Re: local security scanner for vulnerable common opensource www projects

2009-05-05 Thread Mel Flynn
On Wednesday 06 May 2009 00:01:12 Jeroen Hofstee wrote: > Mel Flynn schreef: > > You can do that, the issue is plugins: > > 0) SuperCMS v 1.0 installed > > 1) CoolStuff via webinterface, by SuperCMSNr1Fan, version 0.1.0.1beta > > 2) SuperCMS v 1.0.1 security release, changes some issues with plugin

Re: local security scanner for vulnerable common opensource www projects

2009-05-05 Thread Jeroen Hofstee
Mel Flynn schreef: You can do that, the issue is plugins: 0) SuperCMS v 1.0 installed 1) CoolStuff via webinterface, by SuperCMSNr1Fan, version 0.1.0.1beta 2) SuperCMS v 1.0.1 security release, changes some issues with plugin handling 3) CoolStuff's maintainer is now known as CompetitorCMSNr1Fa

Re: local security scanner for vulnerable common opensource www projects

2009-05-05 Thread Mel Flynn
On Tuesday 05 May 2009 22:04:27 Jeroen Hofstee wrote: > Mel Flynn schreef: > > On Saturday 02 May 2009 14:50:14 Jeroen Hofstee wrote: > >> I tried to find a program which could scan the local filesystem and > >> extract a lists of well known web projects (joomla, wordpress etc) > > > > Not that I'm

Re: local security scanner for vulnerable common opensource www projects

2009-05-05 Thread Jeroen Hofstee
Mel Flynn schreef: On Saturday 02 May 2009 14:50:14 Jeroen Hofstee wrote: I tried to find a program which could scan the local filesystem and extract a lists of well known web projects (joomla, wordpress etc) Not that I'm aware of and it's hell to write and keep current. k, pitty. Although

Re: local security scanner for vulnerable common opensource www projects

2009-05-05 Thread Mel Flynn
On Saturday 02 May 2009 14:50:14 Jeroen Hofstee wrote: > I tried to find a program which could scan the local filesystem and > extract a lists of well known > web projects (yoomla, wordpress etc), extract the installed version > number and match it against > a database of known vulnerabilities. Sim

local security scanner for vulnerable common opensource www projects

2009-05-02 Thread Jeroen Hofstee
I tried to find a program which could scan the local filesystem and extract a lists of well known web projects (yoomla, wordpress etc), extract the installed version number and match it against a database of known vulnerabilities. Similiar to portaudit, but then for the standard scripts users i