Page 97 - Hands-On Bug Hunting for Penetration Testers
P. 97

SQL, Code Injection, and Scanners                                           Chapter 5

            After installing BSBDIOJ as per the requirements (and symlinking your installation's
            BSBDIOJ executable), you'll be able to access the BSBDIOJ CLI in your  1"5). Let's look at
            Arachni's help message to explore some of the options available:









































            This is a truncated version of the output. Arachni has so many options there are too many
            to reprint here. But certain CLI options are useful for extending Arachni's functionality and
            creating more sophisticated workflows.



            Going Beyond Defaults

            Like many scanners, BSBDIOJ can be point-and-click almost to a fault. Though no extra
            arguments are required to start spidering a URL from the command-line, there are several
            critical options we should be aware of to get better functionality.

                --timeout


                                                    [ 82 ]
   92   93   94   95   96   97   98   99   100   101   102