Re: Finding non referenced web directories / pages

From: Michael Katz (mike@procinct.com)
Date: 03/14/02


Date: Thu, 14 Mar 2002 12:51:23 -0800
To: pen-test@securityfocus.com
From: Michael Katz <mike@procinct.com>

At 3/12/2002 01:41 AM, helmut schmidt wrote:

>Does anyone have opinions on which are the best tools/scripts are
>available to test for the existence of hidden (or non-referenced) web
>directories and web pages.
>
>For example finding a directory http://www.xxx.com/admin
>and hidden web page http://www.xxx.com/admin/admin.asp etc

The whisker tool (v1.4) from Rain Forest Puppy has a fairly extensive list
of directories for which it scans. Download the package from
http://www.wiretrip.net/rfp/p/doc.asp/i2/d21.htm and take a look at the
scan.db file.

Michael Katz
mike@procinct.com
Procinct Security

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • RE: SQL
    ... Subject: SQL ... >> This list is provided by the SecurityFocus Security ... For more information on SecurityFocus' SIA service which ... >This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Insurance
    ... property--data beign deemed "intangible" for the purposes of insurance. ... for physical security testing there are often 3rd parties ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Pen-Testing Lotus Notes/Domino
    ... Subject: Pen-Testing Lotus Notes/Domino ... of document security. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • R: Pen-Testing help (Compaq Insight & htsearch)
    ... This web server happens to be in front of their ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: Application & Iplanet/Apache web server vulnerability and penetration testing
    ... I don't know what to do on the web servers other than delete example ... Any suggestions on iPlanet and Apache security? ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)