[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] AttackAPI (0.7)
- To: full-disclosure@xxxxxxxxxxxxxxxxx, websecurity@xxxxxxxxxxxxx, webappsec@xxxxxxxxxxxxxxxxx, bugtraq@xxxxxxxxxxxxxxxxx, pen-test@xxxxxxxxxxxxxxxxx, security-basics@xxxxxxxxxxxxxxxxx
- Subject: [Full-disclosure] AttackAPI (0.7)
- From: "pdp (architect)" <pdp.gnucitizen@xxxxxxxxxxxxxx>
- Date: Fri, 15 Sep 2006 23:22:22 +0100
http://www.gnucitizen.org/projects/attackapi/
Client Enumeration
Server Enumeration
AuthorizationForcer
ExtensionScanner
HistoryDumper
NetworkSweeper
PortScanner
Utils
JavaScriptShell
UsernameScanner
URLScanner
Base64Encoder
+
RequestBuilder
Now it can compose requests, fetch text and binary files, scan for
usernames, scan URLs. This pretty much proves that JavaScript can be
used for quite a lot malicious stuff without breaking the rules.
--
pdp (architect)
http://www.gnucitizen.org
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/