Re: I want to create a hackbot for ethical hacking
| From: | Stelian Mocanita | Date: | Thu, 21 Nov 2013 21:51:51 +0000 |
| Subject: | Re: I want to create a hackbot for ethical hacking | ||
| References: | 1 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-17164@lists.php.net to get a copy of this message | ||
Hello,
This is the emailing list for the php webmasters, as in the people that
work on the php.net website and mirrors, so your question should go to a
different emailing list or user group.
My personal recommendation would be to start your project on a shared code
website, like http://github.com and if people like the idea they
will help
you out and contribute code. Also, the idea of informing people of
vulnerabilities is good and always welcome but there is more to it than one
single quote.
You can check resources like OWASP for more information:
https://www.owasp.org/index.php/Category:OWASP_PHP_Project
Kind regards,
Stelian
On Thu, Nov 21, 2013 at 10:37 PM, Joe Caldwell <jcpswd34@gmail.com> wrote:
> Dear PHP Webmaster,
>
> I want to create a pretty simple PHP robot, but I need your help because I
> can't seem to get it right.
>
> I discovered yesterday that if you use Google to type in
> "inurl:index.php?id=", then you can find pages that might be vulnerable to
> SQL Injection. If you just type in a single quote (') after the URL, then
> it is vulnerable if you get an SQL error, but it is not vulnerable if the
> page does not change or if you get an Error 404.
>
> I want to have a PHP robot that will search for "inurl:index.php?id=",
> follow all the links on Google, and tell me if the sites are vulnerable. I
> don't want the robot to steal the passwords or anything, I just want the
> robot to tell me if the sites are vulnerable so that I can inform the
> webmaster that his/her site is vulnerable.
>
> Does that make sense?
>
> Joe Caldwell
> Founder, Indago.info
>