> Just a thought. I've often wanted a tool that I could > point at a site, let run for a few hours, and come > back with a probably list of server side scripts to poke at. > Be nice if it produced lists of variables, too, while I'm > asking... > > BB Sanctum Inc's AppScan has exactly this functionalty, as part of its web application security audit capabilities. Take a look at AppScan: http://www.sanctuminc.com/solutions/appscan/ind ex.html Thanks, Security Forums Group Sanctum Inc Tel: 408 855 9500 x206 email: securityforumsat_private www.sanctuminc.com
This archive was generated by hypermail 2b30 : Thu Jun 14 2001 - 14:30:53 PDT