andresriancho / w3af

w3af: web application attack and audit framework, the open source web vulnerability scanner.
http://w3af.org/
4.53k stars 1.21k forks source link

GUI freezes #13636

Open phenyll opened 8 years ago

phenyll commented 8 years ago

My w3af seems to crash by it stopping to listen to GUI inputs (pobably after scan completes?). I Need to kill it every time. just like #12906

`Exception in thread GTKDraw: Traceback (most recent call last): File "/usr/lib/python2.7/threading.py", line 801, in bootstrap_inner self.run() File "/usr/lib/python2.7/threading.py", line 754, in run self.__target(_self.args, *_self.__kwargs) File "/usr/share/w3af/w3af/core/ui/gui/scanrun.py", line 419, in _draw_real raise ValueError(msg % args) ValueError: A ValueError exception with message "invalid literal for int() with base 10: '201.48'" was found while trying to render a new dotcode. Please create a new bug report at https://github.com/andresriancho/w3af/issues/new including the following info:

['"<GtkTreeIter at 0x356b9a0>" [label="http://localhost/"]']`

I'm on Kali 2016.1 having not changed anything on the distro.

Do you need further details?

cryptogeek commented 8 years ago

Same

darklynx commented 8 years ago

Same here, latest version of up-to-date Kali 2016.1, LXDE, UI hangs forever:

~$ w3af_gui
Starting w3af, running on:
  Python version: 2.7.12rc1 (default, Jun 13 2016, 09:20:59) [GCC 5.4.0 20160609]
  GTK version: 2.24.30
  PyGTK version: 2.24.0
  w3af version:
    w3af - Web Application Attack and Audit Framework
    Version: 1.6.54
    Distribution: Kali Linux
    Author: Andres Riancho and the w3af team.
/usr/share/w3af/w3af/core/ui/gui/reqResViewer.py:182: GtkWarning: gtk_box_pack: assertion 'child->parent == NULL' failed
  self.pack_start(hbox, False, False, padding=5)
openjdk version "1.8.0_91"
OpenJDK Runtime Environment (build 1.8.0_91-8u91-b14-2-b14)
OpenJDK 64-Bit Server VM (build 25.91-b14, mixed mode)
The page is written in: "en".
Exception in thread GTKDraw:
Traceback (most recent call last):
  File "/usr/lib/python2.7/threading.py", line 801, in __bootstrap_inner
    self.run()
  File "/usr/lib/python2.7/threading.py", line 754, in run
    self.__target(*self.__args, **self.__kwargs)
  File "/usr/share/w3af/w3af/core/ui/gui/scanrun.py", line 419, in _draw_real
    raise ValueError(msg % args)
ValueError: A ValueError exception with message "invalid literal for int() with base 10: '146.89'" was found while trying to render a new dotcode. Please create a new bug report at https://github.com/andresriancho/w3af/issues/new including the following info:

['"<GtkTreeIter at 0x32b8b80>" [label="https://rbaskets.in"]']

New URL found by web_spider plugin: "https://rbaskets.in/web"
The URL: "https://rbaskets.in/web" has a "<form>" element with auto-complete enabled. This information was found in the request with id 37.
New URL found by web_spider plugin: "https://rbaskets.in/"
Found 2 URLs and 4 different injections points.
The URL list is:
- https://rbaskets.in/
- https://rbaskets.in/web
The list of fuzzable requests is:
- Method: GET | https://rbaskets.in/
- Method: GET | https://rbaskets.in/
- Method: GET | https://rbaskets.in/web
- Method: GET | https://rbaskets.in/web | URL encoded form: (basket_name)
The whole target has no protection (X-Frame-Options header) against Click-Jacking attacks. This vulnerability was found in the requests with ids 18 and 37.
Password profiling TOP 100:
- [1] function with 170 repetitions.
- [2] token with 140 repetitions.
- [3] data with 110 repetitions.
- [4] Baskets with 70 repetitions.
- [5] event with 60 repetitions.
- [6] Request with 60 repetitions.
- [7] fetchBaskets with 50 repetitions.
- [8] html with 50 repetitions.
- [9] jqXHR with 40 repetitions.
- [10] sessionStorage with 40 repetitions.
- [11] modal with 40 repetitions.
- [12] margin with 40 repetitions.
- [13] basketsCount with 40 repetitions.
- [14] click with 40 repetitions.
- [15] addClass with 30 repetitions.
- [16] removeClass with 30 repetitions.
- [17] names with 30 repetitions.
- [18] else with 30 repetitions.
- [19] indicateMasterToken with 30 repetitions.
- [20] clearBaskets with 30 repetitions.
- [21] hide with 30 repetitions.
- [22] onAjaxError with 30 repetitions.
- [23] Token with 20 repetitions.
- [24] success with 20 repetitions.
- [25] HTTP with 20 repetitions.
- [26] fail with 20 repetitions.
- [27] bottom with 20 repetitions.
- [28] 60px with 20 repetitions.
- [29] createBasket with 20 repetitions.
- [30] saveMasterToken with 20 repetitions.
- [31] height with 20 repetitions.
- [32] href with 20 repetitions.
- [33] mark with 20 repetitions.
- [34] Basket with 20 repetitions.
- [35] addBaskets with 20 repetitions.
- [36] Close with 20 repetitions.
- [37] warning with 20 repetitions.
- [38] setItem with 20 repetitions.
- [39] position with 20 repetitions.
- [40] Powered with 10 repetitions.
- [41] text with 10 repetitions.
- [42] 40px with 10 repetitions.
- [43] statusText with 10 repetitions.
- [44] skip with 10 repetitions.
- [45] 70px with 10 repetitions.
- [46] background with 10 repetitions.
- [47] removeItem with 10 repetitions.
- [48] always with 10 repetitions.
- [49] preventDefault with 10 repetitions.
- [50] refresh with 10 repetitions.
- [51] jQuery with 10 repetitions.
- [52] Create with 10 repetitions.
- [53] successfully with 10 repetitions.
- [54] relative with 10 repetitions.
- [55] Master with 10 repetitions.
- [56] append with 10 repetitions.
- [57] container with 10 repetitions.
- [58] muted with 10 repetitions.
- [59] body with 10 repetitions.
- [60] Created with 10 repetitions.
- [61] post with 10 repetitions.
- [62] Authorize with 10 repetitions.
- [63] created with 10 repetitions.
- [64] Open with 10 repetitions.
- [65] length with 10 repetitions.
- [66] responseText with 10 repetitions.
- [67] color with 10 repetitions.
- [68] additional with 10 repetitions.
- [69] submit with 10 repetitions.
- [70] width with 10 repetitions.
- [71] master with 10 repetitions.
- [72] padding with 10 repetitions.
- [73] gain with 10 repetitions.
- [74] attr with 10 repetitions.
- [75] error with 10 repetitions.
- [76] Cancel with 10 repetitions.
- [77] 20px with 10 repetitions.
- [78] providing with 10 repetitions.
- [79] Your with 10 repetitions.
- [80] ready with 10 repetitions.
- [81] absolute with 10 repetitions.
- [82] privileges with 10 repetitions.
- [83] document with 10 repetitions.
- [84] status with 10 repetitions.
- [85] f5f5f5 with 10 repetitions.
- [86] getItem with 10 repetitions.
- [87] footer with 10 repetitions.
- [88] request with 10 repetitions.
- [89] left with 10 repetitions.
Scan finished in 7 seconds.
Stopping the core...
AverageS commented 8 years ago

Same for me, just like @darklynx

nadavkav commented 8 years ago

Same

dbeare commented 7 years ago

Same problem for me. Has anyone discovered a solution yet?