Closed GoogleCodeExporter closed 9 years ago
side comment - this was with skipfish 1.32-0.4.b.fc12, installed via the fedora
repo
making it really easy to get started!
Original comment by binarymo...@gmail.com
on 17 May 2010 at 8:22
To look forward to see the feature.
Original comment by silver.z...@gmail.com
on 27 May 2010 at 2:26
Skipfish currently does not support JavaScript, and realistically, there are
limits to what JS support in an automated scanner can achieve: most JS-enabled
scanners can execute onload handlers and so forth, but they are completely
oblivious to the right way to interact with complex client-side UIs, etc.
To scratch that itch, you might find it more useful to give ratproxy a try.
Original comment by lcam...@gmail.com
on 23 Nov 2010 at 6:48
Javascript has been very much on my mind lately (e.g. link against v8) but as
Michal indicated, without using a full browser, the benefits will be limited.
Next step here is to see how much effort it actually is and what the benefits
on a crawler and detection (e.g. DOM xss) level will be before starting with
an implementation.
Given that there is no immediate action here; in combination with JS support
being on the wishlist but not actively worked on now; I propose to close out
this issue (and revive it when the time comes).
Original comment by niels.he...@gmail.com
on 2 Sep 2012 at 12:33
Original issue reported on code.google.com by
binarymo...@gmail.com
on 17 May 2010 at 8:12