pen-test
[Top] [All Lists]

Re: Website detection

To: "3 shool" <3shool@gmail.com>
Subject: Re: Website detection
From: "Robin Wood" <dninja@gmail.com>
Date: Tue, 20 Feb 2007 23:52:08 +0000
Cc: pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=UclGrL0vVeQyXZk1Dxk0e8u4FVgjy9MrFgF+zP+K44TV9UG+qoNOlIu6VcNTfhqA9ZRpkPcTvYgKQev9Bn69Qz5cyMq+woPCmuAuJc6fN7b3xmOaT3YpIqLr5RBec8I5peUS1/H+LpsdlPtakOC72MQghyxQv+JwEwkhot4pUUA=
In-reply-to: <5a4274b50702190208l76d97209wec4b527a9730ad8a@mail.gmail.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <5a4274b50702190208l76d97209wec4b527a9730ad8a@mail.gmail.com>
Resent-date: Wed, 21 Feb 2007 21:16:31 -0700 (MST)
Resent-from: pen-test-return-1078483578@securityfocus.com
Resent-message-id: <20070222041631.0BB8D143E87@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
It would be fairly simple to write a script which took a dictionary
and used curl or wget to hit the site with each dictionary word
appended on the url.

Try to add extra words to the dictionary from the company website and
company related documentation to allow you to cover company specific
words.

That is how I'd start.

Robin

On 2/19/07, 3 shool <3shool@gmail.com> wrote:
Hello Everyone,

We are doing a PT for one of our customers with 5 webservers. None of
these webservers have the website on the main url like
http://xxx.xxx.xxx.xxx but they have confirmed that they have critical
applications running on all the 5 web servers and for security
purposes they have moved the websites to something like
http://xxx.xxx.xxx.xxx/yyy.

Now manually I guess it will take years to identify the correct URL
having the critical website by using guessing techniques. I was
wondering if there is a tool that could try various popular and brute
force combinations to automatically guess the possible URLs.

I'm sure many of you would have wonderful ideas to address this
problem. Pls. enlighten.

THNX

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>