← All cheat sheets

WEBSCARAB

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

WebScarab is an OWASP web application security testing framework.
It operates as an intercepting proxy, allowing analysts to observe
and modify HTTP/HTTPS requests and responses between browser and
web server.

LAUNCHING#

java -jar webscarab.jar          # Launch full interface
java -jar webscarab.jar -lite    # Launch lite interface

PROXY SETUP#

# Default proxy: 127.0.0.1:8008
# Configure browser to use this proxy
# For HTTPS: install WebScarab CA certificate

CORE FEATURES#

# 1. Intercepting Proxy
# - View/modify HTTP requests before sending
# - View/modify HTTP responses before rendering
# - Intercept specific content types

# 2. Spider/Crawler
# - Automatic web application crawling
# - Discover pages and forms
# - Map application structure

# 3. Session ID Analysis
# - Collect session tokens
# - Statistical randomness analysis
# - Detect weak session generation

# 4. Fuzzer
# - Parameter fuzzing
# - Custom payload lists
# - Automated testing

# 5. Manual Request Editor
# - Craft custom HTTP requests
# - Replay and modify requests
# - Test edge cases

PROXY INTERCEPTION#

# Intercept requests:
# Proxy → Intercept requests → Enable
# Modify headers, parameters, body
# Forward or drop requests

# Intercept responses:
# Proxy → Intercept responses → Enable
# Modify response headers, body
# Test client-side controls

SPIDER#

# Spider → Configure:
# - Allowed domains
# - Max depth
# - Thread count
# - Form handling

# Start spider from a seed URL
# Reviews discovered URLs in tree view

SESSION ID ANALYSIS#

# SessionID Analysis tab:
# 1. Identify cookie/parameter containing session ID
# 2. Collect multiple samples (50-100+)
# 3. Analyze for:
#    - Randomness
#    - Predictability
#    - Sequential patterns
#    - Character distribution

FUZZER USAGE#

# Fuzzer tab:
# 1. Select request to fuzz
# 2. Mark parameter to fuzz
# 3. Load payload list (or generate)
# 4. Start fuzzing
# 5. Analyze responses for anomalies

# Payload sources:
# - Custom wordlists
# - Generated sequences
# - SQL injection strings
# - XSS payloads

FRAGMENTS#

# Fragments tab:
# - View script fragments
# - Analyze JavaScript
# - Extract hidden form fields
# - Identify client-side logic

COMPARE FEATURE#

# Compare requests/responses:
# - Side-by-side comparison
# - Highlight differences
# - Useful for testing access controls

MANUAL REQUEST#

# Manual Request tab:
# 1. Paste or create HTTP request
# 2. Modify as needed
# 3. Send to server
# 4. Analyze response
# 5. Iterate and test

ENCODING/DECODING#

# Transcoder tool:
# - Base64 encode/decode
# - URL encode/decode
# - HTML entity encode/decode
# - Hex encode/decode

NOTES#

- Java-based (cross-platform)
- OWASP project (open source)
- Largely superseded by OWASP ZAP and Burp Suite
- Good for learning web security concepts
- Lightweight alternative to commercial proxies
- Session ID analysis is unique feature
- No longer actively maintained
- Consider OWASP ZAP for modern web testing