-
Notifications
You must be signed in to change notification settings - Fork 473
Running only certain plugins and or plugin types
- You can see the plugin types available in the help wiki
- You can see the plugins available by listing them
You can then call OWTF like this:
-
Only runs the passive plugins:
owtf.py -t passive https://accounts.google.com
-
Only runs the Spiders_Robots_and_Crawlers plugins (including semi_passive and active!):
owtf.py -o Spiders_Robots_and_Crawlers https://accounts.google.com
-
Only runs the passive Spiders_Robots_and_Crawlers plugin:
owtf.py -t passive -o Spiders_Robots_and_Crawlers https://accounts.google.com
-
Runs all the semi_passive plugins EXCEPT (-e) Search_engine_discovery_reconnaissance:
owtf.py -t semi_passive -e Search_engine_discovery_reconnaissance https://accounts.google.com
This wiki and the OWTF README document contains a lot of information, please take your time and read these instructions carefully.
We provide a CHANGELOG that provides details about almost every OWTF release.
Be sure to read the CONTRIBUTING guidelines before reporting a new OWTF issue or opening a pull request.
If you have any questions about the OWTF usage or want to share some information with the community, please go to one of the following places:
- IRC channel
#owtf
(irc.freenode.net)
Google Summer of Code 2018 Guide
Installation
Getting Started
- Define where your tools are
- Run OWASP OWTF
- HTTP Auth Configurations
- Simulation mode
- AUX plugins usage
- FAQ
SET usage
Cookbooks (GSoC 2014 Projects UPDATE)
-
Zest Integration:
- Quick Guide to get started with Zest,ZAP and Replay
- Zest and ZAP API Installation
- Zest and ZAP integration Introduction
- Zest Runner module
- Forward HTTP request to ZAP
- Zest script creation from single HTTP transaction
- Zest script creation from multiple HTTP transactions
- Zest Script Creator module
- HTTP Request Editing Window (Replay Function)
- Zest Script Recording Functionality
- Zest scripting console
Development
-
Plugins:
-
Tests:
Contact