<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/securitysoftware/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Scrawlr</title><link>http://www.communities.hp.com/securitysoftware/forums/198.aspx</link><description>Discussions related to the Scrawlr tool and it's use</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Re: Scrawlr &amp; HacmeBank</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/85858.aspx</link><pubDate>Mon, 29 Sep 2008 20:11:52 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:85858</guid><dc:creator>HansEnders</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/85858.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=85858</wfw:commentRss><description>&lt;p&gt;Walker-SRS;&lt;/p&gt;&lt;p&gt;You are partly correct.&amp;nbsp; Scrawlr will miss the SQLi vulns in HacmeBank due to its lightweight and free design aimed at the recent Microsoft attack vectors.&amp;nbsp; Scrawlr was meant to specifically search for URL injection points via the GET method, and cannot authenticate.&amp;nbsp; The SQLi vulns, both verbose and Blind, found on HacmeBank are forms found in the POST, specifically &amp;quot;txtUserName&amp;quot; and &amp;quot;txtPassword&amp;quot;.&lt;/p&gt;&lt;p&gt;Here are the details on Scrawlr taken from this other forum posting:&amp;nbsp; http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx?jumpid=reg_R1002_USEN&lt;/p&gt;&lt;p&gt;&amp;lt;&amp;lt;&lt;/p&gt;&lt;p&gt;Technical details for Scrawlr&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Identify Verbose SQL Injection vulnerabilities in URL parameters&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Can be configured to use a Proxy to access the web site&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Will identify the type of SQL server in use&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Will extract table names (verbose only) to guarantee no false positives&lt;br /&gt;&lt;br /&gt;Scrawlr does have some limitations versus our professional solutions and our fully functional SQL Injector tool&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Will only crawls up to 1500 pages&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Does not support sites requiring authentication&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Does not perform Blind SQL injection&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Cannot retrieve database contents&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Does not support JavaScript or flash parsing&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Will not test forms for SQL Injection (POST Parameters) &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;gt;&amp;gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Scrawlr &amp; HacmeBank</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/84173.aspx</link><pubDate>Thu, 07 Aug 2008 11:28:27 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:84173</guid><dc:creator>Walker-SRS</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/84173.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=84173</wfw:commentRss><description>&lt;p&gt;I ran Scrawlr against Foundstones HacMe Bank web site, which is riddled with SQL Injection vulnerabilities, and it came up with nothing.&lt;/p&gt;&lt;p&gt;&amp;nbsp;If the application cannot identify the base level vulnerabilities in a purposefully built vulnerable site, is it not leading others into a false sense of security?&lt;/p&gt;&lt;p&gt;&amp;nbsp;Or am I missing something? &lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>