URLs Indirectly Referred During Successful Login In CC&B 2.4.0.3 (Doc ID 2283865.1)

Last updated on JULY 10, 2017

Applies to:

Oracle Utilities Customer Care and Billing - Version 2.4.0.3.0 and later
Information in this document applies to any platform.

Goal

  1. Find below some of the URLs which are automatically loaded within the proxy server used  , upon authenticating on billing.eac.org web application. The rest can be found into the attached file.
http://action.attavik.ca/home/justice-gn/attach/2007/gaz02part2.pdf
http://actualidad.terra.es/sociedad/articulo/cuba_llama_ahorrar_energia_cambio_1957044.htm
http://adsabs.harvard.edu/full/1932JRASC..26...49S
http://dmses.dot.gov/docimages/p63/135818.pdf
http://dmses.dot.gov/docimages/pdf95/382329_web.pdf
http://dof.gob.mx/nota_detalle.php?codigo=5127480&fecha=06/01/2010
http://evols.library.manoa.hawaii.edu/
http://evols.library.manoa.hawaii.edu/bitstream/10524/239/2/JL26215.pdf
http://f1-getfeatureconfiguration/
http://f1-getfeatureconfiguration/options
http://frwebgate.access.gpo.gov/
http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=1999_register&docid=fr21oc99-15
http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=2000_register&docid=fr17au00-22
http://gaceta.diputados.gob.mx/
http://gaceta.diputados.gob.mx/Gaceta
http://gaceta.diputados.gob.mx/Gaceta/61
http://gaceta.diputados.gob.mx/Gaceta/61/2009
http://gaceta.diputados.gob.mx/Gaceta/61/2009/dic
http://gaceta.diputados.gob.mx/Gaceta/61/2009/dic/20091210-V.pdf
http://gaceta.diputados.gob.mx/Gaceta/61/2009/dic/V2-101209.html
etc...


These URLs are logged only after successful login to the web application, and only when “passive spidering” is enabled. More information on Passive Spidering can be found here:
https://portswigger.net/burp/help/spider_options.html#passive

There are 80+ URLs which seem to be indirectly referred from the Web application. The text file contains the URLs.

Note that there have been removed the “expected” URLs/domains from the list (i.e. w3.org, debian.org etc.) and only kept the ones which seemed irrelevant to the application. 


Solution

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms