|
PrivEscRunner
The Privilege Escalation Runner automates the scanning with different login credentials, and then continues to perform the Privilege Escalation tests available in AppScan. To use it, first record a login sequence with each user role. This can be done by following these steps:
Once the login sequences are recorded, open the extension's main form from Tools->Extensions->'Privilege Escalation Runner'. In the form, perform the following steps:
The eXtension will proceed to run individual scans, once with no login and once with each login sequence, and save those scans into the configured folder. When all the scans have run, the scan with the primary login will be configured for Privilege Escalation testing with the other scans, and the test phase will be run with these tests only. Finally, the results will be saved to the results scan file. |