Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




pen-test logo Penetration Testing mailing list archives

Website search engine is a hacking tool..
From: Amal Mohammad Al Hajeri <amal () nis etisalat ae>
Date: Mon, 19 Jul 2004 08:06:21 +0400

Hi List,

Did you ever thought of the website search engine as a hacking tool?
During one of the pen-tests, The website search engine, was a valuable
tool to discover interesting directories within the website itself,
these directories were not detected by famous website scanners like
nikto or SPI dynamics,i managed to get documentation pages about the API
application implemented, management login pages, backup files and much
more.
I leave it to your imagination to search for words like:
password,login,oracle,database,administrator, backup...etc

Best Regards,

 
-----------------------------------
Amal M. Al-Hajeri
E/Network & Information Security
Etisalat





  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]