Ok pour le module, mais pourquoi tu avais marqué :
Citation:
tu essaye d'appeler un module quelque part d'autre, je te conseille avec un proxy du genre burp ou webscarab, de voir si ce que tu envoi n'est pas modifié client side avant que les requetes arrive sur le serveur.
Ensuite, pour w3af : le résultat est le suivante.
Code:
[lun. 30 juil. 2012 16:28:26 PMT] Auto-enabling plugin: grep.collectCookies
[lun. 30 juil. 2012 16:28:26 PMT] Auto-enabling plugin: grep.httpAuthDetect
[lun. 30 juil. 2012 16:28:26 PMT] Auto-enabling plugin: grep.error500
[lun. 30 juil. 2012 16:28:26 PMT] Auto-enabling plugin: discovery.serverHeader
[lun. 30 juil. 2012 16:28:26 PMT] Auto-enabling plugin: discovery.allowedMethods
[lun. 30 juil. 2012 16:28:26 PMT] Auto-enabling plugin: discovery.frontpage_version
[lun. 30 juil. 2012 16:28:30 PMT] The server header for the remote web server is: "Apache/2.2.22/DataZone SP (Unix) mod_zfpm/0.2". This information was found in the request with id 18.
[lun. 30 juil. 2012 16:28:42 PMT] The URL: "http://www.sitevictime.info/" has the following DAV methods enabled:
[lun. 30 juil. 2012 16:28:42 PMT] - *, ACL, BASELINE_CONTROL, CHECKIN, CHECKOUT, CONNECT, COPY, DEBUG, GET, HEAD, INDEX, INVALID, INVOKE, LABEL, LINK, LOCK, MERGE, MKACTIVITY, MKCOL, MKDIR, MKWORKSPACE, MOVE, NOTIFY, OPTIONS, PATCH, PIN, POLL, POST, PROPFIND, PROPPATCH, REPLY, REPORT, RMDIR, SEARCH, SHOWMETHOD, SPACEJUMP, SUBSCRIBE, SUBSCRIPTIONS, TEXTSEARCH, TRACK, UNCHECKOUT, UNLINK, UNLOCK, UNSUBSCRIBE, VERSION_CONTROL
[lun. 30 juil. 2012 16:28:42 PMT] Found 2 URLs and 4 different points of injection.
[lun. 30 juil. 2012 16:28:42 PMT] The list of URLs is:
[lun. 30 juil. 2012 16:28:42 PMT] - http://www.sitevictime.info
[lun. 30 juil. 2012 16:28:42 PMT] - http://www.google.ee/custom
[lun. 30 juil. 2012 16:28:42 PMT] The list of fuzzable requests is:
[lun. 30 juil. 2012 16:28:42 PMT] - http://www.sitevictime.info | Method: GET
[lun. 30 juil. 2012 16:28:42 PMT] - http://www.google.ee/custom | Method: GET | Parameters: (oe="iso-8859-1", client="pub-647282...", q="", forid="1", hl="en", cof="GALT:#0080...", domains="www.sitevictime...", sitesearch="", ie="iso-8859-1")
[lun. 30 juil. 2012 16:28:42 PMT] - http://www.google.ee/custom | Method: GET | Parameters: (oe="iso-8859-1", client="pub-647282...", q="", forid="1", hl="en", cof="GALT:#0080...", domains="www.sitevictime...", sitesearch="www.sitevictime...", ie="iso-8859-1")
[lun. 30 juil. 2012 16:28:42 PMT] - http://www.google.ee/custom | Method: GET | Parameters: (oe="iso-8859-1", client="pub-647282...", q="", forid="1", hl="en", cof="GALT:#0080...", domains="www.sitevictime...", sitesearch="www.sitevictime...", sitesearch="", ie="iso-8859-1")
[lun. 30 juil. 2012 16:28:42 PMT] The web application sent a persistent cookie.
[lun. 30 juil. 2012 16:28:42 PMT] The following scripts are vulnerable to a trivial form of XSRF:
[lun. 30 juil. 2012 16:28:42 PMT] - http://www.google.ee/custom
[lun. 30 juil. 2012 16:29:03 PMT] The URL: http://www.google.ee/custom is vulnerable to cross site request forgery.
[lun. 30 juil. 2012 16:29:03 PMT] The server header for the remote web server is: "Apache/2.2.22/DataZone SP (Unix) mod_zfpm/0.2". This information was found in the request with id 18.
[lun. 30 juil. 2012 16:29:03 PMT] The URL "http://www.sitevictime.info/" has the following allowed methods, which include DAV methods: *, ACL, BASELINE_CONTROL, CHECKIN, CHECKOUT, CONNECT, COPY, DEBUG, GET, HEAD, INDEX, INVALID, INVOKE, LABEL, LINK, LOCK, MERGE, MKACTIVITY, MKCOL, MKDIR, MKWORKSPACE, MOVE, NOTIFY, OPTIONS, PATCH, PIN, POLL, POST, PROPFIND, PROPPATCH, REPLY, REPORT, RMDIR, SEARCH, SHOWMETHOD, SPACEJUMP, SUBSCRIBE, SUBSCRIPTIONS, TEXTSEARCH, TRACK, UNCHECKOUT, UNLINK, UNLOCK, UNSUBSCRIBE, VERSION_CONTROL.
[lun. 30 juil. 2012 16:29:03 PMT] The URL: "http://www.sitevictime.info" sent the cookie: "PHPSESSID=ca4f2d91067aac2c8e2a025a8bc80be6; path=/". This information was found in the request with id 2.
[lun. 30 juil. 2012 16:29:22 PMT] A possible ReDoS was found at: "http://www.google.ee/custom", using HTTP method GET. The sent data was: "oe=iso-8859-1&client=pub-6472823573423448&q=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaXX%21&forid=1&hl=en&cof=GALT:%23008000%3BGL:1%3BDIV:%23336699%3BVLC:663399%3BAH:center%3BBGC:FFFFFF%3BLBGC:336699%3BALC:0000FF%3BLC:0000FF%3BT:000000%3BGFNT:0000FF%3BGIMP:0000FF%3BFORID:1&domains=www.sitevictime.info&sa=Search&sitesearch=&ie=iso-8859-1". The modified parameter was "q". . Please review manually. This information was found in the request with id 817.
[lun. 30 juil. 2012 16:31:12 PMT] OS Commanding was found at: "http://www.google.ee/custom", using HTTP method GET. The sent data was: "oe=iso-8859-1&client=pub-6472823573423448&q=/bin/cat+/etc/passwd&forid=1&hl=en&cof=GALT:%23008000%3BGL:1%3BDIV:%23336699%3BVLC:663399%3BAH:center%3BBGC:FFFFFF%3BLBGC:336699%3BALC:0000FF%3BLC:0000FF%3BT:000000%3BGFNT:0000FF%3BGIMP:0000FF%3BFORID:1&domains=www.sitevictime.info&sa=Search&sitesearch=&ie=iso-8859-1". The modified parameter was "q". This vulnerability was found in the request with id 1298.
[lun. 30 juil. 2012 16:31:31 PMT] eval() input injection was found at: "http://www.google.ee/custom", using HTTP method GET. The sent data was: "oe=iso-8859-1&client=pub-6472823573423448&q=Thread.Sleep(9000)%3B&forid=1&hl=en&cof=GALT:%23008000%3BGL:1%3BDIV:%23336699%3BVLC:663399%3BAH:center%3BBGC:FFFFFF%3BLBGC:336699%3BALC:0000FF%3BLC:0000FF%3BT:000000%3BGFNT:0000FF%3BGIMP:0000FF%3BFORID:1&domains=www.sitevictime.info&sa=Search&sitesearch=&ie=iso-8859-1". The modified parameter was "q". . Please review manually. This information was found in the request with id 1867.
[lun. 30 juil. 2012 16:34:06 PMT] The URL: "http://www.sitevictime.info" sent these cookies:
[lun. 30 juil. 2012 16:34:06 PMT] - PHPSESSID=ca4f2d91067aac2c8e2a025a8bc80be6; path=/
[lun. 30 juil. 2012 16:34:06 PMT] - PHPSESSID=ca4f2d91067aac2c8e2a025a8bc80be6; Path=/
[lun. 30 juil. 2012 16:34:06 PMT] Finished scanning process.
Je comprends pas pourquoi il met l'URL
http://www.google.ee/custom ?
NotF0und!