FAQ

Q:
I need help! Where is the manual?
A:
Please refer to the Help section on this webpage to get a user's guide.
Q:
I registered domainname.com as a host and uploaded the signature file, but I can't access www.domainname.com
A:
The signature file is valid for one host exactly. As domainname.com and www.domainname.com are technically speaking two hosts, it won't work. Just register www.domainname.com as the host in Chorizo! and the access to www.domainname.com will work. If you want to scan more hosts (i.e. wildcard domains etc.), please upgrade to the Standard version.
Q:
Can you read my scans, test data and found vulnerabilities?
A:
No. We encrypt all the data in the database. You can only view the data with your account. See our data protection declaration in the legal terms.
Q:
Do I need special Software to use Chorizo!?
A:
No. All you need is a common web browser with JavaScript enabled, you set up Chorizo! as proxy server and there it goes.
Q:
What are the proxy parameters to use Chorizo!?
A:
There are two possibilities: either you use chorizo-scanner.com with port number 3128, or you choose chorizo-proxy.com with port number 80
Q:
Which browsers are supported?
A:
The following browsers are supported: Firefox >= 1.0, Mozilla >= 1.7 and Internet Explorer 6 and 7
Q:
Does Chorizo! support frame-based applications?
A:
Currently not. Due to the nature of frames, Chorizo! cannot decide easily on which frameset to open its proxy window. Try to use deeplinks or frameless applications.
Q:
What is the difference between "Scan Page" and "Scan while browsing"?
A:
While "Scan Page" just scans the page you are currently on, "scan while browsing" allows you to surf through your website and have Chorizo! scan in the background. This could be useful if you want to have a look at password secured areas or have multi-page forms. If scanning applications with hidden JavaScript, e.g. Ajax, you need to use the "scan while browsing" mode.
Q:
What is "Scan recursive"?
A:
Using "scan recursive" makes Chorizo! scan the page you are currently on and all linked pages within this page on your server down to the level you selected.
Q:
Can I scan all pages in the Internet?
A:
No, after registering on the Chorizo! server you'll receive a file with a generated content. You have to put this file into your root-folder otherwise Chorizo! will not work.
Q:
How do you assure that no one scans my pages?
A:
After registering on the Chorizo! server, the user receives a file with a generated content. Chorizo! does not work if it does not find the file in the root-folder of a website.
Q:
What does the stuff in the report window mean?
A:
In the report window you see security issues found by Chorizo!. You get information what kind of security issue was found and if you got Chorizo! Standard you'll receive additional information how to solve this issue.
Q:
Does Chorizo! work with https?
A:
Yes. Generally it works, but you need to start your scan on the root URL.
Q:
Can I change my password?
A:
Yes. Just go to the "My Chorizo" page and edit your profile on the right side. You see a text input called "New password" where you can enter your password. Be careful: if you change your password, all your previous scans and reports will be lost!
Q:
Is there a way to switch proxies easily?
A:
Yes, if you're using Firefox, you could use the Switch Proxy Tool-extension.
Q:
Is it possible to scan Applications within my secured Intranet?
A:
Yes, but not in the ASP-Version. MAYFLOWER has a boxed solution, which could be installed in your internal IT structure. Please contact us for further information. sales@mayflower.de
Q:
In my company, I am only allowed to use port 80 or I am bound to our corporate proxy. Can I use Chorizo!?
A:
Yes, you have to use the web interface and click on "Scan my site now". Using the proxy will not work. Please be aware that this will use the so-called CGI Proxy system in Chorizo! and thus is not able to scan everything (i.e. JavaScript requests, URLs generated by JavaScript etc.). If you want to leverage the full power of Chorizo!, please contact your local admins or contact sales for a dedicated appliance of Chorizo! inside your company.

© Copyright 2006 - 2008, MAYFLOWER GmbH. The products mentioned here are registered trademarks of MAYFLOWER GmbH. / Imprint