Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add automated/configurable session management for tested apps (e.g support for JSESSIONID, PHPSESSID, aspsessionid.*, asp.net_sessionid, etc) #10

Open
GoogleCodeExporter opened this issue Aug 1, 2015 · 2 comments

Comments

@GoogleCodeExporter
Copy link

What steps will reproduce the problem?
1. Pick a test Web application which normally requires authentication
2. Point webvulscan to the test Web app and attempt a scan
3. Currently, there is no way the tool will pass login page (unless 
authentication is disabled entirely for the test app - which is unrealistic)

What is the expected output? What do you see instead?
Be able to scan an app which requires authentication and normally uses 
authorisation cookies to maintain the user session on client-side. Currently, 
this is not possible with latest version of webvulscan tool.

What version of the product are you using? On what operating system?
webvulscan_v0.12

Please provide any additional information below.


Original issue reported on code.google.com by marian.v...@gmail.com on 17 Oct 2012 at 1:09

@GoogleCodeExporter
Copy link
Author

Original comment by webvuls...@gmail.com on 22 Oct 2012 at 11:13

  • Added labels: Priority-High, Type-Enhancement
  • Removed labels: Priority-Medium, Type-Defect

@GoogleCodeExporter
Copy link
Author

Original comment by webvuls...@gmail.com on 22 Oct 2012 at 11:16

  • Changed state: Accepted

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant