<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>jikto source code</title>
        <description>Hi guys,

I was listening to the latest Security Now! (with Steve Gibson; hey, this guy has good intentions :P) and he mentioned about jikto source code being leaked out.
I would like to take a look. Anybody has a copy?</description>
        <link>http://sla.ckers.org/forum/read.php?11,9275,9275#msg-9275</link>
        <lastBuildDate>Tue, 18 Jun 2013 00:38:27 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9748#msg-9748</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9748#msg-9748</link>
            <description><![CDATA[You're not using it incorrectly, although technically you don't need a complex PHP controller for that simple purpose.  You can just grep through your logs looking for that string if that's all you're looking for.]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 08 Apr 2007 16:23:05 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9728#msg-9728</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9728#msg-9728</link>
            <description><![CDATA[I got jikto and everything<br />
<br />
I edited the jikto.js to direct to my control.txt<br />
<br />
the-cloak banned me within seconds so im using google translate even though im testing pages in the same domain<br />
<br />
with firebug i can see for example<br />
http://www.testdomainiamusing.com/jikto/control.txt1&amp;url=http%3A//www.testdomainiamusing.com%3A80/gallery/details.php%3Fimage_id%3D30&amp;method=GET<br />
<br />
looking at the code in jikto.js:<br />
<br />
function reportURL(method, url) {<br />
        var i = new Image();<br />
        i.src = GUIURL + &quot;1&amp;url=&quot; + escape(url) + &quot;&amp;method=&quot; + escape(method);  <br />
    }<br />
    <br />
    function reportVuln(method, url, sev, title, req, resp) {<br />
        var i = new Image();<br />
        i.src = GUIURL + &quot;2&amp;url=&quot;<br />
<br />
which means that unless I see &quot;http://www.testdomainiamusing.com/jikto/control.txt2&amp;url=&quot; <br />
it did not find a vulnerability<br />
<br />
i guess that's the way to do it without a controller, but someone above me said they wrote up a controller, can you post the source to the controller?<br />
<br />
or maybe im using the tool incorrectly?]]></description>
            <dc:creator>Royal2000H</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 08 Apr 2007 06:36:48 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9607#msg-9607</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9607#msg-9607</link>
            <description><![CDATA[Heh hopefully they know how to click a link. I mean the amount of people who PMed me even after you posted the link was ridiculous. Either they can't read or don't know how to use Google. I was asking myself this, if they cant even Google or read this page then how will they know how to use Jikto? I say someone make a post with links to known mirrors a sticky.]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Fri, 06 Apr 2007 13:37:40 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9605#msg-9605</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9605#msg-9605</link>
            <description><![CDATA[Mirror or Jikto -&gt; http://busin3ss.name/jikto-in-the-wild]]></description>
            <dc:creator>busin3ss</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Fri, 06 Apr 2007 13:01:38 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9561#msg-9561</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9561#msg-9561</link>
            <description><![CDATA[@CM<br />
<br />
Edit the post? ;)]]></description>
            <dc:creator>thrill</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Fri, 06 Apr 2007 00:36:20 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9559#msg-9559</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9559#msg-9559</link>
            <description><![CDATA[Note to everyone who comes to this post PMing me I am not responding to PMs for Jikto source anymore. If you can't be smart and use Google to find mirrors or even bother to read the posts on this page which clearly provides a working link to a copy of Jikto then I will ignore you. Come on people do we need our hands held for everything?]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Thu, 05 Apr 2007 23:50:22 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9439#msg-9439</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9439#msg-9439</link>
            <description><![CDATA[For those with reading disablilites:<br />
http://busin3ss.name/wp-content/uploads/2007/04/jitko.zip<br />
<br />
Greetings,<br />
.mario]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Tue, 03 Apr 2007 16:15:49 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9438#msg-9438</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9438#msg-9438</link>
            <description><![CDATA[I missed the download window. Anyone has the whole lot available for me, pls?]]></description>
            <dc:creator>Beetlejuice</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Tue, 03 Apr 2007 13:56:00 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9399#msg-9399</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9399#msg-9399</link>
            <description><![CDATA[Doesn't really do anything, I change the URL and nothing really occurs. Loads the site in an iframe and...nothing.]]></description>
            <dc:creator>Delixe</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 02 Apr 2007 16:52:38 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9396#msg-9396</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9396#msg-9396</link>
            <description><![CDATA[You can run it against localhost sites to test. You'll need to edit the sendRequest() function. The global variable &quot;prefix&quot; holds the URL prefixing for the proxying site. The code in the isLinkgood() function should prevent Jikto from getting out of control and scanning pages that aren't on localhost]]></description>
            <dc:creator>Acidus</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 02 Apr 2007 15:38:19 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9394#msg-9394</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9394#msg-9394</link>
            <description><![CDATA[&gt;&gt; wtf?<br />
&gt;&gt; [blogs.zdnet.com]<br />
<br />
oops]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 02 Apr 2007 15:03:10 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9393#msg-9393</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9393#msg-9393</link>
            <description><![CDATA[Downloading Firebug right know...<br />
<br />
For those who want to download the source code (Since all mirrors are offline):<br />
<br />
http://busin3ss.name/jikto-in-the-wild]]></description>
            <dc:creator>busin3ss</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 02 Apr 2007 15:02:04 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9391#msg-9391</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9391#msg-9391</link>
            <description><![CDATA[busin3ss, I'm testing on localhost like you did.<br />
You are most definitely doing something wrong, maybe didn't used rot13 or entered some bad URL or path or ?<br />
The script is working pretty nice, I'm watching the requests/responses with Firebug.<br />
You can even insert breakpoints and debug the code if you want. Firebug rocks!]]></description>
            <dc:creator>blad3</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 02 Apr 2007 14:51:42 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9388#msg-9388</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9388#msg-9388</link>
            <description><![CDATA[Ryan Naraine Wrote:<br />
-------------------------------------------------------<br />
&gt; The code has since been posted to the Sla.ckers.org forum. <br />
&gt; Hacker RSnake discusses nippets of the code, which can be <br />
&gt; used to hunt for common security holes and then connect <br />
&gt; back to its controller for instructions on which Web sites <br />
&gt; to hit and &gt;which flaws to look for.<br />
<br />
Hahahaha...]]></description>
            <dc:creator>busin3ss</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 02 Apr 2007 14:37:43 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9383#msg-9383</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9383#msg-9383</link>
            <description><![CDATA[wtf?<br />
http://blogs.zdnet.com/security/?p=146]]></description>
            <dc:creator>blad3</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 02 Apr 2007 14:14:31 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9382#msg-9382</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9382#msg-9382</link>
            <description><![CDATA[Well there are four files, I just coded a quick php file to replace control control.txt and changed the var GUIURL.<br />
<br />
I'm trying without using a &quot;proxy&quot;, I'm scanning a site in the same domain (To bypass the Same Origin Policy)... But I get this weird javascript errors<br />
<br />
Is there any chance that I can see a working demo blad3? Just to see how your are testing]]></description>
            <dc:creator>busin3ss</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 02 Apr 2007 14:04:40 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9381#msg-9381</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9381#msg-9381</link>
            <description><![CDATA[I did some tests. What problems do you have?]]></description>
            <dc:creator>blad3</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 02 Apr 2007 13:56:54 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9379#msg-9379</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9379#msg-9379</link>
            <description><![CDATA[Anyone playing with this tool?  I need some guidance :)]]></description>
            <dc:creator>busin3ss</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 02 Apr 2007 13:43:41 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9338#msg-9338</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9338#msg-9338</link>
            <description><![CDATA[Here are the slides<br />
http://www.spidynamics.com/spilabs/education/presentations/Javascript_malware.pdf]]></description>
            <dc:creator>blad3</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 02 Apr 2007 02:33:06 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9334#msg-9334</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9334#msg-9334</link>
            <description><![CDATA[Taking my server down, anyone want copy PM me.<br />
<br />
UPDATE: please read http://sla.ckers.org/forum/read.php?11,9275,9326#msg-9559]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 02 Apr 2007 00:07:51 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9333#msg-9333</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9333#msg-9333</link>
            <description><![CDATA[Interesting how the jikto control was changed!  Already being used by a number of people I see.]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 01 Apr 2007 23:32:04 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9331#msg-9331</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9331#msg-9331</link>
            <description><![CDATA[Anyone else want a copy before I take it down?]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 01 Apr 2007 21:39:36 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9329#msg-9329</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9329#msg-9329</link>
            <description><![CDATA[Fukken Saved! I was wondering when the actual source would be available as it was supposed to be out around the 25th, and I knew they had already presented it to the public.]]></description>
            <dc:creator>Awesome AnDrEw</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 01 Apr 2007 20:10:55 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9326#msg-9326</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9326#msg-9326</link>
            <description><![CDATA[[URL REMOVED] Please look elswhere<br />
<br />
btw this is not an April Fools Joke. Tell if if server is not responding or not. Its on my home server so kinda unreliable. Make backup because will take server down after you check.]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 01 Apr 2007 18:46:53 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9324#msg-9324</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9324#msg-9324</link>
            <description><![CDATA[I have a backup I thought they might take it down. Seeing they were asking people to take it off their sites.]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 01 Apr 2007 18:36:45 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9301#msg-9301</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9301#msg-9301</link>
            <description><![CDATA[1st of april??]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 01 Apr 2007 14:16:21 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9300#msg-9300</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9300#msg-9300</link>
            <description><![CDATA[I'd like to see the source also.  Anyone have it?]]></description>
            <dc:creator>Henaro</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 01 Apr 2007 14:14:13 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9299#msg-9299</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9299#msg-9299</link>
            <description><![CDATA[damnit - down already. did you backup the files?]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 01 Apr 2007 14:11:17 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9285#msg-9285</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9285#msg-9285</link>
            <description><![CDATA[http://www.pentest.it/jikto/ other files]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 01 Apr 2007 08:28:34 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,9275,9284#msg-9284</guid>
            <title>Re: jikto source code</title>
            <link>http://sla.ckers.org/forum/read.php?11,9275,9284#msg-9284</link>
            <description><![CDATA[Is this it? http://www.pentest.it/jikto/jikto.js]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 01 Apr 2007 08:27:40 -0500</pubDate>
        </item>
    </channel>
</rss>
