.9/login.php [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1647] Browser: Checking: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1650] Browser: Allow: Scope enforcement disabled. [!!] [browser#request_handler:1582] Browser: Request can proceed to origin. [!!!] [http/proxy_server/connection#handle_request:99] Connection: -- Handler approves, running... [!!!] [http/proxy_server/connection#handle_request:107] Connection: -- ...completed in 0.003232: HTTP/1.1 200 OK [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#response_handler:1617] Browser: Injected custom JS. [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/polyfills.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/taint_tracer.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/dom_monitor.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#response_handler:1641] Browser: Stored. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 69992565520260 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/polyfills.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/polyfills.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 69992465231220 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/taint_tracer.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/polyfills.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 69992465228220 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/dom_monitor.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#fire_event:766] Browser: [waiting for requests]: submit ({:inputs=>{"username"=>"admin", "password"=>"password", "Login"=>"Login", "user_token"=>"f26c1daee2c027b5664b36ce963c519a"}}) [!!] [browser#wait_for_pending_requests:1400] Browser: Waiting for 0 requests to complete... [!!] [browser#wait_for_pending_requests:1405] Browser: ...done. [!!] [browser#fire_event:768] Browser: [done waiting for requests]: submit ({:inputs=>{"username"=>"admin", "password"=>"password", "Login"=>"Login", "user_token"=>"f26c1daee2c027b5664b36ce963c519a"}}) [!!] [browser#fire_event:773] Browser: [done in 0.437739164s]: submit ({:inputs=>{"username"=>"admin", "password"=>"password", "Login"=>"Login", "user_token"=>"f26c1daee2c027b5664b36ce963c519a"}}) [!] [session#login_from_configuration:383] Session: Form submitted. [!!] [http/proxy_server#shutdown:68] ProxyServer: Shutting down.. [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [Arachni::Reactor::Connection::Error::Closed] end of file reached [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [Arachni::Reactor::Connection::Error::Closed] end of file reached [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [Arachni::Reactor::Connection::Error::Closed] end of file reached [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [Arachni::Reactor::Connection::Error::Closed] end of file reached [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [NilClass] [!!] [http/proxy_server#shutdown:73] ProxyServer: Shutdown. [*] AutoLogin: Form submitted successfully, checking the session's validity. [!] [session#logged_in?:285] Session: Performing login check. [!] [session#logged_in?:291] Session: Login check done: false [!] [session#logged_in?:294] Session: GET /DVWA-1.9/login.php HTTP/1.1 Host: 10.0.2.15 Accept-Encoding: gzip, deflate User-Agent: Arachni/v1.4 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.8,he;q=0.6 Cookie: security=impossible;PHPSESSID=1u1dgkb9281odkm9lfqhkr06s6 HTTP/1.1 200 OK Date: Fri, 15 Jul 2016 06:33:36 GMT Server: Apache/2.4.10 (Debian) Expires: Tue, 23 Jun 2009 12:00:00 GMT Cache-Control: no-cache, must-revalidate Pragma: no-cache Vary: Accept-Encoding Content-Encoding: gzip Content-Length: 722 Content-Type: text/html;charset=utf-8 Login :: Damn Vulnerable Web Application (DVWA) v1.9












[-] [components/plugins/autologin#handle_error:84] AutoLogin: The response did not match the verifier. [~] AutoLogin: Aborting the scan. [*] ... done. [*] BrowserCluster: Initializing 6 browsers... [!!] [http/proxy_server#start_async:50] ProxyServer: Starting [!!] [http/proxy_server#start_async:63] ProxyServer: Started [!] [browser#spawn_phantomjs:1277] BrowserCluster Worker#30944180: Spawning PhantomJS... [!] [browser#spawn_phantomjs:1290] BrowserCluster Worker#30944180: Attempt #0, chose port number 10864 [!] [browser#spawn_phantomjs:1294] BrowserCluster Worker#30944180: Spawning process: /home/arachni/arachni-1.4-0.5.10/bin/../system/usr/bin/phantomjs [!] [browser#spawn_phantomjs:1315] BrowserCluster Worker#30944180: Process spawned, waiting for it to boot-up... [!] [browser#spawn_phantomjs:1329] BrowserCluster Worker#30944180: Boot-up complete. [!] [browser#spawn_phantomjs:1337] BrowserCluster Worker#30944180: 7935: Started PID: 7938 7935: Working 7935: Working PhantomJS is launching GhostDriver... 7935: Working [INFO - 2016-07-15T06:33:37.113Z] GhostDriver - Main - running on port 10864 [!] [browser#spawn_phantomjs:1341] BrowserCluster Worker#30944180: PhantomJS is ready. [*] BrowserCluster: Spawned #1 with PID 7938 [lifeline at PID 7935]. [!!] [http/proxy_server#start_async:50] ProxyServer: Starting [!!] [http/proxy_server#start_async:63] ProxyServer: Started [!] [browser#spawn_phantomjs:1277] BrowserCluster Worker#30944180: Spawning PhantomJS... [!] [browser#spawn_phantomjs:1290] BrowserCluster Worker#30944180: Attempt #0, chose port number 55940 [!] [browser#spawn_phantomjs:1294] BrowserCluster Worker#30944180: Spawning process: /home/arachni/arachni-1.4-0.5.10/bin/../system/usr/bin/phantomjs [!] [browser#spawn_phantomjs:1315] BrowserCluster Worker#30944180: Process spawned, waiting for it to boot-up... [!] [browser#spawn_phantomjs:1329] BrowserCluster Worker#30944180: Boot-up complete. [!] [browser#spawn_phantomjs:1337] BrowserCluster Worker#30944180: 7958: Started PID: 7961 7958: Working 7958: Working 7958: Working PhantomJS is launching GhostDriver... 7958: Working [INFO - 2016-07-15T06:33:37.659Z] GhostDriver - Main - running on port 55940 [!] [browser#spawn_phantomjs:1341] BrowserCluster Worker#30944180: PhantomJS is ready. [*] BrowserCluster: Spawned #2 with PID 7961 [lifeline at PID 7958]. [!!] [http/proxy_server#start_async:50] ProxyServer: Starting [!!] [http/proxy_server#start_async:63] ProxyServer: Started [!] [browser#spawn_phantomjs:1277] BrowserCluster Worker#30944180: Spawning PhantomJS... [!] [browser#spawn_phantomjs:1290] BrowserCluster Worker#30944180: Attempt #0, chose port number 63101 [!] [browser#spawn_phantomjs:1294] BrowserCluster Worker#30944180: Spawning process: /home/arachni/arachni-1.4-0.5.10/bin/../system/usr/bin/phantomjs [!] [browser#spawn_phantomjs:1315] BrowserCluster Worker#30944180: Process spawned, waiting for it to boot-up... [!] [browser#spawn_phantomjs:1329] BrowserCluster Worker#30944180: Boot-up complete. [!] [browser#spawn_phantomjs:1337] BrowserCluster Worker#30944180: 7981: Started PID: 7984 7981: Working 7981: Working 7981: Working PhantomJS is launching GhostDriver... [INFO - 2016-07-15T06:33:38.157Z] GhostDriver - Main - running on port 63101 [!] [browser#spawn_phantomjs:1341] BrowserCluster Worker#30944180: PhantomJS is ready. [*] BrowserCluster: Spawned #3 with PID 7984 [lifeline at PID 7981]. [!!] [http/proxy_server#start_async:50] ProxyServer: Starting [!!] [http/proxy_server#start_async:63] ProxyServer: Started [!] [browser#spawn_phantomjs:1277] BrowserCluster Worker#30944180: Spawning PhantomJS... [!] [browser#spawn_phantomjs:1290] BrowserCluster Worker#30944180: Attempt #0, chose port number 59289 [!] [browser#spawn_phantomjs:1294] BrowserCluster Worker#30944180: Spawning process: /home/arachni/arachni-1.4-0.5.10/bin/../system/usr/bin/phantomjs [!] [browser#spawn_phantomjs:1315] BrowserCluster Worker#30944180: Process spawned, waiting for it to boot-up... [!] [browser#spawn_phantomjs:1329] BrowserCluster Worker#30944180: Boot-up complete. [!] [browser#spawn_phantomjs:1337] BrowserCluster Worker#30944180: 8004: Started PID: 8007 8004: Working 8004: Working PhantomJS is launching GhostDriver... 8004: Working [INFO - 2016-07-15T06:33:38.681Z] GhostDriver - Main - running on port 59289 [!] [browser#spawn_phantomjs:1341] BrowserCluster Worker#30944180: PhantomJS is ready. [*] BrowserCluster: Spawned #4 with PID 8007 [lifeline at PID 8004]. [!!] [http/proxy_server#start_async:50] ProxyServer: Starting [!!] [http/proxy_server#start_async:63] ProxyServer: Started [!] [browser#spawn_phantomjs:1277] BrowserCluster Worker#30944180: Spawning PhantomJS... [!] [browser#spawn_phantomjs:1290] BrowserCluster Worker#30944180: Attempt #0, chose port number 24640 [!] [browser#spawn_phantomjs:1294] BrowserCluster Worker#30944180: Spawning process: /home/arachni/arachni-1.4-0.5.10/bin/../system/usr/bin/phantomjs [!] [browser#spawn_phantomjs:1315] BrowserCluster Worker#30944180: Process spawned, waiting for it to boot-up... [!] [browser#spawn_phantomjs:1329] BrowserCluster Worker#30944180: Boot-up complete. [!] [browser#spawn_phantomjs:1337] BrowserCluster Worker#30944180: 8027: Started PID: 8030 8027: Working 8027: Working PhantomJS is launching GhostDriver... 8027: Working [INFO - 2016-07-15T06:33:39.135Z] GhostDriver - Main - running on port 24640 [!] [browser#spawn_phantomjs:1341] BrowserCluster Worker#30944180: PhantomJS is ready. [*] BrowserCluster: Spawned #5 with PID 8030 [lifeline at PID 8027]. [!!] [http/proxy_server#start_async:50] ProxyServer: Starting [!!] [http/proxy_server#start_async:63] ProxyServer: Started [!] [browser#spawn_phantomjs:1277] BrowserCluster Worker#30944180: Spawning PhantomJS... [!] [browser#spawn_phantomjs:1290] BrowserCluster Worker#30944180: Attempt #0, chose port number 54935 [!] [browser#spawn_phantomjs:1294] BrowserCluster Worker#30944180: Spawning process: /home/arachni/arachni-1.4-0.5.10/bin/../system/usr/bin/phantomjs [!] [browser#spawn_phantomjs:1315] BrowserCluster Worker#30944180: Process spawned, waiting for it to boot-up... [!] [browser#spawn_phantomjs:1329] BrowserCluster Worker#30944180: Boot-up complete. [!] [browser#spawn_phantomjs:1337] BrowserCluster Worker#30944180: 8050: Started PID: 8053 8050: Working 8050: Working PhantomJS is launching GhostDriver... [INFO - 2016-07-15T06:33:39.636Z] GhostDriver - Main - running on port 54935 [!] [browser#spawn_phantomjs:1341] BrowserCluster Worker#30944180: PhantomJS is ready. [*] BrowserCluster: Spawned #6 with PID 8053 [lifeline at PID 8050]. [*] BrowserCluster: Initialization completed with 6 browsers in the pool. [~] Scheduled 302 redirection: http://10.0.2.15/DVWA-1.9/index.php => login.php [!] [session#logged_in?:285] Session: Performing login check. [!] [session#logged_in?:291] Session: Login check done: false [!] [session#logged_in?:294] Session: GET /DVWA-1.9/login.php HTTP/1.1 Host: 10.0.2.15 Accept-Encoding: gzip, deflate User-Agent: Arachni/v1.4 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.8,he;q=0.6 Cookie: security=impossible;PHPSESSID=1u1dgkb9281odkm9lfqhkr06s6 HTTP/1.1 200 OK Date: Fri, 15 Jul 2016 06:33:39 GMT Server: Apache/2.4.10 (Debian) Expires: Tue, 23 Jun 2009 12:00:00 GMT Cache-Control: no-cache, must-revalidate Pragma: no-cache Vary: Accept-Encoding Content-Encoding: gzip Content-Length: 722 Content-Type: text/html;charset=utf-8 Login :: Damn Vulnerable Web Application (DVWA) v1.9












[-] Session: The scanner has been logged out. [~] Session: Trying to re-login... [!!] [http/proxy_server#start_async:50] ProxyServer: Starting [!!] [http/proxy_server#start_async:63] ProxyServer: Started [!] [browser#spawn_phantomjs:1277] Browser: Spawning PhantomJS... [!] [browser#spawn_phantomjs:1290] Browser: Attempt #0, chose port number 19539 [!] [browser#spawn_phantomjs:1294] Browser: Spawning process: /home/arachni/arachni-1.4-0.5.10/bin/../system/usr/bin/phantomjs [!] [browser#spawn_phantomjs:1315] Browser: Process spawned, waiting for it to boot-up... [!] [browser#spawn_phantomjs:1329] Browser: Boot-up complete. [!] [browser#spawn_phantomjs:1337] Browser: 8073: Started PID: 8076 8073: Working 8073: Working PhantomJS is launching GhostDriver... 8073: Working [INFO - 2016-07-15T06:33:40.143Z] GhostDriver - Main - running on port 19539 [!] [browser#spawn_phantomjs:1341] Browser: PhantomJS is ready. [!] [session#login_from_configuration:326] Session: Logging in via configuration. [!] [session#login_from_configuration:329] Session: Logging in using browser. [!] [session#login_from_configuration:334] Session: Grabbing page at: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#load_cookies:1443] Browser: Setting cookies: ["security=impossible; Path=/DVWA-1.9/; HttpOnly", "PHPSESSID=1u1dgkb9281odkm9lfqhkr06s6; Path=/"] [!!!] [http/proxy_server/connection#initialize:33] Connection: Starting new connection: 22266840 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/login.php/set-cookies-55de739ce1aa88d2320f8a72cd7dbce6 [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php/set-cookies-55de739ce1aa88d2320f8a72cd7dbce6 [!!] [browser#request_handler:1575] Browser: Resource has been preloaded. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#goto:370] Browser: Loading http://10.0.2.15/DVWA-1.9/login.php ... [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 22266840 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/login.php [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1647] Browser: Checking: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1650] Browser: Allow: Scope enforcement disabled. [!!] [browser#request_handler:1582] Browser: Request can proceed to origin. [!!!] [http/proxy_server/connection#handle_request:99] Connection: -- Handler approves, running... [!!!] [http/proxy_server/connection#handle_request:107] Connection: -- ...completed in 0.003498: HTTP/1.1 200 OK [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#response_handler:1617] Browser: Injected custom JS. [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/polyfills.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/taint_tracer.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/dom_monitor.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#response_handler:1641] Browser: Stored. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:33] Connection: Starting new connection: 23821620 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/polyfills.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 22266840 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/dvwa/css/login.css [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#initialize:33] Connection: Starting new connection: 23817960 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/dvwa/css/login.css [!!] [browser#ignore_request?:1647] Browser: Checking: http://10.0.2.15/DVWA-1.9/dvwa/css/login.css [!!] [browser#ignore_request?:1650] Browser: Allow: Scope enforcement disabled. [!!] [browser#request_handler:1582] Browser: Request can proceed to origin. [!!!] [http/proxy_server/connection#handle_request:99] Connection: -- Handler approves, running... [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/polyfills.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/polyfills.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/dom_monitor.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:33] Connection: Starting new connection: 23815580 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/taint_tracer.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:107] Connection: -- ...completed in 0.003192: HTTP/1.1 200 OK [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://10.0.2.15/DVWA-1.9/dvwa/css/login.css [!!] [browser#response_handler:1617] Browser: Injected custom JS. [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 22266840 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/dvwa/images/login_logo.png [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/dvwa/images/login_logo.png [!!] [browser#ignore_request?:1647] Browser: Checking: http://10.0.2.15/DVWA-1.9/dvwa/images/login_logo.png [!!] [browser#ignore_request?:1650] Browser: Allow: Scope enforcement disabled. [!!] [browser#request_handler:1582] Browser: Request can proceed to origin. [!!!] [http/proxy_server/connection#handle_request:99] Connection: -- Handler approves, running... [!!!] [http/proxy_server/connection#handle_request:107] Connection: -- ...completed in 0.000316: HTTP/1.1 304 Not Modified [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://10.0.2.15/DVWA-1.9/dvwa/images/login_logo.png [!!] [browser#response_handler:1617] Browser: Injected custom JS. [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#goto:372] Browser: ...done. [!!] [browser#wait_till_ready:409] Browser: Waiting for custom JS... [!!] [browser#wait_till_ready:411] Browser: ...done. [!!] [browser#wait_for_pending_requests:1400] Browser: Waiting for 0 requests to complete... [!!] [browser#wait_for_pending_requests:1405] Browser: ...done. [!] [session#login_from_configuration:344] Session: Got page with URL http://10.0.2.15/DVWA-1.9/login.php [!] [session#login_from_configuration:360] Session: Found login form: form:post:http://10.0.2.15/DVWA-1.9/login.php:353957017509698694:996847763304354300 [!] [session#login_from_configuration:377] Session: Updated form inputs: {"username"=>"admin", "password"=>"password", "Login"=>"Login", "user_token"=>"11af8f794f9f3419ebb39bec8562a878"} [!] [session#login_from_configuration:381] Session: Submitting form. [!!] [browser#load_cookies:1443] Browser: Setting cookies: ["security=impossible; Path=/DVWA-1.9/; HttpOnly", "PHPSESSID=1u1dgkb9281odkm9lfqhkr06s6; Path=/"] [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 22266840 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/login.php/set-cookies-55de739ce1aa88d2320f8a72cd7dbce6 [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php/set-cookies-55de739ce1aa88d2320f8a72cd7dbce6 [!!] [browser#request_handler:1575] Browser: Resource has been preloaded. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#goto:370] Browser: Loading http://10.0.2.15/DVWA-1.9/login.php ... [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 22266840 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/login.php [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1647] Browser: Checking: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1650] Browser: Allow: Scope enforcement disabled. [!!] [browser#request_handler:1582] Browser: Request can proceed to origin. [!!!] [http/proxy_server/connection#handle_request:99] Connection: -- Handler approves, running... [!!!] [http/proxy_server/connection#handle_request:107] Connection: -- ...completed in 0.001773: HTTP/1.1 200 OK [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#response_handler:1617] Browser: Injected custom JS. [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/polyfills.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/taint_tracer.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/dom_monitor.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#response_handler:1641] Browser: Stored. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 23821620 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/polyfills.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/polyfills.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/polyfills.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 23817960 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/taint_tracer.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 23815580 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/dom_monitor.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#goto:372] Browser: ...done. [!!] [browser#wait_till_ready:409] Browser: Waiting for custom JS... [!!] [browser#wait_till_ready:411] Browser: ...done. [!!] [browser#wait_for_pending_requests:1400] Browser: Waiting for 0 requests to complete... [!!] [browser#wait_for_pending_requests:1405] Browser: ...done. [!] [page/dom#restore:174] Browser: Could not load snapshot by URL (http://10.0.2.15/DVWA-1.9/login.php), will load by replaying transitions. [!!] [browser#load_cookies:1443] Browser: Setting cookies: ["security=impossible; Path=/DVWA-1.9/; HttpOnly", "PHPSESSID=1u1dgkb9281odkm9lfqhkr06s6; Path=/"] [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 22266840 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/login.php/set-cookies-55de739ce1aa88d2320f8a72cd7dbce6 [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php/set-cookies-55de739ce1aa88d2320f8a72cd7dbce6 [!!] [browser#request_handler:1575] Browser: Resource has been preloaded. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#goto:370] Browser: Loading http://10.0.2.15/DVWA-1.9/login.php ... [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 22266840 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://10.0.2.15/DVWA-1.9/login.php [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1647] Browser: Checking: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1650] Browser: Allow: Scope enforcement disabled. [!!] [browser#request_handler:1582] Browser: Request can proceed to origin. [!!!] [http/proxy_server/connection#handle_request:99] Connection: -- Handler approves, running... [!!!] [http/proxy_server/connection#handle_request:107] Connection: -- ...completed in 0.002317: HTTP/1.1 200 OK [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#response_handler:1617] Browser: Injected custom JS. [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/polyfills.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/taint_tracer.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/dom_monitor.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#response_handler:1641] Browser: Stored. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 23821620 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/polyfills.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 23817960 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/taint_tracer.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 23815580 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/dom_monitor.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/polyfills.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/polyfills.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#goto:372] Browser: ...done. [!!] [browser#wait_till_ready:409] Browser: Waiting for custom JS... [!!] [browser#wait_till_ready:411] Browser: ...done. [!!] [browser#wait_for_pending_requests:1400] Browser: Waiting for 0 requests to complete... [!!] [browser#wait_for_pending_requests:1405] Browser: ...done. [!!] [browser#fire_event:720] Browser: [start]: submit ({:inputs=>{"username"=>"admin", "password"=>"password", "Login"=>"Login", "user_token"=>"11af8f794f9f3419ebb39bec8562a878"}})
[!!] [browser#fill_in_form_inputs:1195] Browser: Could not fill in form input 'Login' because: Error Message => 'Element must be user-editable in order to clear it.' caused by Request => {"headers":{"Accept":"application/json","Accept-Encoding":"gzip;q=1.0,deflate;q=0.6,identity;q=0.3","Connection":"close","Content-Length":"2","Content-Type":"application/x-www-form-urlencoded","Host":"127.0.0.1:19539","User-Agent":"Ruby"},"httpVersion":"1.1","method":"POST","post":"{}","postRaw":"{}","url":"/clear","urlParsed":{"anchor":"","query":"","file":"clear","directory":"/","path":"/clear","relative":"/clear","port":"","host":"","password":"","user":"","userInfo":"","authority":"","protocol":"","source":"/clear","queryKey":{},"chunks":["clear"]},"urlOriginal":"/session/116e4120-4a56-11e6-bad6-9b71db7468e8/element/%3Awdc%3A1468564421802/clear"} (ReqHand) [Selenium::WebDriver::Error::InvalidElementStateError [!!] [browser#fill_in_form_inputs:1195] Browser: Could not fill in form input 'user_token' because: Error Message => 'Element is not currently interactable and may not be manipulated' caused by Request => {"headers":{"Accept":"application/json","Accept-Encoding":"gzip;q=1.0,deflate;q=0.6,identity;q=0.3","Connection":"close","Content-Length":"2","Content-Type":"application/x-www-form-urlencoded","Host":"127.0.0.1:19539","User-Agent":"Ruby"},"httpVersion":"1.1","method":"POST","post":"{}","postRaw":"{}","url":"/clear","urlParsed":{"anchor":"","query":"","file":"clear","directory":"/","path":"/clear","relative":"/clear","port":"","host":"","password":"","user":"","userInfo":"","authority":"","protocol":"","source":"/clear","queryKey":{},"chunks":["clear"]},"urlOriginal":"/session/116e4120-4a56-11e6-bad6-9b71db7468e8/element/%3Awdc%3A1468564421803/clear"} (ReqHand) [Selenium::WebDriver::Error::InvalidElementStateError [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 22266840 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:43] Connection: Got 76 bytes. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: POST http://10.0.2.15/DVWA-1.9/login.php [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1647] Browser: Checking: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#ignore_request?:1650] Browser: Allow: Scope enforcement disabled. [!!] [browser#request_handler:1582] Browser: Request can proceed to origin. [!!!] [http/proxy_server/connection#handle_request:99] Connection: -- Handler approves, running... [!!!] [http/proxy_server/connection#handle_request:107] Connection: -- ...completed in 0.004818: HTTP/1.1 200 OK [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://10.0.2.15/DVWA-1.9/login.php [!!] [browser#response_handler:1617] Browser: Injected custom JS. [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/polyfills.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/taint_tracer.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#whitelist_asset_domains:1707] Browser: browser.arachni from http://javascript.browser.arachni/dom_monitor.js based on <\s*script.*?src=['"](.*?)['"].*?> [!!] [browser#response_handler:1641] Browser: Stored. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 23821620 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/polyfills.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/polyfills.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/polyfills.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 23817960 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/taint_tracer.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#initialize:31] Connection: Reusing connection: 23815580 [!!!] [http/proxy_server/connection#initialize:38] Connection: Incoming request. [!!!] [http/proxy_server/connection#initialize:51] Connection: Request received: GET http://javascript.browser.arachni/dom_monitor.js [!!!] [http/proxy_server/connection#handle_request:86] Connection: Processing request. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/dom_monitor.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#handle_request:90] Connection: -- Has special handler: # [!!] [browser#request_handler:1540] Browser: Request: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#request_handler:1553] Browser: Serving local JS. [!!!] [http/proxy_server/connection#handle_request:109] Connection: -- Handler did not approve, will not run. [!!!] [http/proxy_server/connection#handle_request:120] Connection: Processed request. [!!!] [http/proxy_server/connection#handle_response:131] Connection: Preparing response. [!!!] [http/proxy_server/connection#handle_response:141] Connection: -- Has special handler: # [!!] [browser#response_handler:1600] Browser: Got response: http://javascript.browser.arachni/taint_tracer.js [!!] [browser#response_handler:1623] Browser: Asset detected, will not store. [!!!] [http/proxy_server/connection#handle_response:169] Connection: Sending response. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!!] [http/proxy_server/connection#on_flush:200] Connection: Response sent. [!!] [browser#fire_event:766] Browser: [waiting for requests]: submit ({:inputs=>{"username"=>"admin", "password"=>"password", "Login"=>"Login", "user_token"=>"11af8f794f9f3419ebb39bec8562a878"}}) [!!] [browser#wait_for_pending_requests:1400] Browser: Waiting for 0 requests to complete... [!!] [browser#wait_for_pending_requests:1405] Browser: ...done. [!!] [browser#fire_event:768] Browser: [done waiting for requests]: submit ({:inputs=>{"username"=>"admin", "password"=>"password", "Login"=>"Login", "user_token"=>"11af8f794f9f3419ebb39bec8562a878"}}) [!!] [browser#fire_event:773] Browser: [done in 0.42625471s]: submit ({:inputs=>{"username"=>"admin", "password"=>"password", "Login"=>"Login", "user_token"=>"11af8f794f9f3419ebb39bec8562a878"}}) [!] [session#login_from_configuration:383] Session: Form submitted. [!!] [http/proxy_server#shutdown:68] ProxyServer: Shutting down.. [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [Arachni::Reactor::Connection::Error::Closed] end of file reached [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [Arachni::Reactor::Connection::Error::Closed] end of file reached [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [Arachni::Reactor::Connection::Error::Closed] end of file reached [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [Arachni::Reactor::Connection::Error::Closed] end of file reached [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [NilClass] [!!] [http/proxy_server#shutdown:73] ProxyServer: Shutdown. [!] [session#logged_in?:285] Session: Performing login check. [!] [session#logged_in?:291] Session: Login check done: false [!] [session#logged_in?:294] Session: GET /DVWA-1.9/login.php HTTP/1.1 Host: 10.0.2.15 Accept-Encoding: gzip, deflate User-Agent: Arachni/v1.4 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.8,he;q=0.6 Cookie: security=impossible;PHPSESSID=1u1dgkb9281odkm9lfqhkr06s6 HTTP/1.1 200 OK Date: Fri, 15 Jul 2016 06:33:42 GMT Server: Apache/2.4.10 (Debian) Expires: Tue, 23 Jun 2009 12:00:00 GMT Cache-Control: no-cache, must-revalidate Pragma: no-cache Vary: Accept-Encoding Content-Encoding: gzip Content-Length: 721 Content-Type: text/html;charset=utf-8 Login :: Damn Vulnerable Web Application (DVWA) v1.9












[-] Session: Could not re-login. [*] [HTTP: 302] http://10.0.2.15/DVWA-1.9/index.php [~] Analysis resulted in 0 usable paths. [~] DOM depth: 0 (Limit: 5) [!!] [http/proxy_server#shutdown:68] ProxyServer: Shutting down.. [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [NilClass] [!!] [http/proxy_server#shutdown:73] ProxyServer: Shutdown. [!!] [http/proxy_server#shutdown:68] ProxyServer: Shutting down.. [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [NilClass] [!!] [http/proxy_server#shutdown:73] ProxyServer: Shutdown. [!!] [http/proxy_server#shutdown:68] ProxyServer: Shutting down.. [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [NilClass] [!!] [http/proxy_server#shutdown:73] ProxyServer: Shutdown. [!!] [http/proxy_server#shutdown:68] ProxyServer: Shutting down.. [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [NilClass] [!!] [http/proxy_server#shutdown:73] ProxyServer: Shutdown. [!!] [http/proxy_server#shutdown:68] ProxyServer: Shutting down.. [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [NilClass] [!!] [http/proxy_server#shutdown:73] ProxyServer: Shutdown. [!!] [http/proxy_server#shutdown:68] ProxyServer: Shutting down.. [!!!] [http/proxy_server/connection#on_close:178] Connection: Closed because: [NilClass] [!!] [http/proxy_server#shutdown:73] ProxyServer: Shutdown. [!] [plugin/manager#block:161] [!] [plugin/manager#block:162] Waiting on 4 plugins to finish: [!] [plugin/manager#block:163] healthmap, timing_attacks, discovery, uniformity [!] [plugin/manager#block:164] ================================================================================ [+] Web Application Security Report - Arachni Framework [~] Report generated on: 2016-07-15 09:33:42 +0300 [~] Report false positives at: http://github.com/Arachni/arachni/issues [+] System settings: [~] --------------- [~] Version: 1.4 [~] Audit started on: 2016-07-15 09:33:34 +0300 [~] Audit finished on: 2016-07-15 09:33:42 +0300 [~] Runtime: 00:00:08 [~] URL: http://10.0.2.15/DVWA-1.9/index.php [~] User agent: Arachni/v1.4 [*] Audited elements: [~] * Links [~] * Forms [~] * Cookies [~] * XMLs [~] * JSONs [~] * UI inputs [~] * UI forms [*] Checks: [~] =========================== [+] 0 issues were detected. [+] Plugin data: [~] --------------- [*] AutoLogin [~] ~~~~~~~~~~~~~~ [~] Description: It looks for the login form in the user provided URL, merges its input fields with the user supplied parameters and sets the cookies of the response and request as framework-wide cookies. **NOTICE**: If the login form is by default hidden and requires a sequence of DOM interactions in order to become visible, this plugin will not be able to submit it. [+] The response did not match the verifier. [*] Health map [~] ~~~~~~~~~~~~~~ [~] Description: Generates a simple list of safe/unsafe URLs. [~] Legend: [+] No issues [-] Has issues [+] http://10.0.2.15/DVWA-1.9/index.php [~] Total: 1 [+] Without issues: 1 [-] With issues: 0 ( 0% ) [~] Report saved at: /home/arachni/arachni-1.4-0.5.10/bin/10.0.2.15 2016-07-15 09_33_42 +0300.afr [0.0MB] [~] The scan has logged errors: /home/arachni/arachni-1.4-0.5.10/bin/../system/logs/framework/error-7674.log [~] Audited 1 pages. [~] Duration: 00:00:08 [~] Processed 19/19 HTTP requests. [~] -- 77.941 requests/second. [~] Processed 0/0 browser jobs. [~] -- 0.0 second/job. [~] Currently auditing http://10.0.2.15/DVWA-1.9/index.php [~] Burst response time sum 0.004 seconds [~] Burst response count 2 [~] Burst average response time 0.002 seconds [~] Burst average 8.2 requests/second [~] Timed-out requests 0 [~] Original max concurrency 20 [~] Throttled max concurrency 20