Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 419731 - dev-util/skipfish-2.07b version bump
Summary: dev-util/skipfish-2.07b version bump
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: No maintainer - Look at https://wiki.gentoo.org/wiki/Project:Proxy_Maintainers if you want to take care of it
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-06-05 09:46 UTC by Paolo Pedroni
Modified: 2012-06-05 17:45 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Paolo Pedroni 2012-06-05 09:46:10 UTC
There is a new version of skipfish (2.07b) on the site.

ChangeLog:
- A horrible bug fix which caused instable pages not be marked as such. The result: false positives.
- A change to fprint_response() will help reduce false positives that could occur for differential tests (i.e. the query and shell injection tests)
- We now suppress implicit cache warnings when dealing with 302, 303 and 307 redirects.
- Added --no-checks which allows a scan to be run without any injection tests. This still allows bruteforcing and combines well with the new ability to load URLs from previous scan results.
- We can now parse the pivots.txt, which can be found in the output directory of older scans. All URLs will be loaded which seriously speeds up recurring scans.
- Directory bruteforcing now includes a content negotiation trick where using a fake mime in the Accept: header will cause some servers to propose us files via a 406 response.

Renaming the current ebuild seems to work fine.
Comment 1 Michael Weber (RETIRED) gentoo-dev 2012-06-05 17:45:59 UTC
+*skipfish-2.07_beta (05 Jun 2012)
+
+  05 Jun 2012; Michael Weber <xmw@gentoo.org> +skipfish-2.07_beta.ebuild:
+  Version bump (thanks Paolo Pedroni, bug 419731)
+