broken-link-checker icon indicating copy to clipboard operation
broken-link-checker copied to clipboard

Document broken link hijacking

Open AnotherWayIn opened this issue 6 years ago • 9 comments

Awesome tool. Any chance you could make it accept a list of URLs and run multi threaded please?

AnotherWayIn avatar Aug 30 '18 08:08 AnotherWayIn

A list of URLs for what purpose?

The requests are already multi-threaded thanks to libuv.

stevenvachon avatar Aug 30 '18 12:08 stevenvachon

I’m using it for pentesting a large scope of web apps. Thanks

Sent from my iPhone

On 30 Aug 2018, at 20:28, Steven Vachon <[email protected]mailto:[email protected]> wrote:

A list of URLs for what purpose?

The requests are already multi-threaded thanks to libuvhttps://github.com/libuv/libuv.

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/stevenvachon/broken-link-checker/issues/124#issuecomment-417301479, or mute the threadhttps://github.com/notifications/unsubscribe-auth/AKA6ORmdZ31NmuCB_kadYW0CK2_yse3Jks5uV9ptgaJpZM4WS-mK.

AnotherWayIn avatar Aug 30 '18 12:08 AnotherWayIn

Why not simply use curl?

stevenvachon avatar Aug 30 '18 12:08 stevenvachon

I don’t understand. Could you give an example? If curl could achieve the same results in a quicker way, then what value does this tool add?

All I need is a fast method of finding broken links across many apps

Sent from my iPhone

On 30 Aug 2018, at 20:48, Steven Vachon <[email protected]mailto:[email protected]> wrote:

Why not simply use curl?

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/stevenvachon/broken-link-checker/issues/124#issuecomment-417307252, or mute the threadhttps://github.com/notifications/unsubscribe-auth/AKA6OVUhGZMiX_yPESYUxBB-F7dpS3X4ks5uV98sgaJpZM4WS-mK.

AnotherWayIn avatar Aug 30 '18 13:08 AnotherWayIn

I'm pretty sure that finding broken links is not a penetration test.

If all you want is to test multiple sites, you can do so with multiple commands in a shell script or batch file.

stevenvachon avatar Aug 30 '18 13:08 stevenvachon

It's okay, you obviously don't understand the implications of having broken links in your apps, from a security perspective.

AnotherWayIn avatar Aug 30 '18 13:08 AnotherWayIn

If you have security related broken links, then you probably have XSS issues.

stevenvachon avatar Aug 30 '18 13:08 stevenvachon

Partly. It'll be easier if I provide a link with specific examples using this tool: https://edoverflow.com/2017/broken-link-hijacking/

AnotherWayIn avatar Aug 30 '18 13:08 AnotherWayIn

Thank you. I'll look into this further at a later time.

stevenvachon avatar Aug 30 '18 13:08 stevenvachon