Hey, I'm currently playing around with the discovery and audit plugin and I'm testing on a server where the script /cgibin/finger is installed. It takes paramaters like /cgibin/finger?root and runs the finger command on the given input.
Now I'm assuming the osCommanding audit module (or at least *some* module) will attempt this but when I try audit all all I get are a load of GET requests for the regular URL. I'm obviously misunderstanding something here so could somebody point me in the right direction? Cheers, nnp -- http://www.unprotectedhex.com http://www.smashthestack.org ------------------------------------------------------------------------------ Apps built with the Adobe(R) Flex(R) framework and Flex Builder(TM) are powering Web 2.0 with engaging, cross-platform capabilities. Quickly and easily build your RIAs with Flex Builder, the Eclipse(TM)based development software that enables intelligent coding and step-through debugging. Download the free 60 day trial. http://p.sf.net/sfu/www-adobe-com _______________________________________________ W3af-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/w3af-users
