The document presents a new tool called Spider-Pig that can identify web applications connected to a target company through business relationships rather than just technical information. Spider-Pig uses a scored keyword list to search for links and crawl results, identifying over 150,000 domain names related to a large test company. The automated tool found 223 confirmed web applications, including some hosted externally, and identified vulnerabilities without requiring human interaction beyond the initial keyword list.
Related topics: