Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-24 Thread Jon Dowland
On Sun, Feb 22, 2009 at 07:27:43PM -0600, Ron Johnson wrote: But what (besides web crawling) is the (legal) purpose of that? And why does it need a word list? It seems to me that this tool is as open to abuse as nmap, ping, wget, and several other apps we distribute. -- Jon Dowland

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-24 Thread Ron Johnson
On 02/24/2009 08:13 AM, Jon Dowland wrote: On Sun, Feb 22, 2009 at 07:27:43PM -0600, Ron Johnson wrote: But what (besides web crawling) is the (legal) purpose of that? And why does it need a word list? It seems to me that this tool is as open to abuse as nmap, ping, wget, and several other

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-24 Thread Holger Levsen
Hi, On Dienstag, 24. Februar 2009, Ron Johnson wrote: The apps you specify have obvious non-abusive uses. What (besides penetration testing) are such uses for w3bfukk0r? penetration testing is a useful use. you might even do it for others. (As Noah Slater pointed out, it's hard to lose a

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden?directories (forced browsing)

2009-02-24 Thread Noah Slater
On Tue, Feb 24, 2009 at 09:17:35PM +0100, Holger Levsen wrote: (As Noah Slater pointed out, it's hard to lose a directory on your own machine...) you can loose access to your machine... At which point you may as well call it someone else's machine. -- Noah Slater,

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden?directories (forced browsing)

2009-02-24 Thread Holger Levsen
Hi, On Dienstag, 24. Februar 2009, Noah Slater wrote: you can loose access to your machine... At which point you may as well call it someone else's machine. I ment loosing/forgetting the passwords or the keys. regards, Holger signature.asc Description: This is a digitally signed

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden?directories (forced browsing)

2009-02-24 Thread Ron Johnson
On 02/24/2009 02:38 PM, Holger Levsen wrote: Hi, On Dienstag, 24. Februar 2009, Noah Slater wrote: you can loose access to your machine... At which point you may as well call it someone else's machine. I ment loosing/forgetting the passwords Rescue disk!

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden?directories (forced browsing)

2009-02-24 Thread Nico Golde
Hi, * Noah Slater nsla...@tumbolia.org [2009-02-25 01:32]: On Tue, Feb 24, 2009 at 09:17:35PM +0100, Holger Levsen wrote: (As Noah Slater pointed out, it's hard to lose a directory on your own machine...) you can loose access to your machine... At which point you may as well call it

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-23 Thread Bjørn Mork
Noah Slater nsla...@tumbolia.org writes: On Sun, Feb 22, 2009 at 05:18:39PM -0800, Asheesh Laroia wrote: I think that the description explains that the purpose is to find hidden directories on web servers, presumably either your own or other people's. Why would you need to find directories on

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-23 Thread Nico Golde
Hi, * Don Armstrong d...@debian.org [2009-02-23 10:07]: On Mon, 23 Feb 2009, Paul Wise wrote: [...] It'd also be best if this package didn't refer to invented terminology like forced browsing and instead said what it actually does (return the subset of HEAD requests that return 200 from a

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-23 Thread Noah Slater
On Mon, Feb 23, 2009 at 01:06:38PM +0100, Bjørn Mork wrote: Noah Slater nsla...@tumbolia.org writes: On Sun, Feb 22, 2009 at 05:18:39PM -0800, Asheesh Laroia wrote: I think that the description explains that the purpose is to find hidden directories on web servers, presumably either your

Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-22 Thread Maximilian Gaß
Package: wnpp Severity: wishlist Owner: Maximilian Gaß m...@cloudconnected.org * Package name: w3bfukk0r Version : 0.2 Upstream Author : Nico Golde and Andreas Krennmair * URL : http://www.ngolde.de/w3bfukk0r.html * License : MIT Programming Lang: C

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-22 Thread Ron Johnson
On 02/22/2009 04:39 PM, Maximilian Gaß wrote: Package: wnpp Severity: wishlist Owner: Maximilian Gaß m...@cloudconnected.org * Package name: w3bfukk0r Version : 0.2 Upstream Author : Nico Golde and Andreas Krennmair * URL : http://www.ngolde.de/w3bfukk0r.html *

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-22 Thread Ron Johnson
On 02/22/2009 07:18 PM, Asheesh Laroia wrote: On Sun, 22 Feb 2009, Ron Johnson wrote: On 02/22/2009 04:39 PM, Maximilian Gaß wrote: Description : scan webservers for hidden directories (forced browsing) w3bfukk0r is a forced browsing tool, it basically scans webservers (HTTP/HTTPS)

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-22 Thread Asheesh Laroia
On Sun, 22 Feb 2009, Ron Johnson wrote: On 02/22/2009 04:39 PM, Maximilian Gaß wrote: Description : scan webservers for hidden directories (forced browsing) w3bfukk0r is a forced browsing tool, it basically scans webservers (HTTP/HTTPS) for a directory by using HTTP HEAD command and

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-22 Thread Noah Slater
On Sun, Feb 22, 2009 at 05:18:39PM -0800, Asheesh Laroia wrote: I think that the description explains that the purpose is to find hidden directories on web servers, presumably either your own or other people's. Why would you need to find directories on your own server? -- Noah Slater,

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-22 Thread Paul Wise
On Mon, Feb 23, 2009 at 10:27 AM, Ron Johnson ron.l.john...@cox.net wrote: But what (besides web crawling) is the (legal) purpose of that? And why does it need a word list? Presumably it is a useful tool as part of a security professional's penetration testing toolbox? -- bye, pabs

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden directories (forced browsing)

2009-02-22 Thread Don Armstrong
On Mon, 23 Feb 2009, Paul Wise wrote: On Mon, Feb 23, 2009 at 10:27 AM, Ron Johnson ron.l.john...@cox.net wrote: But what (besides web crawling) is the (legal) purpose of that? And why does it need a word list? Presumably it is a useful tool as part of a security professional's