pen-test
[Top] [All Lists]

RE: Website detection

To: "'3 shool'" <3shool@gmail.com>, <pen-test@securityfocus.com>
Subject: RE: Website detection
From: "Password Crackers, Inc." <pwcrack@pwcrack.com>
Date: Tue, 20 Feb 2007 18:48:19 -0500
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <5a4274b50702190208l76d97209wec4b527a9730ad8a@mail.gmail.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <5a4274b50702190208l76d97209wec4b527a9730ad8a@mail.gmail.com>
Resent-date: Wed, 21 Feb 2007 21:16:20 -0700 (MST)
Resent-from: pen-test-return-1078483577@securityfocus.com
Resent-message-id: <20070222041620.EB66D143F64@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Thread-index: AcdVSPnIXsqhJEfzQCmlKildrTzTqAAAJMVQ
Check robots.txt to see if they have listed the websites there.  If not,
you'll certainly want to try Google.

Bob Weiss
Password Crackers, Inc. 

-----Original Message-----
From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com] On
Behalf Of 3 shool
Sent: Monday, February 19, 2007 5:09 AM
To: pen-test@securityfocus.com
Subject: Website detection

Hello Everyone,

We are doing a PT for one of our customers with 5 webservers. None of these
webservers have the website on the main url like http://xxx.xxx.xxx.xxx but
they have confirmed that they have critical applications running on all the
5 web servers and for security purposes they have moved the websites to
something like http://xxx.xxx.xxx.xxx/yyy.

Now manually I guess it will take years to identify the correct URL having
the critical website by using guessing techniques. I was wondering if there
is a tool that could try various popular and brute force combinations to
automatically guess the possible URLs.

I'm sure many of you would have wonderful ideas to address this problem.
Pls. enlighten.

THNX

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=70160000
0008bOW
------------------------------------------------------------------------



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>