Skip to content
GitLab
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • A arachni
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 125
    • Issues 125
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 8
    • Merge requests 8
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Infrastructure Registry
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • Arachni - Web Application Security Scanner Framework
  • arachni
  • Issues
  • #430
Closed
Open
Issue created Mar 02, 2014 by Administrator@rootContributor

Module - Localstart.asp

Created by: treadie

With regards to the localstart.asp module, rather than flagging when this file exists, the module should instead flag whenever it discovers NTLM based basic authentication (or just basic auth for that matter. however it should differentiate the 2). As this will always be tied to the local computer or the internal domain, and essentially allow brute forcing of user accounts and/or DoS (locking domain accounts). It also means that you could add ‘localstart.asp’ to the common file list, and have the ‘ntlm basic auth?’ module flag whenever it encounters a 401 requesting NTLM auth.

Assignee
Assign to
Time tracking