Re: Website search engine is a hacking tool..

c0ntex_at_open-security.org
Date: 07/23/04

  • Next message: BillyBobKnob: "Simple script to test IE zones"
    Date: 23 Jul 2004 21:55:15 -0000
    To: pen-test@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) In-Reply-To: <20040722063551.GA30017@liderlink.net>

    >On Mon, Jul 19, 2004 at 08:06:21AM +0400, Amal Mohammad Al Hajeri wrote:
    >> Hi List,
    >>
    >> Did you ever thought of the website search engine as a hacking tool?
    >> During one of the pen-tests, The website search engine, was a valuable
    >> tool to discover interesting directories within the website itself,
    >> these directories were not detected by famous website scanners like
    >> nikto or SPI dynamics,i managed to get documentation pages about the API
    >> application implemented, management login pages, backup files and much
    >> more.

    I wrote a paper on search engine spiders a while back, it is a well known trick now but still a useful method for data mining, as you discovered :)

    http://open-security.org/texts/8_Legs.txt

    cheers
    c0ntex


  • Next message: BillyBobKnob: "Simple script to test IE zones"

    Relevant Pages

    • Get Maximum Traffic
      ... Aren't you tired of paying for clicks? ... Maximum Traffic enables you to generate a steady flow of customers to ... Maximum Traffic uses search engine optimization techniques that always ... Your website will not be banned for using Maximum Traffic to bring ...
      (alt.html)
    • Do The Search Engines Know Your Website?
      ... Are you considering a search engine promotion campaign to improve your ... Perhaps you may be thinking why do I need to check my website? ... Your checks should be done in the Google and Yahoo search engines ... Enter the "site" command and your website's URL in the ...
      (alt.html)
    • Which way is better to change my domain name so it doesnt affect my search engine rankings?
      ... rankings are mainly for one keyword phrase. ... about Search Engine Optimization, and decided to overhall my website. ... Google illudes me. ...
      (alt.internet.search-engines)
    • Re: Search Engine Optimisation ?
      ... then some other website and ranking of that other website. ... My questions is it worth paying to SEO corporation a $1200 - $3000 setup ... Google 'search engine friendly url'. ...
      (comp.lang.php)
    • Re: Why site optimization is required?
      ... website, and hope there business id run on there website, means querry, ... intrested to waste there preciouse time to collect your website address ... from you, they just go to the most trusted search engine like google, ... Google Groups emits some strange verbage sometimes. ...
      (alt.internet.search-engines)