Re: [NEW] security/skipfish

2015-07-27 Thread Bryan C. Everly
Stuart, I believe I have incorporated the changes you suggested in the attached tarball. If you could please look it over and give me feedback, I'd appreciate it. Thanks, Bryan On Mon, Jul 27, 2015 at 7:10 AM, Stuart Henderson wrote: > On 2015/07/26 15:22, Bryan C. Everly wrote: >> Steven, >>

Re: [NEW] security/skipfish

2015-07-27 Thread Bryan C. Everly
Stuart, Thanks for pointing me towards arc4random_uniform(). After reading the manpage that makes perfect sense. I'll make that change and the others you suggest and resubmit. What's the typical rhythm for ports changes going in? First 3 months post release? Thanks, Bryan On Mon, Jul 27, 20

Re: [NEW] security/skipfish

2015-07-27 Thread Stuart Henderson
On 2015/07/26 15:22, Bryan C. Everly wrote: > Steven, > > My apologies. I missed your arc4random() comment in the original > message. The attached tarball contains all of your suggestions now. : -#define R(_ceil) ((u32)(random() % (_ceil))) : +#define R(_ceil) ((u32)(arc4random() % (_ceil))) t

Re: [NEW] security/skipfish

2015-07-26 Thread Bryan C. Everly
Steven, My apologies. I missed your arc4random() comment in the original message. The attached tarball contains all of your suggestions now. Thanks, Bryan On Sun, Jul 26, 2015 at 2:35 PM, Bryan C. Everly wrote: > Steven, > > Thanks for your feedback! > > If you wouldn't mind taking a look at

Re: [NEW] security/skipfish

2015-07-26 Thread Bryan C. Everly
Steven, Thanks for your feedback! If you wouldn't mind taking a look at the attached to see if I got everything correct, I'd appreciate it. If it's good, are you ok committing it on my behalf? Thanks, Bryan On Sun, Jul 26, 2015 at 5:16 AM, Steven Mestdagh wrote: > Bryan C. Everly [2015-07-25

Re: [NEW] security/skipfish

2015-07-26 Thread Steven Mestdagh
Bryan C. Everly [2015-07-25, 12:52:21]: > $COMMENT: active web application security reconnaissance tool > > pkg/DESCR: > > Skipfish is an active web application security reconnaissance tool. It > prepares an interactive sitemap for the targeted site by carrying out > a recursive crawl and diction

[NEW] security/skipfish

2015-07-25 Thread Bryan C. Everly
$COMMENT: active web application security reconnaissance tool pkg/DESCR: Skipfish is an active web application security reconnaissance tool. It prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and dictionary-based probes. The resulting map is then annotated