RE: Website detection



We are doing a PT for one of our customers with 5 webservers. None of
these webservers have the website
on the main url like http://xxx.xxx.xxx.xxx but they have confirmed that
they have critical applications
running on all the 5 web servers and for security purposes they have moved
the websites to something
like http://xxx.xxx.xxx.xxx/yyy.

That's a finding in and of itself. Security through obscurity might keep
automated scanners at bay, but it's akin to having an anonymous ftp server
running on port 24. It's still potentially vulnerable even though you have
to jump through extra hoops to find it.

Now manually I guess it will take years to identify the correct URL having
the critical website by using
guessing techniques. I was wondering if there is a tool that could try
various popular and brute force
combinations to automatically guess the possible URLs.

Have you tried Google searches using 'site:client.dom' to see if possibly
these URLs are already floating around out there somewhere?

PaulM


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



Relevant Pages

  • Re: Informing Companies about security vulnerabilities...
    ... security vulnerabilities... ... the vulnerable web apps I use for class. ... I go to a live public website or two during the class and we talk ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: Informing Companies about security vulnerabilities...
    ... I know it is your responsability to teach your students how to ... Depending on the information you can get through the website (customer ... Need to secure your web apps? ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: Website detection
    ... these webservers have the website on the main url like ... Need to secure your web apps? ... Cenzic Hailstorm finds vulnerabilities fast. ... Click the link to buy it, try it or download Hailstorm for FREE. ...
    (Pen-Test)
  • Re: Informing Companies about security vulnerabilities...
    ... The Editor Does Not Do Web Security. ... Depending on the information you can get through the website (customer ... Cenzic Hailstorm finds vulnerabilities fast. ... Click the link to buy it, try it or download Hailstorm for FREE. ...
    (Pen-Test)
  • Re: Informing Companies about security vulnerabilities..
    ... However if you read the email you'd know he did in fact test it, ... this implies testing. ... He then states how he contacted this particular website to let them know he found vulns in their site. ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)