What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
- Project maintenance status and runtime prerequisites: confirm against the repository before use
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
w3af, the Web Application Attack and Audit Framework, is organized entirely around plugins, and understanding the plugin types is understanding the tool. Crawl plugins discover URLs and input points by following links, reading robots and sitemap files, guessing filenames and parsing responses. Audit plugins take those input points and inject payloads to test for SQL injection, cross-site scripting, file inclusion, command execution, cross-site request forgery and the rest of the standard classes. Grep plugins passively inspect every request and response the framework sees and flag interesting content such as comments, email addresses, error messages and credentials. Output plugins write the findings.
The distinguishing type is attack plugins. Where most scanners stop at reporting, w3af can take a confirmed finding and turn it into access: an SQL injection into a database shell, a command execution into an interactive shell. That places it between a scanner and an exploitation framework. It is driven from a console with a scriptable command language and from a graphical interface. A proxy and manual request editor are included for hands-on work alongside the automated plugins.
Where it fits
This is a penetration tester's tool for assessment work against systems you are authorized to attack, not a scanner you schedule against production. It runs from an operator's workstation, typically on a security-focused Linux distribution where its dependencies are already handled. Nothing about its output or workflow is aimed at feeding findings to developers. Before use, check the project's current state and its runtime requirements, since dependency and interpreter expectations are the usual friction point.
Strengths
- The plugin architecture is clean and well separated, which makes it a good framework to extend with your own checks.
- Attack plugins turn findings into demonstrated access, which settles arguments about exploitability.
- Passive grep plugins catch information disclosure that active testing alone would miss.
- Console scripting allows repeatable assessment runs without the GUI.
Limitations
- Development has been quiet for a long time, so check library currency and environment compatibility must be assessed before you depend on it.
- No JavaScript execution in the crawler, which makes it largely blind to modern single-page applications.
- The audit plugins are noisy and prone to false positives compared with scanners that confirm findings before reporting.
- Setting up a working environment is often the hardest part of using it.
Who it suits
Of interest to penetration testers who want a scriptable, extensible framework and to anyone learning how a scanner is constructed internally, since the plugin model makes the mechanics unusually legible. Not a sensible choice for a team needing maintained, low-noise scanning of contemporary JavaScript applications.
Used w3af? Recommend it under your own name and title.
Recommend this tool