HTTP Cross Domain Policy File Scanner

HTTP Cross Domain Policy File Scanner

Short Info


Level

Informational

Single Scan

Single Scan

Can be used by

Everyone

Estimated Time

15 seconds

Time Interval

3 days

Scan only one

Domain, IPv4, Subdomain

Toolbox

-

Checks the cross-domain policy file (/crossdomain.xml) and the client-acces-policy file (/clientaccesspolicy.xml) in web applications and lists the trusted domains. Overly permissive settings enable Cross Site Request Forgery attacks and may allow attackers to access sensitive data. This script is useful to detect permissive configurations and possible domain names available for purchase to exploit the application.

The script queries instantdomainsearch.com to lookup the domains. This functionality is turned off by default, to enable it set the script argument http-cross-domain-policy.domain-lookup.

References:

  •  
Get started to protecting your Free Full Security Scan