Issues are reported only for first URL from list of URLs
I am currently using --scope-restrict-paths with my file containing 5 urls like
http://test.com/Users/getUserDetails?groupName=x&domain=x
http://test.com/Groups/getGroupDetails?groupName=x&domain=x
http://test.com/Groups/getMembershipDetails?domain=x&forGroup=x...
http://test.com/Users/getAuditsForUser?domain=x&forUser=x&p...
http://test.com/Groups/getAuditsForGroup?domain=x&forUser=x&...
Interestingly the issues are reported only for the first URL in the list, although it exists in all URLs. If I change the order, it again reports for the top one. Am I missing something ? My command line invocation is like
./arachni http://test.com --output-debug 4 --scope-restrict-paths urlList.txt --checks "*xss*"
-Thanks
Comments are currently closed for this discussion. You can start a new one.
Keyboard shortcuts
Generic
? | Show this help |
---|---|
ESC | Blurs the current field |
Comment Form
r | Focus the comment reply box |
---|---|
^ + ↩ | Submit the comment |
You can use Command ⌘
instead of Control ^
on Mac
Support Staff 1 Posted by Tasos Laskos on 27 Jul, 2016 12:37 PM
This shouldn't be happening, any chance I can get access to that site to try and reproduce the issue?
2 Posted by Varun on 27 Jul, 2016 12:50 PM
Thanks for a quick response.
Unfortunately, this is an internal application so I cannot give you access. I updated my file to only two urls and ran two invocation with different order of urls
First invocation
When I change the order without any change in command invocation, I get the following result
Support Staff 3 Posted by Tasos Laskos on 27 Jul, 2016 02:33 PM
I think I fixed the bug, I'm updating the nightlies so you can test them.
4 Posted by Varun on 27 Jul, 2016 05:50 PM
Thanks Tasos.
It works fine with nightlies. Great !!
Support Staff 5 Posted by Tasos Laskos on 27 Jul, 2016 05:51 PM
Forgot to let you know they were up, but glad to know they fixed the issue.
Thanks for the feedback.
Tasos Laskos closed this discussion on 27 Jul, 2016 05:51 PM.