WebApp Sec mailing list archives

How to list all the URLs on a web server


From: Lists <sakaba () alexandria cc>
Date: Sat, 8 Jan 2005 01:35:08 +0900

Hi Everyone,

I am auditing a system where files are stored on a web server and accessed without authentication directly by an application that knows each file URL. I don't like it but the app owner wants me to demonstrate that someone could guess the URLs. I have tried a number of spider tools but they are based on links so they don't pull up anything.

I am wondering if there is a tool or another method where I could find out all the URLs on the web site. The funny thing is I saw this same kind of system with the same explanation just the other week at another company. Maybe its a new trend...

Regards,
sakaba


Current thread: