+ /opt/arachni-nightly/arachni-2.0dev-1.0dev/bin/arachni http://example.com:9966/petclinic/owners --scope-include-pattern=/petclinic/owners* --input-value=lastName:black --checks=sql_injection_differential --plugin=uniformity --plugin=timing_attacks --browser-cluster-pool-size=2 Arachni - Web Application Security Scanner Framework v2.0dev Author: Tasos "Zapotek" Laskos (With the support of the community and the Arachni Team.) Website: http://arachni-scanner.com Documentation: http://arachni-scanner.com/wiki [~] No element audit options were specified, will audit links, forms, cookies, UI inputs, UI forms, JSONs and XMLs. [*] Initializing... [*] Preparing plugins... [*] ... done. [*] BrowserCluster: Initializing 2 browsers... [*] BrowserCluster: Spawned #1 with PID 6976 [lifeline at PID 6973]. [*] BrowserCluster: Spawned #2 with PID 7000 [lifeline at PID 6997]. [*] BrowserCluster: Initialization completed with 2 browsers in the pool. [*] [HTTP: 200] http://example.com:9966/petclinic/owners [~] Identified as: tomcat, java [~] Analysis resulted in 3 usable paths. [~] DOM depth: 0 (Limit: 5) [*] Harvesting HTTP responses... [~] Depending on server responsiveness and network conditions this may take a while. [*] [HTTP: 200] http://example.com:9966/petclinic/owners.html [~] Identified as: tomcat, java [~] Analysis resulted in 0 usable paths. [~] DOM depth: 0 (Limit: 5) [*] [HTTP: 200] http://example.com:9966/petclinic/owners/find.html [~] Identified as: tomcat, java [~] Analysis resulted in 0 usable paths. [~] DOM depth: 0 (Limit: 5) [*] [HTTP: 200] http://example.com:9966/petclinic/owners/new [~] Identified as: tomcat, java [~] Analysis resulted in 0 usable paths. [~] DOM depth: 0 (Limit: 5) [*] Harvesting HTTP responses... [~] Depending on server responsiveness and network conditions this may take a while. [*] Workload exhausted, waiting for new pages from the browser-cluster... [~] BrowserCluster: Pending jobs: 4 [*] Got new page from the browser-cluster: http://example.com:9966/petclinic/owners.html [~] DOM depth: 1 (Limit: 5) [~] Transitions: [~] -- [0.5660s] load => page (http://example.com:9966/petclinic/owners.html) [~] * [0.0999s] request => http://example.com:9966/petclinic/owners.html [~] * [0.0052s] request => http://example.com:9966/petclinic/resources/css/petclinic.css [~] * [0.1048s] request => http://example.com:9966/petclinic/vendors/jquery-ui/themes/base/minified/jquery-ui.min.css [~] * [0.1028s] request => http://example.com:9966/petclinic/vendors/jquery-ui/themes/base/minified/jquery.ui.theme.min.css [~] * [0.1001s] request => http://example.com:9966/petclinic/vendors/jquery-ui/themes/base/minified/jquery.ui.datepicker.min.css [~] * [0.0989s] request => http://example.com:9966/petclinic/vendors/jquery/jquery.min.js [~] * [0.0154s] request => http://example.com:9966/petclinic/vendors/jquery-ui/ui/jquery.ui.core.js [~] * [0.0147s] request => http://example.com:9966/petclinic/vendors/jquery-ui/ui/jquery.ui.datepicker.js [~] * [0.0137s] request => http://example.com:9966/petclinic/resources/images/spring-pivotal-logo.png [~] * [0.0091s] request => http://example.com:9966/petclinic/vendors/bootstrap/dist/js/bootstrap.min.js [~] * [0.0054s] request => http://example.com:9966/petclinic/resources/images/spring-logo-dataflow.png [*] [HTTP: 200] http://example.com:9966/petclinic/owners.html [~] Identified as: tomcat, java [~] Analysis resulted in 0 usable paths. [~] DOM depth: 1 (Limit: 5) [~] Transitions: [~] -- [0.5660s] load => page (http://example.com:9966/petclinic/owners.html) [~] * [0.0999s] request => http://example.com:9966/petclinic/owners.html [~] * [0.0052s] request => http://example.com:9966/petclinic/resources/css/petclinic.css [~] * [0.1048s] request => http://example.com:9966/petclinic/vendors/jquery-ui/themes/base/minified/jquery-ui.min.css [~] * [0.1028s] request => http://example.com:9966/petclinic/vendors/jquery-ui/themes/base/minified/jquery.ui.theme.min.css [~] * [0.1001s] request => http://example.com:9966/petclinic/vendors/jquery-ui/themes/base/minified/jquery.ui.datepicker.min.css [~] * [0.0989s] request => http://example.com:9966/petclinic/vendors/jquery/jquery.min.js [~] * [0.0154s] request => http://example.com:9966/petclinic/vendors/jquery-ui/ui/jquery.ui.core.js [~] * [0.0147s] request => http://example.com:9966/petclinic/vendors/jquery-ui/ui/jquery.ui.datepicker.js [~] * [0.0137s] request => http://example.com:9966/petclinic/resources/images/spring-pivotal-logo.png [~] * [0.0091s] request => http://example.com:9966/petclinic/vendors/bootstrap/dist/js/bootstrap.min.js [~] * [0.0054s] request => http://example.com:9966/petclinic/resources/images/spring-logo-dataflow.png [*] Workload exhausted, waiting for new pages from the browser-cluster... [~] BrowserCluster: Pending jobs: 44 [*] Got new page from the browser-cluster: http://example.com:9966/petclinic/owners/new [~] DOM depth: 1 (Limit: 5) [~] Transitions: [~] -- [0.3762s] load => page (http://example.com:9966/petclinic/owners/new) [~] * [0.1000s] request => http://example.com:9966/petclinic/owners/new [*] Got new page from the browser-cluster: http://example.com:9966/petclinic/owners/find.html [~] DOM depth: 1 (Limit: 5) [~] Transitions: [~] -- [0.4746s] load => page (http://example.com:9966/petclinic/owners/find.html) [~] * [0.0999s] request => http://example.com:9966/petclinic/owners/find.html [*] [HTTP: 200] http://example.com:9966/petclinic/owners/new [~] Identified as: tomcat, java [~] Analysis resulted in 0 usable paths. [~] DOM depth: 1 (Limit: 5) [~] Transitions: [~] -- [0.3762s] load => page (http://example.com:9966/petclinic/owners/new) [~] * [0.1000s] request => http://example.com:9966/petclinic/owners/new [*] [HTTP: 200] http://example.com:9966/petclinic/owners/find.html [~] Identified as: tomcat, java [~] Analysis resulted in 0 usable paths. [~] DOM depth: 1 (Limit: 5) [~] Transitions: [~] -- [0.4746s] load => page (http://example.com:9966/petclinic/owners/find.html) [~] * [0.0999s] request => http://example.com:9966/petclinic/owners/find.html [*] Workload exhausted, waiting for new pages from the browser-cluster... [~] BrowserCluster: Pending jobs: 68 [~] BrowserCluster: Pending jobs: 66 [~] BrowserCluster: Pending jobs: 65 [~] BrowserCluster: Pending jobs: 64 [~] BrowserCluster: Pending jobs: 63 [~] BrowserCluster: Pending jobs: 62 [~] BrowserCluster: Pending jobs: 61 [~] BrowserCluster: Pending jobs: 60 [~] BrowserCluster: Pending jobs: 59 [~] BrowserCluster: Pending jobs: 58 [~] BrowserCluster: Pending jobs: 57 [~] BrowserCluster: Pending jobs: 56 [~] BrowserCluster: Pending jobs: 55 [~] BrowserCluster: Pending jobs: 54 [~] BrowserCluster: Pending jobs: 53 [~] BrowserCluster: Pending jobs: 52 [~] BrowserCluster: Pending jobs: 51 [~] BrowserCluster: Pending jobs: 50 [~] BrowserCluster: Pending jobs: 49 [~] BrowserCluster: Pending jobs: 48 [~] BrowserCluster: Pending jobs: 46 [~] BrowserCluster: Pending jobs: 45 [~] BrowserCluster: Pending jobs: 44 [~] BrowserCluster: Pending jobs: 43 [~] BrowserCluster: Pending jobs: 42 [~] BrowserCluster: Pending jobs: 41 [~] BrowserCluster: Pending jobs: 40 [~] BrowserCluster: Pending jobs: 39 [~] BrowserCluster: Pending jobs: 38 [~] BrowserCluster: Pending jobs: 37 [~] BrowserCluster: Pending jobs: 36 [~] BrowserCluster: Pending jobs: 35 [~] BrowserCluster: Pending jobs: 34 [~] BrowserCluster: Pending jobs: 33 [~] BrowserCluster: Pending jobs: 32 [~] BrowserCluster: Pending jobs: 31 [~] BrowserCluster: Pending jobs: 30 [~] BrowserCluster: Pending jobs: 29 [~] BrowserCluster: Pending jobs: 28 [~] BrowserCluster: Pending jobs: 27 [~] BrowserCluster: Pending jobs: 26 [~] BrowserCluster: Pending jobs: 25 [~] BrowserCluster: Pending jobs: 24 [~] BrowserCluster: Pending jobs: 23 [~] BrowserCluster: Pending jobs: 21 [~] BrowserCluster: Pending jobs: 19 [~] BrowserCluster: Pending jobs: 18 [~] BrowserCluster: Pending jobs: 17 [~] BrowserCluster: Pending jobs: 16 [~] BrowserCluster: Pending jobs: 15 [~] BrowserCluster: Pending jobs: 14 [~] BrowserCluster: Pending jobs: 13 [~] BrowserCluster: Pending jobs: 12 [~] BrowserCluster: Pending jobs: 11 [~] BrowserCluster: Pending jobs: 9 [~] BrowserCluster: Pending jobs: 7 [~] BrowserCluster: Pending jobs: 6 [~] BrowserCluster: Pending jobs: 5 [~] BrowserCluster: Pending jobs: 4 [*] Got new page from the browser-cluster: http://example.com:9966/petclinic/owners/new [~] DOM depth: 2 (Limit: 5) [~] Transitions: [~] -- [0.3762s] load => page (http://example.com:9966/petclinic/owners/new) [~] * [0.1000s] request => http://example.com:9966/petclinic/owners/new [~] -- [0.3433s] click =>