AppSecNews
DAST Open source Established

w3af

by Andres Riancho and contributors

Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.

Visit github.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run w3af in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
  • Project maintenance status and runtime prerequisites: confirm against the repository before use

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

w3af, the Web Application Attack and Audit Framework, is organized entirely around plugins, and understanding the plugin types is understanding the tool. Crawl plugins discover URLs and input points by following links, reading robots and sitemap files, guessing filenames and parsing responses. Audit plugins take those input points and inject payloads to test for SQL injection, cross-site scripting, file inclusion, command execution, cross-site request forgery and the rest of the standard classes. Grep plugins passively inspect every request and response the framework sees and flag interesting content such as comments, email addresses, error messages and credentials. Output plugins write the findings.

The distinguishing type is attack plugins. Where most scanners stop at reporting, w3af can take a confirmed finding and turn it into access: an SQL injection into a database shell, a command execution into an interactive shell. That places it between a scanner and an exploitation framework. It is driven from a console with a scriptable command language and from a graphical interface. A proxy and manual request editor are included for hands-on work alongside the automated plugins.

Where it fits

This is a penetration tester's tool for assessment work against systems you are authorized to attack, not a scanner you schedule against production. It runs from an operator's workstation, typically on a security-focused Linux distribution where its dependencies are already handled. Nothing about its output or workflow is aimed at feeding findings to developers. Before use, check the project's current state and its runtime requirements, since dependency and interpreter expectations are the usual friction point.

Strengths

  • The plugin architecture is clean and well separated, which makes it a good framework to extend with your own checks.
  • Attack plugins turn findings into demonstrated access, which settles arguments about exploitability.
  • Passive grep plugins catch information disclosure that active testing alone would miss.
  • Console scripting allows repeatable assessment runs without the GUI.

Limitations

  • Development has been quiet for a long time, so check library currency and environment compatibility must be assessed before you depend on it.
  • No JavaScript execution in the crawler, which makes it largely blind to modern single-page applications.
  • The audit plugins are noisy and prone to false positives compared with scanners that confirm findings before reporting.
  • Setting up a working environment is often the hardest part of using it.

Who it suits

Of interest to penetration testers who want a scriptable, extensible framework and to anyone learning how a scanner is constructed internally, since the plugin model makes the mechanics unusually legible. Not a sensible choice for a team needing maintained, low-noise scanning of contemporary JavaScript applications.

Used w3af? Recommend it under your own name and title.

Recommend this tool