mirror of
https://github.com/autistic-symposium/sec-pentesting-toolkit.git
synced 2025-06-19 20:34:07 -04:00
websecurity
This commit is contained in:
parent
0a30e5e40e
commit
c8705de960
1 changed files with 2 additions and 1 deletions
|
@ -49,6 +49,7 @@ $ wget -rck <TARGET-WEBSITE>
|
|||
|
||||
```
|
||||
$ /wget -r -l1 -H -t1 -nd -N -nd -N -A.swf -erobots=off <WEBSITE> -i output_swf_files.txt
|
||||
```
|
||||
|
||||
* Once we have identified and downloaded *.swf files, we must analyze the code, the functions (as *loadMovie*) variables in order to identify those that call and allow other types of vulnerabilities such as cross site scripting. Below shows some vulnerable functions:
|
||||
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue