<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/securitysoftware/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Scrawlr</title><link>http://www.communities.hp.com/securitysoftware/forums/198.aspx</link><description>Discussions related to the Scrawlr tool and it's use</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Scrawlr Rants and Raves</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/83393.aspx</link><pubDate>Wed, 25 Jun 2008 01:14:13 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83393</guid><dc:creator>erik.peterson</dc:creator><slash:comments>3</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/83393.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=83393</wfw:commentRss><description>&lt;p&gt;Let us know what you would like to see improved, questions on how best to use the tool or anything else. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>New download link for Scrawlr - 2009</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/92596.aspx</link><pubDate>Tue, 07 Jul 2009 13:30:11 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:92596</guid><dc:creator>HansEnders</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/92596.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=92596</wfw:commentRss><description>&lt;p&gt;The form/download link for the Scrawlr has been moved to:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="https://h30406.www3.hp.com/campaigns/2008/wwcampaign/1-57C4K/index.php?mcc=DNXA&amp;amp;jumpid=in_r11374_us/en/large/tsg/w1_0908_scrawlr_redirect/mcc_DNXA" class="external free" title="https://h30406.www3.hp.com/campaigns/2008/wwcampaign/1-57C4K/index.php?mcc=DNXA&amp;amp;jumpid=in_r11374_us/en/large/tsg/w1_0908_scrawlr_redirect/mcc_DNXA" rel="nofollow"&gt;https://h30406.www3.hp.com/campaigns/2008/wwcampaign/1-57C4K/index.php?mcc=DNXA&amp;amp;jumpid=in_r11374_us/en/large/tsg/w1_0908_scrawlr_redirect/mcc_DNXA&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The original link does not redirect:&amp;nbsp; &lt;a href="https://download.spidynamics.com/Products/scrawlr/" class="external free" title="https://download.spidynamics.com/Products/scrawlr/" rel="nofollow"&gt;https://download.spidynamics.com/Products/scrawlr/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Scrawlr &amp; HacmeBank</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/84173.aspx</link><pubDate>Thu, 07 Aug 2008 11:28:27 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:84173</guid><dc:creator>Walker-SRS</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/84173.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=84173</wfw:commentRss><description>&lt;p&gt;I ran Scrawlr against Foundstones HacMe Bank web site, which is riddled with SQL Injection vulnerabilities, and it came up with nothing.&lt;/p&gt;&lt;p&gt;&amp;nbsp;If the application cannot identify the base level vulnerabilities in a purposefully built vulnerable site, is it not leading others into a false sense of security?&lt;/p&gt;&lt;p&gt;&amp;nbsp;Or am I missing something? &lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Is Scrawlr unlawful to use?</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/83697.aspx</link><pubDate>Thu, 10 Jul 2008 20:28:02 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83697</guid><dc:creator>etaglio</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/83697.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=83697</wfw:commentRss><description>&lt;p&gt;Is it unlawful to enter a URL other than your own into the Scrawlr URL field?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Can the use of Scrawlr on a site the user doesn&amp;#39;t own be construed as an attempted attack on&amp;nbsp;that website?&amp;nbsp; Or is the software, in and of itself, harmless?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>1500 urls</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/84247.aspx</link><pubDate>Tue, 12 Aug 2008 17:56:59 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:84247</guid><dc:creator>voodoochicken</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/84247.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=84247</wfw:commentRss><description>&lt;p&gt;hi, does limited use to 1500 urls means this is shareware?&lt;/p&gt;&lt;p&gt;i mean, does it mean that after checking 1500 pages the tool will expire, or does it mean that it can only search 1500 pages in a single site&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;if the thing expires after 1500 uses, does it count 1 per each url or by each site? &lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Scrawlr FAQ</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/83373.aspx</link><pubDate>Mon, 23 Jun 2008 23:10:31 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83373</guid><dc:creator>billyhoffman</dc:creator><slash:comments>5</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/83373.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=83373</wfw:commentRss><description>&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: What is Scrawlr?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A:&lt;span&gt;&amp;nbsp; &lt;/span&gt;Scrawlr is a tool
that will crawl a website and audit it for SQL Injection vulnerabilities.
Specifically, Scrawlr is designed to detect SQL Injection vulnerabilities in
dynamic web pages that will be indexed by search engines.&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: Where can I download Scrawlr?&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: &lt;a href="https://download.spidynamics.com/Products/scrawlr/" title="Scrawlr download link"&gt;Download Scrawler Here&lt;/a&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font size="4"&gt;Q: Where can I see Scrawlr in action?&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;A: Here is a &lt;a href="https://download.spidynamics.com/Products/scrawlr/scrawler-screenshot.png"&gt;screen shot of Scrawlr&lt;/a&gt; in action&lt;br /&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: What is SQL Injection?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: SQL Injection is a common vulnerability in web
applications that allows an attacker to execute their own SQL commands on your
backend database system.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Typical attacks
include extracting confidential information, injecting malicious content, executing
stored procedures or operating system commands, and disabling or destroying the
database. You can learn more about SQL Injection by reading our whitepapers.&lt;/font&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: What kind of websites can Scrawlr test?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Scrawlr can be used to test virtually any kind of website
(provided you have permission to audit that website &lt;span style="font-family:Wingdings;"&gt;&lt;span&gt;J&lt;/span&gt;&lt;/span&gt;). Scrawlr does have several
limitations when compared to a traditional web vulnerability scanner &lt;span&gt;&amp;nbsp;&lt;/span&gt;which prevent it from crawling certain parts
of your web application. These limitations include:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;&lt;li class="MsoNormal" style="line-height:normal;"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;span&gt;No submission of web forms&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height:normal;"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;span&gt;Does not interpret JavaScript or Flash&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height:normal;"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;span&gt;Only tests for SQL Injection vulnerabilities and only
     tests the query string parameters of&lt;span&gt;&amp;nbsp;
     &lt;/span&gt;URLs&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height:normal;"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;span&gt;Does not keep state or use Cookies&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height:normal;"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;span&gt;Crawl limit of 1500 pages&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height:normal;"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;span&gt;No authentication support&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;&lt;span&gt;Q: Why doe&lt;/span&gt;s Scrawlr have these
limitations?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Over the last several months, hackers have been using
automated tools to perform mass exploitation of hundreds of thousands of
websites. The attackers are using Google to find web applications built using
Microsoft’s Active Server Pages and then performing SQL Injection attacks
against these sites injecting various types of malware which are subsequently served
to unsuspecting visitors. Scrawlr was specifically designed to help web
developers test their website for SQL injection vulnerabilities that could be
exposed to an attacker through a search engine. As such, Scrawlr crawls a
websites using the same techniques as a search engine: it doesn’t keep state,
or submit forms, or execute JavaScript or Flash. To fully test your web
application for SQL Injection and other web vulnerabilities requires the use of
a full featured web vulnerability scanner such as &lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200%5E14344_4000_100__" title="Download WebInspect"&gt;HP WebInspect&lt;/a&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;font size="4"&gt;Q: How do I know these vulnerabilities are real?&lt;/font&gt;&lt;/font&gt;

&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: When Scrawlr detects what it thinks is a SQL Injection
vulnerability, it will try to extract the database name and type, as well as
the names of all the user defined tables in the database. This proves that data
extraction is possible and that the SQL Injection vulnerability is real.&lt;/font&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: Is Scrawlr limited to auditing only sites built with
Microsoft’s ASP technology?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: No, Scrawlr will also audit PHP, ASP.NET, and JSP pages
that have query string parameters that are encountered during its search
engine-like crawl of the web application.&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: What specific technologies will Scrawlr crawl?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Scrawlr will crawl and audit any of the following file
extensions:&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;htm/html&lt;/li&gt;&lt;li&gt;asp&lt;/li&gt;&lt;li&gt;aspx&lt;/li&gt;&lt;li&gt;php/php3/php4&lt;/li&gt;&lt;li&gt;jsp&lt;/li&gt;&lt;li&gt;js&lt;/li&gt;&lt;li&gt;txt&lt;/li&gt;&lt;li&gt;cfm&lt;/li&gt;&lt;li&gt;any file without an extension&lt;/li&gt;&lt;/ul&gt;

&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: How much does Scrawlr Cost?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Scrawlr is a free tool created by HP’s Web Security
Research Group. It is experimental software and not officially supported by HP.&lt;/font&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font size="4"&gt;Q: Is the source code available for Scrawlr?&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;A: No.&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: Does Scrawlr support scanning a website through a proxy?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Yes, but Scrawlr only supports basic HTTP proxies that do
not require authentication.&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: Can Scrawlr scan web applications spread of many
different hostnames and subdomains?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Yes, you can configure Scrawlr to audit multiple hosts
using the “Allowed Hosts” option under the “Settings” menu. Please note that
you must enter the hostname exactly as it appears. Scrawlr also display disallowed
hostnames at the end of a scan, allowing you to start a new scan which will
audit those discovered hostnames.&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q:&lt;span&gt;&amp;nbsp; &lt;/span&gt;How can I get help
if I have problems with Scrawlr?&lt;/font&gt;&lt;/p&gt;







&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Scrawlr is released as experimental software and is not
officially supported by HP. However, we have set up a forum so Scrawlr users
can assist each other to work around issues.&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;font size="4"&gt;Q: Will this tool be supported or extended?&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: This is an unsupported tool in the sense that individual problems and bug reports may not be addressed.&amp;nbsp; However, the researchers who implemented the tool will actively read the forum postings, and there are plans to extend the tool in the future.&amp;nbsp; We would love to hear your thoughts and constructive criticisms on the forum.&lt;br /&gt;&lt;br /&gt;&lt;font size="4"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;font size="4"&gt;Q: Does Scrawlr find blind SQL injection vulnerabilities?&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: No.&amp;nbsp; The tool only checks for verbose SQL injection.&lt;br /&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Downloading Scrawlr outside of the US?</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/83408.aspx</link><pubDate>Wed, 25 Jun 2008 10:47:19 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83408</guid><dc:creator>aunitt</dc:creator><slash:comments>4</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/83408.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=83408</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;We&amp;#39;d love to try Scrawlr out, however the form to download it only accepts Postcodes (ZIP codes) and telephone numbers in US format.&lt;/p&gt;&lt;p&gt;&amp;nbsp;Can you open it up to the rest of the world?&lt;/p&gt;&lt;p&gt;&amp;nbsp;Thanks&lt;/p&gt;&lt;p&gt;&amp;nbsp;Ashley &lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>