<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/securitysoftware/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Scrawlr</title><link>http://www.communities.hp.com/securitysoftware/forums/198.aspx</link><description>Discussions related to the Scrawlr tool and it's use</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Re: Scrawlr FAQ</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/83439.aspx</link><pubDate>Thu, 26 Jun 2008 02:52:08 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83439</guid><dc:creator>nt-jp</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/83439.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=83439</wfw:commentRss><description>&lt;p&gt;I have tried Scrawlr on Japanese environment.&amp;nbsp; &lt;/p&gt;&lt;p&gt;It dosen&amp;#39;t seem that Scrawlr can analyse Japanese error messages.&lt;/p&gt;&lt;p&gt;Do you have a plan to support Japanese envirionment?&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Scrawlr FAQ</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/83423.aspx</link><pubDate>Wed, 25 Jun 2008 16:47:36 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83423</guid><dc:creator>billyhoffman</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/83423.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=83423</wfw:commentRss><description>&lt;p&gt;WE have fixed the download page. The postal field will now accept international postal codes using the characters: letters, numbers, spaces, and dashes. Sorry about the mix up.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Scrawlr FAQ</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/83399.aspx</link><pubDate>Wed, 25 Jun 2008 06:45:04 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83399</guid><dc:creator>enzotoc</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/83399.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=83399</wfw:commentRss><description>&lt;p&gt;Hi, i&amp;#39;m an italian developer and I have a similar problem, i don&amp;#39;t download Scrawlr because the form don&amp;#39;t accept phone number. I try with +39xxx or 0039xxx but nothing. Can I have help ?&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Scrawlr FAQ</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/83394.aspx</link><pubDate>Wed, 25 Jun 2008 02:43:05 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83394</guid><dc:creator>Anonymous-HPBLOGCS</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/83394.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=83394</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Silly HP systems! Sorry bsanders that IT&amp;#39;s systems are so rude to those in Canada. Just enter a US zip like 30068. I&amp;#39;ll go take the &amp;quot;encouragement&amp;quot; bat down to NOC tomorrow and get this fixed. Sorry about the confusion! &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Scrawlr FAQ</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/83390.aspx</link><pubDate>Tue, 24 Jun 2008 22:30:51 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83390</guid><dc:creator>bsanders</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/83390.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=83390</wfw:commentRss><description>&lt;p&gt;When I try to &amp;quot;register&amp;quot; to download Scrawlr at &lt;a href="https://download.spidynamics.com/Products/scrawlr/"&gt;https://download.spidynamics.com/Products/scrawlr/&lt;/a&gt;, I key my correct - Canadian - Postal Code (V8T 4Y2) but get told this is not a valid Postal Code and can not complete the &amp;quot;registration&amp;quot; and thus can not download Scrawlr.&lt;/p&gt;
&lt;p&gt;I tried using all lower case and&amp;nbsp;not keying the space (v8t4y2, V8T4Y2, v8t 4y2)), but&amp;nbsp;nothing I tried worked.&lt;/p&gt;
&lt;p&gt;How do I&amp;nbsp;key my Postal Code so that this&amp;nbsp;web&amp;nbsp;page (form) will accept it?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Scrawlr FAQ</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/83373.aspx</link><pubDate>Mon, 23 Jun 2008 23:10:31 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83373</guid><dc:creator>billyhoffman</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/83373.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=83373</wfw:commentRss><description>&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: What is Scrawlr?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A:&lt;span&gt;&amp;nbsp; &lt;/span&gt;Scrawlr is a tool
that will crawl a website and audit it for SQL Injection vulnerabilities.
Specifically, Scrawlr is designed to detect SQL Injection vulnerabilities in
dynamic web pages that will be indexed by search engines.&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: Where can I download Scrawlr?&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: &lt;a href="https://download.spidynamics.com/Products/scrawlr/" title="Scrawlr download link"&gt;Download Scrawler Here&lt;/a&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font size="4"&gt;Q: Where can I see Scrawlr in action?&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;A: Here is a &lt;a href="https://download.spidynamics.com/Products/scrawlr/scrawler-screenshot.png"&gt;screen shot of Scrawlr&lt;/a&gt; in action&lt;br /&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: What is SQL Injection?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: SQL Injection is a common vulnerability in web
applications that allows an attacker to execute their own SQL commands on your
backend database system.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Typical attacks
include extracting confidential information, injecting malicious content, executing
stored procedures or operating system commands, and disabling or destroying the
database. You can learn more about SQL Injection by reading our whitepapers.&lt;/font&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: What kind of websites can Scrawlr test?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Scrawlr can be used to test virtually any kind of website
(provided you have permission to audit that website &lt;span style="font-family:Wingdings;"&gt;&lt;span&gt;J&lt;/span&gt;&lt;/span&gt;). Scrawlr does have several
limitations when compared to a traditional web vulnerability scanner &lt;span&gt;&amp;nbsp;&lt;/span&gt;which prevent it from crawling certain parts
of your web application. These limitations include:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;&lt;li class="MsoNormal" style="line-height:normal;"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;span&gt;No submission of web forms&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height:normal;"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;span&gt;Does not interpret JavaScript or Flash&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height:normal;"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;span&gt;Only tests for SQL Injection vulnerabilities and only
     tests the query string parameters of&lt;span&gt;&amp;nbsp;
     &lt;/span&gt;URLs&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height:normal;"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;span&gt;Does not keep state or use Cookies&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height:normal;"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;span&gt;Crawl limit of 1500 pages&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height:normal;"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;span&gt;No authentication support&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;&lt;span&gt;Q: Why doe&lt;/span&gt;s Scrawlr have these
limitations?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Over the last several months, hackers have been using
automated tools to perform mass exploitation of hundreds of thousands of
websites. The attackers are using Google to find web applications built using
Microsoft’s Active Server Pages and then performing SQL Injection attacks
against these sites injecting various types of malware which are subsequently served
to unsuspecting visitors. Scrawlr was specifically designed to help web
developers test their website for SQL injection vulnerabilities that could be
exposed to an attacker through a search engine. As such, Scrawlr crawls a
websites using the same techniques as a search engine: it doesn’t keep state,
or submit forms, or execute JavaScript or Flash. To fully test your web
application for SQL Injection and other web vulnerabilities requires the use of
a full featured web vulnerability scanner such as &lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200%5E14344_4000_100__" title="Download WebInspect"&gt;HP WebInspect&lt;/a&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;font size="4"&gt;Q: How do I know these vulnerabilities are real?&lt;/font&gt;&lt;/font&gt;

&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: When Scrawlr detects what it thinks is a SQL Injection
vulnerability, it will try to extract the database name and type, as well as
the names of all the user defined tables in the database. This proves that data
extraction is possible and that the SQL Injection vulnerability is real.&lt;/font&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: Is Scrawlr limited to auditing only sites built with
Microsoft’s ASP technology?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: No, Scrawlr will also audit PHP, ASP.NET, and JSP pages
that have query string parameters that are encountered during its search
engine-like crawl of the web application.&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: What specific technologies will Scrawlr crawl?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Scrawlr will crawl and audit any of the following file
extensions:&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;htm/html&lt;/li&gt;&lt;li&gt;asp&lt;/li&gt;&lt;li&gt;aspx&lt;/li&gt;&lt;li&gt;php/php3/php4&lt;/li&gt;&lt;li&gt;jsp&lt;/li&gt;&lt;li&gt;js&lt;/li&gt;&lt;li&gt;txt&lt;/li&gt;&lt;li&gt;cfm&lt;/li&gt;&lt;li&gt;any file without an extension&lt;/li&gt;&lt;/ul&gt;

&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: How much does Scrawlr Cost?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Scrawlr is a free tool created by HP’s Web Security
Research Group. It is experimental software and not officially supported by HP.&lt;/font&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font size="4"&gt;Q: Is the source code available for Scrawlr?&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;A: No.&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: Does Scrawlr support scanning a website through a proxy?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Yes, but Scrawlr only supports basic HTTP proxies that do
not require authentication.&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q: Can Scrawlr scan web applications spread of many
different hostnames and subdomains?&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Yes, you can configure Scrawlr to audit multiple hosts
using the “Allowed Hosts” option under the “Settings” menu. Please note that
you must enter the hostname exactly as it appears. Scrawlr also display disallowed
hostnames at the end of a scan, allowing you to start a new scan which will
audit those discovered hostnames.&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif" size="4"&gt;Q:&lt;span&gt;&amp;nbsp; &lt;/span&gt;How can I get help
if I have problems with Scrawlr?&lt;/font&gt;&lt;/p&gt;







&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: Scrawlr is released as experimental software and is not
officially supported by HP. However, we have set up a forum so Scrawlr users
can assist each other to work around issues.&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;font size="4"&gt;Q: Will this tool be supported or extended?&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: This is an unsupported tool in the sense that individual problems and bug reports may not be addressed.&amp;nbsp; However, the researchers who implemented the tool will actively read the forum postings, and there are plans to extend the tool in the future.&amp;nbsp; We would love to hear your thoughts and constructive criticisms on the forum.&lt;br /&gt;&lt;br /&gt;&lt;font size="4"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&lt;font size="4"&gt;Q: Does Scrawlr find blind SQL injection vulnerabilities?&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;A: No.&amp;nbsp; The tool only checks for verbose SQL injection.&lt;br /&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>