WA R N I N G
In some applications, running even a simple web spider that
parses and requests links can be extremely dangerous. For example, an
application may contain administrative functionality that deletes users, shuts
down a database, restarts the server, and the like. If an application-aware
spider is used, great damage can be done if the spider discovers and uses
sensitive functionality. The authors have encountered an application that
included functionality to edit the actual content of the main application. This
functionality was discoverable via the site map and was not protected by any
access control. If an automated spider were run against this site, it would find
the edit function and begin sending arbitrary data, resulting in the main web
site being defaced in real time while the spider was running.
Do'stlaringiz bilan baham: |