Bluehost.com Web Hosting $6.95

Re: [PHP] spider

This is a discussion on Re: [PHP] spider within the PHP General forums, part of the PHP Programming Forums category; On Fri, Mar 21, 2008 at 1:52 PM, tedd <tedd@sperling.com> wrote: > Also, is there ...


Go Back   Usenet Forums > PHP Programming Forums > PHP General

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-21-2008
Eric Butera
 
Posts: n/a
Default Re: [PHP] spider

On Fri, Mar 21, 2008 at 1:52 PM, tedd <tedd@sperling.com> wrote:
> Also, is there a way to spider through a remote web site gathering
> directory permissions?


I should hope not.

>
> If not, can one attempt to write a file and record the
> failures/successes (0777 directories)?


I don't know if you've thought about it like this, but can people just
upload files to your site? It has to run through a form somewhere.

> What I am trying to do is to develop a way to test if a web site is
> secure or not. I'm not trying to develop evil code, but if it can be
> done then I want to know how.


People do "pen tests" using fuzzers and such but most people agree the
only real way to do it is by having a human attempting different
things.

You might want to take a look at the OWASP Top 10 [1] to get a better
idea of what to look for.

[1] http://www.owasp.org/index.php/Top_10_2007
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 04:59 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0