PaulDotCom mailing list archives

Re: [GPWN-list] sitemap2proxy


From: Abuse 007 <abuse007 () gmail com>
Date: Thu, 30 Aug 2012 17:53:40 +1000

Doesn't Burp Spider already do this?

On Fri, Aug 10, 2012 at 10:06 PM, Jason Frank <jasonjfrank () gmail com> wrote:
Thanks man.  Going to have to try this out.

On Fri, Aug 10, 2012 at 5:49 AM, Robin Wood <robin () digininja org> wrote:

So far this week I've given the password crackers/bruteforcers and the
wifi testers new stuff so today is the day for some web app action.

sitemap2proxy is a small script which takes a sitemap.xml file and
requests all entries in it through the proxy of your choosing (Burp,
ZAP etc). It doesn't do any brute forcing, it doesn't try to be
intelligent, it just requests all the pages the webmaster wants the
world to know about. I think this is a nice gentle way to start your
site spidering process.

By default it uses Googlebot's user agent string so anyone browsing
the logs shouldn't see anything out of the ordinary unless they know
by heart the IP addresses of all the Google spiders.

Give it a go and let me know what you think.

http://www.digininja.org/projects/sitemap2proxy.php

Robin




_______________________________________________
gpwn-list mailing list
gpwn-list () lists sans org
https://lists.sans.org/mailman/listinfo/gpwn-list




--
Jason Frank


_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com
_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com


Current thread: