pdp.gnucitizen at googlemail.com
Mon Jul 16 09:32:42 BST 2007
This simple POC uses Yahoo Site Explorer Service to craw/spider other
support was required from my side. The POC proves once again that
Web2.0 technologies open new ways of attacking Web infrastructures.
Keep in mind that this spider is ultra fast. It does only several
connects in order to obtain the entire directory structure of the
targeted website. Also, keep in mind that it will take less then 5
minutes to make it equipped with the latest AJAX exploits. Therefore,
I am not responsible for your actions.
I am planning to write a follow up post on how we can make basic
client-side XSS scanner on the top of this spider, so stay tuned.
pdp (architect) | petko d. petkov
Full-Disclosure is hosted and sponsored by Secunia.