WEBSCARAB
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
WebScarab is an OWASP web application security testing framework. It operates as an intercepting proxy, allowing analysts to observe and modify HTTP/HTTPS requests and responses between browser and web server.
LAUNCHING#
java -jar webscarab.jar # Launch full interface java -jar webscarab.jar -lite # Launch lite interface
PROXY SETUP#
# Default proxy: 127.0.0.1:8008 # Configure browser to use this proxy # For HTTPS: install WebScarab CA certificate
CORE FEATURES#
# 1. Intercepting Proxy # - View/modify HTTP requests before sending # - View/modify HTTP responses before rendering # - Intercept specific content types # 2. Spider/Crawler # - Automatic web application crawling # - Discover pages and forms # - Map application structure # 3. Session ID Analysis # - Collect session tokens # - Statistical randomness analysis # - Detect weak session generation # 4. Fuzzer # - Parameter fuzzing # - Custom payload lists # - Automated testing # 5. Manual Request Editor # - Craft custom HTTP requests # - Replay and modify requests # - Test edge cases
PROXY INTERCEPTION#
# Intercept requests: # Proxy → Intercept requests → Enable # Modify headers, parameters, body # Forward or drop requests # Intercept responses: # Proxy → Intercept responses → Enable # Modify response headers, body # Test client-side controls
SPIDER#
# Spider → Configure: # - Allowed domains # - Max depth # - Thread count # - Form handling # Start spider from a seed URL # Reviews discovered URLs in tree view
SESSION ID ANALYSIS#
# SessionID Analysis tab: # 1. Identify cookie/parameter containing session ID # 2. Collect multiple samples (50-100+) # 3. Analyze for: # - Randomness # - Predictability # - Sequential patterns # - Character distribution
FUZZER USAGE#
# Fuzzer tab: # 1. Select request to fuzz # 2. Mark parameter to fuzz # 3. Load payload list (or generate) # 4. Start fuzzing # 5. Analyze responses for anomalies # Payload sources: # - Custom wordlists # - Generated sequences # - SQL injection strings # - XSS payloads
FRAGMENTS#
# Fragments tab: # - View script fragments # - Analyze JavaScript # - Extract hidden form fields # - Identify client-side logic
COMPARE FEATURE#
# Compare requests/responses: # - Side-by-side comparison # - Highlight differences # - Useful for testing access controls
MANUAL REQUEST#
# Manual Request tab: # 1. Paste or create HTTP request # 2. Modify as needed # 3. Send to server # 4. Analyze response # 5. Iterate and test
ENCODING/DECODING#
# Transcoder tool: # - Base64 encode/decode # - URL encode/decode # - HTML entity encode/decode # - Hex encode/decode
NOTES#
- Java-based (cross-platform) - OWASP project (open source) - Largely superseded by OWASP ZAP and Burp Suite - Good for learning web security concepts - Lightweight alternative to commercial proxies - Session ID analysis is unique feature - No longer actively maintained - Consider OWASP ZAP for modern web testing