Alpha testers wanted

General technological topics without their own forum go here

Alpha testers wanted

Post by bombshop on Mon Mar 07, 2011 4:27 am
([msg=54754]see Alpha testers wanted[/msg])

I am in need of alpha testers for my site http://crwlr.net

Any help about bug submissions, property implementation, enhancements etc. is welcome.

What is crwlr.net
crwlr.net is a site about header indexing. It scans for IP blocks to find web servers and it indexes the header information the server discloses. So you can search for the IP's running Apache web server etc..

Any question is welcome.
bombshop
New User
New User
 
Posts: 8
Joined: Mon Mar 07, 2011 4:14 am
Blog: View Blog (0)


Re: Alpha testers wanted

Post by Goatboy on Mon Mar 07, 2011 4:57 am
([msg=54756]see Re: Alpha testers wanted[/msg])

Some of the links are generated incorrectly. For example, where it shows the latest IP that was scanned, it adds two dots and a space before the last octet, instead of just a single dot.
Mundus Vult Decipi
User avatar
Goatboy
Expert
Expert
 
Posts: 2443
Joined: Mon Jul 07, 2008 9:35 pm
Blog: View Blog (0)


Re: Alpha testers wanted

Post by bombshop on Mon Mar 07, 2011 4:58 am
([msg=54757]see Re: Alpha testers wanted[/msg])

Some of the links are generated incorrectly. For example, where it shows the latest IP that was scanned, it adds two dots and a space before the last octet, instead of just a single dot.


Fixed. Thank you for the quick heads up :)
bombshop
New User
New User
 
Posts: 8
Joined: Mon Mar 07, 2011 4:14 am
Blog: View Blog (0)


Re: Alpha testers wanted

Post by Goatboy on Mon Mar 07, 2011 5:06 am
([msg=54758]see Re: Alpha testers wanted[/msg])

I noticed that it took a while to scan the 190.24.148.X range. Specifically, it took 2 days to get from 190.24.148.142 to 190.24.148.160. Is this normal? How is scanning handled?
Mundus Vult Decipi
User avatar
Goatboy
Expert
Expert
 
Posts: 2443
Joined: Mon Jul 07, 2008 9:35 pm
Blog: View Blog (0)


Re: Alpha testers wanted

Post by bombshop on Mon Mar 07, 2011 5:12 am
([msg=54760]see Re: Alpha testers wanted[/msg])

For now the scanning is handled using php's built in functions. I didn't have time to write it in perl or something :oops:
Also i am having some server related problems, the code that run flawlessly on my home server gives me problems on my hosting account. The code stops executing after some undefined interval. After it i have to start it again. That's why it takes that long.
bombshop
New User
New User
 
Posts: 8
Joined: Mon Mar 07, 2011 4:14 am
Blog: View Blog (0)


Re: Alpha testers wanted

Post by Goatboy on Mon Mar 07, 2011 5:31 am
([msg=54761]see Re: Alpha testers wanted[/msg])

I found a bug. Visit the following URL: http://crwlr.net/?search=&q=herp''&[]=derp

It just redirects back to the main page for some reason.
Mundus Vult Decipi
User avatar
Goatboy
Expert
Expert
 
Posts: 2443
Joined: Mon Jul 07, 2008 9:35 pm
Blog: View Blog (0)


Re: Alpha testers wanted

Post by bombshop on Mon Mar 07, 2011 5:33 am
([msg=54762]see Re: Alpha testers wanted[/msg])

Hmm that's interesting, it redirected when i clicked on the link but it didn't redirect when i post the address to the address bar.. I'll see what causes it.
bombshop
New User
New User
 
Posts: 8
Joined: Mon Mar 07, 2011 4:14 am
Blog: View Blog (0)


Re: Alpha testers wanted

Post by Goatboy on Mon Mar 07, 2011 5:44 am
([msg=54763]see Re: Alpha testers wanted[/msg])

This is me with admin access (click for bigger images):

Image

Image

You are very vulnerable to both XSS and social engineering. The link I gave you was a cookie stealer. I promise I have not done anything malicious with this, but you should really look into it. I also entered my IP into the database with a custom HTTP header containing what will turn into a stored XSS attack if I am correct. Ciao.
Mundus Vult Decipi
User avatar
Goatboy
Expert
Expert
 
Posts: 2443
Joined: Mon Jul 07, 2008 9:35 pm
Blog: View Blog (0)


Re: Alpha testers wanted

Post by bombshop on Mon Mar 07, 2011 9:24 am
([msg=54769]see Re: Alpha testers wanted[/msg])

Wow that's nice work! Please let me understand, you could get the admin access while my cookie was valid or whenever you want? Thanks again, it is good to know that it is vulnerable :)
bombshop
New User
New User
 
Posts: 8
Joined: Mon Mar 07, 2011 4:14 am
Blog: View Blog (0)


Re: Alpha testers wanted

Post by jgreen45 on Mon Mar 07, 2011 11:01 am
([msg=54772]see Re: Alpha testers wanted[/msg])

Goatboy wrote:You are very vulnerable to both XSS and social engineering. The link I gave you was a cookie stealer. I promise I have not done anything malicious with this, but you should really look into it. I also entered my IP into the database with a custom HTTP header containing what will turn into a stored XSS attack if I am correct. Ciao.


Oh god, deja vu for the realistic missions :D
I can't come to bed...
Someone is WRONG on the internet


http://xkcd.com/386/
User avatar
jgreen45
Poster
Poster
 
Posts: 107
Joined: Wed Feb 25, 2009 6:18 pm
Blog: View Blog (0)


Next

Return to General

Who is online

Users browsing this forum: No registered users and 0 guests