Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Re: Website "Scanner"

Re: Website "Scanner"

From: Javier Fernandez-Sanguino <jfernandez_at_germinus.com>
Date: Thu, 09 Jan 2003 13:57:14 +0100

sullo_at_cirt.net wrote:

>Quoting backed.up.by.2048.bit.encryption_at_hushmail.com:
>
>
>>Is there anything out there like a port scanner but for websites, where it
>>dictionary attacks the files. For example you plug in the domain:
>>
>>
>
>Not that I know of. The closest I can think of are two functions I have in
>Nikto, which can do two similar things currently:
>1) guess Apache user names in a similar manner
> For example
> ~a
> ~aa
> etc
>
>
Well, the user enumeration plugin could be trivially be modified to do a
brute force attack of filenames too. The problem being, however, that
the number of requests you are going to make are quite high (and
increase exponentially). Maybe it would be better to try to first index
the site (spider like), and then attempt to retrieve "mutated"
filenames. For example, if you see index.html try: index.html.old,
index.html.bak...

Regards

Javi
Received on Jan 10 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos