Just now when I was looking for a cool SiteMap generator, I found this XML-SiteMaps.com. It’s cool enough with it’s nice interface, and so I submitted my site URL (Not http://zoiz.web.id). And of course clicking on the Start button, and so the crawler start doing it’s jobs. A minute later, the XML SiteMap output was generated. And I submitted it to Google Webmasters Tools.

So where is the Denial Of Service part? Aha! Sorry to keep you read all the nonsenses above :P But did you notice something interesting in my story? If you don’t maybe I can share you mine. Crawling a site cost more process usage. So the point is, if you can find CSFR (Cross Site Request Forgery) on a SiteMap Generator Site and write an automated script requesting numerous crawl on a victim site will give the victim system a hard punch (drain it’s resources). The result is the same as Denial Of Service.

Original Idea By : Zoiz [at] HackingForte.org

Tagged with:  

7 Responses to “CSRF on SiteMap Generator Engine = Denial Of Service?”

  1. lain says:

    aha, finally you ‘re playing on CSRF ;)
    a lot of fun there! >:)

  2. Zoiz says:

    hehehe.. I just wrote a simple program to automated this attack :P

  3. [...] you have read my previous article about CSRF on SiteMap Engine to launch a Denial Of Service (Sorry for my noob-ness that I targeted DoS to exhaust server bandwith). This time I am going to [...]

  4. JKR says:

    haha..cool bro..

    let c what u got next

    roflmao :D

  5. [...] you have read my previous article about CSRF on SiteMap Engine to launch a Denial Of Service (Sorry for my noob-ness that I targeted DoS to exhaust server bandwith). This time I am going to [...]

  6. ymm0t says:

    Yaaaay! WordPress has filtered it

Leave a Reply