[vortiz@redhattest miagent]$ arachni --checks - --plugin=login_script:script=login2.rb --browser-cluster-pool-size='4' --browser-cluster-job-timeout='30' http://dev-miu-rs.miutility.com Arachni - Web Application Security Scanner Framework v2.0dev Author: Tasos "Zapotek" Laskos (With the support of the community and the Arachni Team.) Website: http://arachni-scanner.com Documentation: http://arachni-scanner.com/wiki [~] No element audit options were specified, will audit links, forms, cookies, UI inputs, UI forms, JSONs and XMLs. [*] Initializing... [*] Preparing plugins... [~] Login script: Running the script. https://miutilityadfs.miutilityadfs.com/adfs/oauth2/authorize?response_type=id_token&client_id=0174c6a8-24b0-4760-95e8-c0224d73f006&redirect_uri=http%3A%2F%2Fdev-miu-rs.miutility.com%2F&state=a8e95136-2003-4f0d-9901-734acd1d2c3e&client-request-id=23cf3bf5-13cb-4350-8b45-7d82b44dbf87&x-client-SKU=Js&x-client-Ver=1.0.10&nonce=a22d2d6a-c39c-4b80-b4c6-a028581a9bec http://dev-miu-rs.miutility.com/miagent/launch-pad [~] Login script: Execution completed. [+] Login script: Login was successful. [~] Login script: Cookies set to: [~] Login script: * "MSISAuth" = "AAEAAFd osW05m9ym7a5BlGcTZI9Dn/LtngeOAohH5grr/BLLMe60RxOkIvcuqaXBGQtAQKh5GWQNcijusnPfEHzuCPMtcJQ460tyUPOTdmwbGELSJZ5fmu6nAhd27N2Uel8TGpdQ/S0o M8 YxHaCnxB8qYib3 WJ hhgEKyymnwBSWJw87JjTCE9L7PN1 jN2O/rfLPGYgB7H/9WDpkNKs9VvBHrE6FuzVXM04ikD1MUK4DYBscEBgg43rfo9ghthQobhjHVEH2vwsECByq9e/DxcYjZm3OwBNfieJtXsAAHwwq0k7T0M nT3epw YkJ5Qu9ip0letgBbAmWeK3KvJYNU55wnpRSC3ieQmPLu2rV3/450DgaI8kPxz00TkEAkVKwABAACyBPKkND3IrX6id2HOf5HS8oLRHbD0yBx8rIPG8ylISejYDGZfld7M43t6om8WdX7Ur0yxuibic3G7uipaNAXOYZ6nsDhLgDnI6PnpegwJ4jGs33HxHdEFLG8EzVP7YgYx2tLs3n mQ/hjcwQjW49mMjg0EYLP1soM fp YuQjsQMIPTbMK3ROh94cr/nB/XgXc X3wNH4bd8sIvAf4Jh7fff4pnVrOCaU3pb8VeJ0B8j39wA8y65Tjcs3yUZ5PKJywbu4g7wgC/YTYJn8gMj/Kgwr4Qzmmi CCfmZD/QmCfGcel7YRi3QmHFbl1exv11f2a3FWUlOafpOw4xu9sKzIAMAAJpTGb6UXK6DtNlt6YHV3wxhcPl0yvVVotYJapMA qpxvM3jGC0icLPp5bjOPqxdfgZKScppP3tAR2OS/lnyqNywq oc3pXiBFHBNlunDU0gbVgjZ5VGj x23AOQp7IuUseAhXoRvR nvjdaLFVnsJTGiIj07j/GbVKCTz9kLIF0rVFmgsTNnjzeeS6FzN6idR pgVpg3/UobCmhNjT0ec1BDoCArbUD48VAuQp0B3w0icqbMXaJLFjgjrd8BahMphSzI5Ss8DCBaLzw/ON8v1WN8qy4g4pgcmoVW0T1BOMcWm8n1E9A69pg0qQQ2rXIYAUFsdTaWIWrcumFuXR6GxIr8l9FyQm/wyK3Fv Rw2FKY3zVcD87kYr2JY2IVWZPm9ezdem7phUjeTJ3osNi5TPsfl6GM8KADFepg6D7TC80ia1H1erR Kuv0TM7qOC/G9LarsxyT9 UNsKRAEhCWm5pKJ3YvpeHyn3KdMx/uKjia/SGGuWByEYGAC9v3ds7X4Vc FgzLiDNGh69hQoUcENZiXZymPGPfLZiZQYQ0FEwVjrIiyDSHA7aQCwveLsVaKnpFji5Ja FL/JL09CiJJHwgEAU4yDglv62eele0FokOzb9CjAcnihcepudEQDaBnqoqpKSYFMUJ3tDuSj9dQeOtKnnyHYSueJNeEiR5VQ8r/zVkHbVKb8jOeht/gEwpcjJ2Ng3O2aEB0W8Rs2cVj0QYa8aEJbtraZLtS3uQ/lzs4JPurlV9/vF0OhqCx7EOQ/New W4uS/uV42Cgjqmu/SqN1Tf9Ul5XJC7ngWDofCKfUhE a1PEClk0yS4j2LGIHHVW2dkNqJt2SdgLRl1E/VZcRnPzBDX6Cm49TA/REq5lzgto7oRdappXO1gnwJ4jKCX7x mkDix 6BqaMpFBwrOxDKyqLlYRnWKd61gaLBEoVvvs5xddDCTyOtRhIfG2SSmMd6jK5A8VCBTS97qtsYBAYywppG2qF8siD0x7bhpEi/Vyi6pFC/xB4bSEA29FOoizrtvPeAJGXr4vVz8POQmRVZ6JSr3U2JIHYOQJtB" [~] Login script: * "MSISAuthenticated" = "NC8xNi8yMDE3IDQ6MTU6MjkgQU0=" [~] Login script: * "MSISLoopDetectionCookie" = "MjAxNy0wNC0xNjowNDoxNToxN1pcMg==" [~] Login script: * "access_token" = "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6IjFPTmlzMU1lUHg5QXRfMlB6UjQ1WW1YN1ZqQSJ9.eyJhdWQiOiJodHRwOi8vd3d3Lm1pdXRpbGl0eS5jb20vZ2F0ZXdheSIsImlzcyI6Imh0dHBzOi8vbWl1dGlsaXR5YWRmcy5taXV0aWxpdHlhZGZzLmNvbS9hZGZzL3NlcnZpY2VzL3RydXN0IiwiaWF0IjoxNDkyMzE2MTI5LCJleHAiOjE0OTIzMTk3MjksInVuaXF1ZV9uYW1lIjoidnNoaW5kZSIsImFwcHR5cGUiOiJQdWJsaWMiLCJhcHBpZCI6IjAxNzRjNmE4LTI0YjAtNDc2MC05NWU4LWMwMjI0ZDczZjAwNiIsImF1dGhtZXRob2QiOiJ1cm46b2FzaXM6bmFtZXM6dGM6U0FNTDoyLjA6YWM6Y2xhc3NlczpQYXNzd29yZFByb3RlY3RlZFRyYW5zcG9ydCIsImF1dGhfdGltZSI6IjIwMTctMDQtMTZUMDQ6MTU6MTcuMzA4WiIsInZlciI6IjEuMCJ9.YCKAsBrRhd6umIw9ZQkm2Iohhrb5_1Jbw_bzJ9bnq0TtnTIYnuR5j4cRljLTt_829YSiOuNlJK8VedUgcarH90N_Uh-XK70WBKItiE-YjcjTJdD13nErKosYGAqyb2U54HOMU4CQ-C523qTaEkCwcKrl_UUHO9_BRyWsc3Op9JLuKpeGWgQySdYoPjj5EJsfC7rwUMjcjt1yoh8SbItf_ZNZnYa_nW0ouo4YOp6Iviypfc-aNzGPVAwrJOrH95FKcXYZ5pMLoAFH2pFyMrepHbmEo9Os8pCuMxSgx6vq3jCEtsc7mV3C5oTG1dbNjMCfGsL0KXX8mQ_bckVBRBOGFA" [*] ... done. [*] BrowserCluster: Initializing 4 browsers... [*] BrowserCluster: Spawned #1 with PID 10760 [lifeline at PID 10755]. [*] BrowserCluster: Spawned #2 with PID 10785 [lifeline at PID 10782]. [*] BrowserCluster: Spawned #3 with PID 10812 [lifeline at PID 10807]. [*] BrowserCluster: Spawned #4 with PID 10837 [lifeline at PID 10834]. [*] BrowserCluster: Initialization completed with 4 browsers in the pool. [*] [HTTP: 200] http://dev-miu-rs.miutility.com/ [~] Identified as: windows, iis, asp, aspx [~] Analysis resulted in 0 usable paths. [~] DOM depth: 0 (Limit: 5) [*] Workload exhausted, waiting for new pages from the browser-cluster... [~] BrowserCluster: Pending jobs: 1 [*] Got new page from the browser-cluster: http://dev-miu-rs.miutility.com/login [~] DOM depth: 1 (Limit: 5) [~] Transitions: [~] -- [15.7250s] load => page (http://dev-miu-rs.miutility.com/) [~] * [0.1000s] request => http://dev-miu-rs.miutility.com/ [~] * [0.1015s] request => http://dev-miu-rs.miutility.com/settings/get [~] * [0.0932s] request => http://dev-miu-rs.miutility.com/feature/get [~] * [0.1000s] request => http://dev-miu-rs.miutility.com/login [~] * [0.1001s] request => http://dev-miu-rs.miutility.com/settings/get [*] [HTTP: 200] http://dev-miu-rs.miutility.com/login [~] Identified as: windows, iis, asp, aspx [~] Analysis resulted in 0 usable paths. [~] DOM depth: 1 (Limit: 5) [~] Transitions: [~] -- [15.7250s] load => page (http://dev-miu-rs.miutility.com/) [~] * [0.1000s] request => http://dev-miu-rs.miutility.com/ [~] * [0.1015s] request => http://dev-miu-rs.miutility.com/settings/get [~] * [0.0932s] request => http://dev-miu-rs.miutility.com/feature/get [~] * [0.1000s] request => http://dev-miu-rs.miutility.com/login [~] * [0.1001s] request => http://dev-miu-rs.miutility.com/settings/get [*] Workload exhausted, waiting for new pages from the browser-cluster... [~] BrowserCluster: Pending jobs: 2 [~] BrowserCluster: Pending jobs: 10 [~] Worker: Retrying (1/6) due to time out: # time= timed_out=false> [~] Worker: Retrying (1/6) due to time out: # @event=:click @element=