分享web开发知识

注册/登录|最近发布|今日推荐

主页 IT知识网页技术软件开发前端开发代码编程运营维护技术分享教程案例
当前位置:首页 > 前端开发

Web安全扫描工具-Arachni

发布时间:2023-09-06 01:07责任编辑:郭大石关键词:Web

Arachni是一个多功能、模块化、高性能的Ruby框架,旨在帮助渗透测试人员和管理员评估web应用程序的安全性。同时Arachni开源免费,可安装在windows、linux以及mac系统上,并且可导出评估报告。

一、Arachni下载与启动,以LInux环境为例

下载地址:http://www.arachni-scanner.com/download/

解压文件arachni-1.5.1-0.5.12-darwin-x86_64.tar.gz,然后进入arachni-1.5.1-0.5.12目录下的bin文件夹,运行./arachni_web,随后浏览器访问http://localhost:9292

二、Arachni配置扫描

Arachni目录里有关于该工具的简单使用说明,也可以找到安装后的初始用户名和密码

tdcqma:arachni-1.5.1-0.5.12 $ lsLICENSETROUBLESHOOTINGbinREADMEVERSIONsystemtdcqma:arachni-1.5.1-0.5.12 $ cat README ???Arachni - Web Application Security Scanner FrameworkHomepage ??????????- http://arachni-scanner.comBlog ??????????????- http://arachni-scanner.com/blogDocumentation ?????- https://github.com/Arachni/arachni/wikiSupport ???????????- http://support.arachni-scanner.comGitHub page ???????- http://github.com/Arachni/arachniCode Documentation - http://rubydoc.info/github/Arachni/arachniAuthor ????????????- Tasos "Zapotek" Laskos (http://twitter.com/Zap0tek)Twitter ???????????- http://twitter.com/ArachniScannerCopyright ?????????- 2010-2017 Sarosys LLCLicense ???????????- Arachni Public Source License v1.0 -- see LICENSE file)--------------------------------------------------------------------------------To use Arachni run the executables under "bin/".To launch the Web interface: ???bin/arachni_webDefault account details: ???Administrator: ???????E-mail address: admin@admin.admin ???????Password: ??????administrator ???User: ???????E-mail address: user@user.user ???????Password: ??????regular_userFor a quick scan: via the command-line interface: ???bin/arachni http://test.comTo see the available CLI options: ???bin/arachni -hFor detailed documentation see: ???http://arachni-scanner.com/wiki/User-guideUpgrading/migrating--------------To migrate your existing data into this new package please see: ???https://github.com/Arachni/arachni-ui-web/wiki/upgradingTroubleshooting--------------See the included TROUBLESHOOTING file.Disclaimer--------------Arachni is free software and you are allowed to use it as you see fit.However, I can‘t be held responsible for your actions or for any damagecaused by the use of this software.Copying--------------For the Arachni license please see the LICENSE file.The bundled PhantomJS (http://phantomjs.org/) executable is distributedunder the BSD license: ???https://github.com/ariya/phantomjs/blob/master/LICENSE.BSDtdcqma:arachni-1.5.1-0.5.12 $ 

 浏览器访问http://localhost:9292,进入登录页面

登录后点击右上角的Administrator-》Edit account进行修改默认密码

新建扫描,Scans-》+New并配置扫描选项,安全策略包括XSS、SQL注入等,默认情况下选Default即可。

扫描结果分析,检出弱点总数及漏洞分类一览

点击awaiting review进入漏洞详细说明界面

报告导出,以HTML格式为例

 查看报告,包括总结图表及漏洞详细说明

Web安全扫描工具-Arachni

原文地址:http://www.cnblogs.com/tdcqma/p/7517313.html

知识推荐

我的编程学习网——分享web前端后端开发技术知识。 垃圾信息处理邮箱 tousu563@163.com 网站地图
icp备案号 闽ICP备2023006418号-8 不良信息举报平台 互联网安全管理备案 Copyright 2023 www.wodecom.cn All Rights Reserved