Custom Scripts / Scans

Franna's Avatar

Franna

19 May, 2016 11:04 AM

Hi. I am keen to understand how I can create custom test scripts in Arachni. Is there any documentation available regarding this?

  1. Support Staff 1 Posted by Tasos Laskos on 19 May, 2016 02:47 PM

    Tasos Laskos's Avatar

    Hello,

    I'm not sure what your goal is, could you please describe what you want to achieve?

    Cheers

  2. 2 Posted by Francois Marais on 20 May, 2016 05:47 AM

    Francois Marais's Avatar

    Hi Tasos

    Herewith my scenario:

    As a secops member responsible for regression testing of our web application
    I want to only test and report on the relevant findings I know about
    by providing a custom script or policy containing the URL's,
    parameters and data needed to perform regression testing.
    So that I only report on the findings of interest and relevance to me
    and the team.
    So that I can create my own test criteria and use Arachni to scan my
    web applications and report on my own test criteria.

    Hope this helps.

    Sent from Nine
    ________________________________

  3. Support Staff 3 Posted by Tasos Laskos on 20 May, 2016 05:49 AM

    Tasos Laskos's Avatar

    If I understand correctly, you want to perform an initial full scan and then verify that the identified and fixed issues stay fixed?

  4. 4 Posted by Francois Marais on 20 May, 2016 05:55 AM

    Francois Marais's Avatar

    The scenario applies to both auotamted test results / full scan and
    custom criteria, ie. test that requires the creation of a custom
    script / policy. Example: Testing for a specific value or response
    should trigger an event / report entry based on custom test criteria.

    Sent from Nine
    ________________________________

  5. Support Staff 5 Posted by Tasos Laskos on 20 May, 2016 05:58 AM

    Tasos Laskos's Avatar

    The easier way to control Arachni is via the REST API.
    You can use that to script scans in whatever way you like.

  6. Tasos Laskos closed this discussion on 03 Aug, 2016 02:28 PM.

Comments are currently closed for this discussion. You can start a new one.

Keyboard shortcuts

Generic

? Show this help
ESC Blurs the current field

Comment Form

r Focus the comment reply box
^ + ↩ Submit the comment

You can use Command ⌘ instead of Control ^ on Mac