Top 10 winner
Cross-Site Port Attacks
A Bug Hunter's Rhapsody: Cross Site Port Attacks - XSPA
Part one of three naming Cross Site Port Attacks (XSPA): an application that fetches a user-supplied URL can be driven to port-scan intranet and Internet hosts, grab banners, fingerprint internal apps and read local files. Shows the vulnerable PHP patterns file_get_contents, fsockopen and curl_exec, and lists finds in Facebook, Google, Mozilla, Yahoo and Pinterest.
Record
- Document
- A Bug Hunter's Rhapsody: Cross Site Port Attacks - XSPA
- Researcher
- Riyaz Ahemed Walikar
- Published by
- riyazwalikar.com
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Riyaz Ahemed Walikar, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .