Website search engine is a hacking tool..

From: Amal Mohammad Al Hajeri (amal_at_nis.etisalat.ae)
Date: 07/19/04

  • Next message: easternerd: "RE: Find out the subnetting of a company"
    To: pen-test@securityfocus.com
    Date: Mon, 19 Jul 2004 08:06:21 +0400
    
    

    Hi List,

    Did you ever thought of the website search engine as a hacking tool?
    During one of the pen-tests, The website search engine, was a valuable
    tool to discover interesting directories within the website itself,
    these directories were not detected by famous website scanners like
    nikto or SPI dynamics,i managed to get documentation pages about the API
    application implemented, management login pages, backup files and much
    more.
    I leave it to your imagination to search for words like:
    password,login,oracle,database,administrator, backup...etc

    Best Regards,

     
    -----------------------------------
    Amal M. Al-Hajeri
    E/Network & Information Security
    Etisalat


  • Next message: easternerd: "RE: Find out the subnetting of a company"