Giter VIP home page Giter VIP logo

Comments (4)

GoogleCodeExporter avatar GoogleCodeExporter commented on July 20, 2024
Yes that should be relatively simple enough to implement. I will try fit it in 
for the next release.

The test that checks for potentially insecure direct object references looks 
for file names, or paths, in the URL query string but does not actually go the 
step further and manipulate them to test for RFI/LFI.

Original comment by [email protected] on 21 May 2012 at 12:11

  • Added labels: Type-Enhancement
  • Removed labels: Type-Defect

from webvulscan.

GoogleCodeExporter avatar GoogleCodeExporter commented on July 20, 2024

Original comment by [email protected] on 21 May 2012 at 12:12

  • Changed state: Accepted

from webvulscan.

GoogleCodeExporter avatar GoogleCodeExporter commented on July 20, 2024
Using dynamic methods for this is far better than using someone elses shell. 
See code.google.com/p/fimap for ideas. 
Adding RFI/LFI to this would be excellent - I think a good compromise would be 
to have it test for LFI/RFI on all parameters, while also using the rfilist.dat 
file floating around (I will link when I find it) to check paths, just in case.
Loving the project though!

Original comment by [email protected] on 9 Jun 2012 at 4:52

from webvulscan.

GoogleCodeExporter avatar GoogleCodeExporter commented on July 20, 2024
Great that you like the project! Yes I agree, I think the scanner should have 
support for this vulnerability as it can be a high-risk one. I released another 
version yesterday but, unfortunately, I only had a few days to spend on the 
project and had a few issues to fix so I did not think I would fit this in. I 
should definitely be able to fit it in for the next one though. Thanks for the 
feedback and suggestions!

Original comment by [email protected] on 10 Jun 2012 at 4:22

from webvulscan.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.