Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 184 guests and 1 member online
 
Advertisement

You are here: Home arrow Resourcesarrow Tutorialsarrow Why directory browsing is important?
EH-Net
May 23, 2013, 09:50:06 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Why directory browsing is important?  (Read 6723 times)
0 Members and 1 Guest are viewing this topic.
Cyber.spirit
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« on: September 20, 2012, 04:40:23 PM »

hi guys.
In all of pentest learning videos which i watch they always say check the webserver to find directory browsing addresses u can find it via nikto or the robots.txt file.
I've find some directory browsing addresses in my friend's site during the pentest now what? What can i do with it? I just report it or have we some methods to penetrate with directory browsing?

Totally why directory browsing is important?
Logged

ICS Academy Network Security Certified
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #1 on: September 20, 2012, 04:50:40 PM »

You simply don't want to readily disclose directory contents. There may be files like db.conf.php.old001 or tax_return2011.pdf lying around somewhere. Granted, such files shouldn't be on a web server in the first place, but if someone forgets about them or makes a mistake, you don't want them openly displayed for the entire world to see.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Cyber.spirit
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #2 on: September 20, 2012, 05:05:50 PM »

You simply don't want to readily disclose directory contents. There may be files like db.conf.php.old001 or tax_return2011.pdf lying around somewhere. Granted, such files shouldn't be on a web server in the first place, but if someone forgets about them or makes a mistake, you don't want them openly displayed for the entire world to see.

Ok man so u mean i must report them to turn the directory service off that set? Nothing more?
Logged

ICS Academy Network Security Certified
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #3 on: September 20, 2012, 05:11:32 PM »

Correct. You could add a warning about making sure only necessary files are present, etc., and add some extra value, but the core solution is indeed just disabling directory browsing.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #4 on: September 20, 2012, 05:41:08 PM »

Also it doesn't stop at the directory you are currently viewing. Just because the current directory doesn't display anything interesting doesn't mean that $path/../../../../../etc/passwd isnt viewable (have to play with the path's here, can sometimes be loaded by script paths, templates, cookies, hidden form fields, etc.) Check out https://www.owasp.org/index.php/Testing_for_Path_Traversal for more info.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
superkojiman
Jr. Member
**
Offline Offline

Posts: 60



View Profile WWW
« Reply #5 on: September 20, 2012, 10:49:37 PM »

I've find some directory browsing addresses in my friend's site during the pentest now what? What can i do with it?

Depends. Sometimes nothing. Other times, you might find something that reveals more about the site, such as services, or users on the server, configuration files, etc.
Logged

OSCP, GSEC
m0wgli
Full Member
***
Offline Offline

Posts: 248


View Profile
« Reply #6 on: September 21, 2012, 02:08:29 AM »

You can also try and find hidden directories and content through brute force using tools such as dirbuster for example:

https://www.owasp.org/index.php/Category:OWASP_DirBuster_Project
Logged

Security + | OSWP | eCPPT | CSTA
Cyber.spirit
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #7 on: September 21, 2012, 02:48:49 AM »

You can also try and find hidden directories and content through brute force using tools such as dirbuster for example:

https://www.owasp.org/index.php/Category:OWASP_DirBuster_Project
Wow man thank u what a great source i haven't known that. I'll try to find some sensitive data thanx again
Logged

ICS Academy Network Security Certified
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #8 on: September 21, 2012, 11:31:35 AM »

To pile on top of what everyone else said, if you find old app files, like login.php.bak, guess what, you can download that file and get the raw PHP code, which may contain sql connection credentials, code level notes like:

/* if a user puts in special characters, they can access resources they shouldn't. will fix soon */

All sorts of goodies... This could give you all sorts of juicy tidbits of info for further attacks.
Logged

Poking at security since 1986.  +++ATH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.078 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.