RE: Google lists vulnerable sites.

From: Erick Arturo Perez Huemer (eperez@compuservice.net)
Date: 07/06/02


From: "Erick Arturo Perez Huemer" <eperez@compuservice.net>
To: <silencedscream@hotmail.com>, <vuln-dev@securityfocus.com>
Date: Fri, 5 Jul 2002 18:12:27 -0500

Doing a query of a specific country/language and using inurl:iisadmin
revealed a simple list of sites running the Internet Information Server
administrator page, the list returned was 45. Of those, 9 had no
password and were visible from my side.

Several searches can be made: Ports in the url, specific cgi, specific
files (like the db) etc.

Using the db as an example, I was able to see several sites that use a
web program to manage statistics and other data. Those sites were under
an obfuscated URL and I guess they were supposed not to be seen by the
outsiders.

The only drawback is that I do not seem to be able to define a "set" of
ip addresses rather than domains to search.

Google.com.....Simple Nmap's rival?? (itīs a joke, dont start
blaming....)

Erick A. Perez H.
Asesor de Seguridad informatica
y TeleComunicaciones
Panama, Republica de Panama
Tel. (507) 226-6217
Movil. (507) 652-4889 (24 horas)
eperez@compuservice.net
 

> -----Original Message-----
> From: silencedscream@hotmail.com [mailto:silencedscream@hotmail.com]
> Sent: Viernes, 05 de Julio de 2002 02:01 p.m.
> To: vuln-dev@securityfocus.com
> Subject: Google lists vulnerable sites.
>
>
>
>
> Let me first say that I do now know if this issue has been brought to
> light before or in what detail it might have been discussed.
> On to the
> show...
>
> The problem I have found is that google may be archiving too much
> information on sites. By carefully crafting search strings you can
> reliably return sites who's root, cgi-bin, bin, admin, etc...
> directories
> are exposed and unprotected. The first thing you must do is
> select the
> name of a commonnly protected directory (I will use admin in this
> example). The second is to think of a filetype that only the
> administrator and not the average web surfer would have access to.
> Things like bin, txt, or htm are no good because they are
> commonly made
> available in other directories for legitimate reasons. For
> this example
> I choose to go with .db. Now to create the search string.
>
> inurl:admin filetype:db
> The above gives us,
> http://www.google.com/search?sourceid=navclient&q=inurl%3Aadmi
n+filetype%
3Adb

The above search sets the requirments that admin must be in the url and
only sites that contain a file of the type .db are returned.

Now most of the links you click on will take you to some meaningless url

or email database but if for exaple you had

www.somesite.org/admin/cgi-bin/url.db

and you removed the url.db from the link you are now free to traverse
through there directories and files. By useing carefully selected
search
terms like the ones above I have about a 90-95% success rate of
vulnerable sites returned. The trick is finding the right directory and

filetypes to use in the search.



Relevant Pages

  • Re: brute force ColdFusion MX7 admin page
    ... respond with the HTTP status of 302. ... This document lists another ColdFusion page ... did not have enough time to guess the admin password. ... I imagine the salt is predictable but I also imagine ...
    (Pen-Test)
  • Lyris ListManager 8.95: Add arbitrary administrator to arbitrary list
    ... Advisory: Lyris ListManager 8.95: Add arbitrary ... administrator to arbitrary list ... I'm sure there's SQL injection possibilities here as ... and the value of your mailing lists. ...
    (Bugtraq)
  • Re: Simple Web Parts question
    ... I am having a similar problem, although I am the administrator. ... I created a site based on the team site, customised it (add a few lists and ... Any new site that I create using that template the users cannot access the ... gallery, 0 in virtual server gallery, 8 in Online Gallery (MSNBC Business ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: User group tool
    ... To get a list of all users in the admin group... ... Copy above into a.BAT or .CMD file, then use a Windows GPO or login script ... google'd and use pwdump for lists etc; I also use net user and net group ...
    (Pen-Test)
  • Re: [opensuse] silly girls cli copy problem
    ... well one more pro sys admin here... ... positive feedback from this and other lists. ... community being very responsive, very responsible and very helpfull indeed. ... when I was a real Linux newbie) I ...
    (SuSE)