<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/securitysoftware/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Scrawlr</title><link>http://www.communities.hp.com/securitysoftware/forums/198.aspx</link><description>Discussions related to the Scrawlr tool and it's use</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Re: Scrawlr Rants and Raves</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/101328.aspx</link><pubDate>Tue, 08 Sep 2009 19:47:57 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:101328</guid><dc:creator>efelsenthal</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/101328.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=101328</wfw:commentRss><description>&lt;p&gt;I found plenty of vulnerable pages on my site and fixed them thanks to scrawlr.&amp;nbsp; It was also useful to get me thinking along the lines that I better validate any forms data before sending it to a SQL command.&amp;nbsp; I used both truncation and replace statements to fix up my code.&amp;nbsp; Funny thing is that the best test to see if all my fixes work will be if I get re-injected!&amp;nbsp; I am using the injection attack as the ultimate test of my website.&amp;nbsp; The bad people are sending my website users to x.18x.com&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Scrawlr Rants and Raves</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/84006.aspx</link><pubDate>Fri, 25 Jul 2008 04:16:23 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:84006</guid><dc:creator>StephenKelly2000</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/84006.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=84006</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;IT would be good, if there was a simple one or two pages about how the basic process worked, as it is not finding some links on one site we were testing it on. (which to us appeared as normal links that a crawler should have found).&lt;/p&gt;&lt;p&gt;Thanks&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Steve &lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Scrawlr Rants and Raves</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/83976.aspx</link><pubDate>Wed, 23 Jul 2008 07:53:19 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83976</guid><dc:creator>Biscount92</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/83976.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=83976</wfw:commentRss><description>&lt;p&gt;I ran scrawlr on my site as I had already been infected once with fgg.js&lt;br /&gt;However the page that was infected was not in the list of pages scanned&lt;/p&gt;
&lt;p&gt;The site is &lt;a href="http://www.biscount.com/"&gt;www.biscount.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;the folder in question is down loads&lt;/p&gt;
&lt;p&gt;it contains the following files&lt;/p&gt;
&lt;p&gt;beta.htm&lt;br /&gt;flash.htm&lt;br /&gt;hhwebinstall.htm&lt;br /&gt;L10HC_FlashParams.txt&lt;br /&gt;news.html&lt;br /&gt;update_notes.htm&lt;br /&gt;vb6_page.htm&lt;br /&gt;welcome.html&lt;/p&gt;
&lt;p&gt;scrawler only scans &lt;/p&gt;
&lt;p&gt;news.html&lt;br /&gt;hhwebinstall.htm&lt;br /&gt;vb6_page.htm&lt;br /&gt;beta.htm&lt;br /&gt;update_notes.htm&lt;/p&gt;
&lt;p&gt;it misses &lt;/p&gt;
&lt;p&gt;welcome.html&lt;br /&gt;flash.htm&lt;br /&gt;L10HC_FlashParams.txt&lt;/p&gt;
&lt;p&gt;and welcome.html is the file that was infected - how is your program useful if it misses pages that are vunerable?&lt;/p&gt;
&lt;p&gt;Any ideas what is the problem?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Scrawlr Rants and Raves</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/83393.aspx</link><pubDate>Wed, 25 Jun 2008 01:14:13 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:83393</guid><dc:creator>erik.peterson</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/83393.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=198&amp;PostID=83393</wfw:commentRss><description>&lt;p&gt;Let us know what you would like to see improved, questions on how best to use the tool or anything else. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>