Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


[WIP] Hacker Toolkit filter_list
Author
Message
RE: [WIP] Hacker Toolkit #14
-- Update --
Added basic vulnerability scanner that detects possible
  • SQL Injection
  • Cross-Site Scripting
  • Cross-Site Request Forgery
  • Remote File Inclusion
  • Local File Inclusion
  • Full Path Disclosure

Currently the existence of FPD is only detected through improperly handled SQLI errors.

-- Question ---
Methods to detect FPD outside SQLI. I know that by turning a parameter into an array, such as modifying ?id= to ?id[]=, can do the trick. Does anyone have any other good methods?
"SQL Injection-a-holic"

Twitter | Security Sucks | My Blog

Reply





Messages In This Thread
[WIP] Hacker Toolkit - by RogueCoder - 06-21-2013, 12:49 PM