Full Disclosure mailing list archives
RE: Any thoughts on War-Googling?
From: jay jay <fd () postmaster co uk>
Date: Mon, 19 Apr 2004 09:29:10 +0100
It says something about using Google to target servers by searching paths to vulnerabilities. Any thoughts on that?
Hola, i found out that the Google - " allinurl: " - option is optimal for this: like: allinurl: .php file= .txt allinurl: .php parse= Just do this with stupid common words, a good Web-Programmer would never use as a parameter in the URL. Then it´s quite simple to view mostly anything with ../../../ .... - so check your input ! ; ) Ciao Jay ___________________________________________________ Reduce your company's IT costs today with Officemaster. Sign up for a free trial! http://www.officemaster.net _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- ReportingWebService.asmx - message.real.com, (continued)
- ReportingWebService.asmx - message.real.com fd (Apr 30)
- Re: Any thoughts on War-Googling? yossarian (Apr 18)
- Re: Any thoughts on War-Googling? (long and inflammatory) Michal Zalewski (Apr 18)
- Re: Any thoughts on War-Googling? Gregory A. Gilliss (Apr 18)
- Re: Any thoughts on War-Googling? Aschwin Wesselius (Apr 18)
- Re: Any thoughts on War-Googling? Aschwin Wesselius (Apr 18)
- RE: Any thoughts on War-Googling? Jeremiah Cornelius (Apr 18)
- Re: Any thoughts on War-Googling? Mark Fagan (Apr 18)
- Re: Any thoughts on War-Googling? Tyler Thomson (Apr 19)
- Re: Any thoughts on War-Googling? Fabio Weissert (Apr 18)
- RE: Any thoughts on War-Googling? jay jay (Apr 19)
- Re: Any thoughts on War-Googling? J.J. (Apr 19)