Web Hack List

Top 10 winner

Cross-Site Port Attacks

A Bug Hunter's Rhapsody: Cross Site Port Attacks - XSPA

Part one of three naming Cross Site Port Attacks (XSPA): an application that fetches a user-supplied URL can be driven to port-scan intranet and Internet hosts, grab banners, fingerprint internal apps and read local files. Shows the vulnerable PHP patterns file_get_contents, fsockopen and curl_exec, and lists finds in Facebook, Google, Mozilla, Yahoo and Pinterest.

Record

Document
A Bug Hunter's Rhapsody: Cross Site Port Attacks - XSPA
Researcher
Riyaz Ahemed Walikar
Published by
riyazwalikar.com
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Riyaz Ahemed Walikar, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .