I've been messing around with DVWA (Damn vulnerable web application) and w3af. I've been scanning DVWA with w3af, and have used the spiderMan proxy and http config to setup auth credentials to get past the login screen of DVWA, but w3af still doesn't seem to be finding any sql injection anywhere (which is guaranteed).
I've seen a few vague tutorials online showing it to be trivial, but even when tweaking my setup in a few ways I still have yet to see it detect SQLi.
Anyone have an suggestions or ideas as to why this may be an issue?
Thanks in advance!