Bug#884733: dirb - request for features (patch included)

Philippe Thierry phil at reseau-libre.net
Mon Dec 18 20:53:38 UTC 2017


Package: dirb
Version: 2.22+dfsg-2
Severity: wishlist
Tags: patch

See attached message for more info. 


-------- Message d'origine --------
De : Mathieu BAEUMLER <mbaeumler at excellium-services.com>
Envoyé : 13 décembre 2017 10:26:59 GMT+01:00
À : "phil at reseau-libre.net" <phil at reseau-libre.net>
Objet : dirb - request for features (patch included)

Hello,

One of the tools I happen to use sometimes on Kali is dirb. In two specific cases, I needed two options from the libcurl:

-          CURLOPT_PATH_AS_IS : don't squash/merge /../ ./ sequences in the path, useful when there is a directory traversal vulnerability

-          CURLOPT_SSLCERT : use a client certificate

I implemented the needed changes, with the resulting two quilt patches (path-as-is.patch to be applied before client_cert.patch).

Could you include them in the debian/kali package?

Regards,

--
Mathieu Baeumler

-- 
 O       Philippe Thierry. 
/Y\/   GPG: 7010 9a3c e210 763e 6341 4581 c257 b91b cdaf c1ea
o#o
-------------- next part --------------
A non-text attachment was scrubbed...
Name: client_cert.patch
Type: application/octet-stream
Size: 3545 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-security-team/attachments/20171218/a5f5183b/attachment-0003.obj>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: path-as-is.patch
Type: application/octet-stream
Size: 3165 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-security-team/attachments/20171218/a5f5183b/attachment-0004.obj>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: series
Type: application/octet-stream
Size: 171 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-security-team/attachments/20171218/a5f5183b/attachment-0005.obj>


More information about the Pkg-security-team mailing list