Penetration Testing mailing list archives

RE: Website search engine is a hacking tool..


From: "Vinicius Moreira Mello" <vinicius () lineone net>
Date: Thu, 29 Jul 2004 23:15:44 -0300

Hi,

-- Original Message --
Subject: RE: Website search engine is a hacking tool..
From: Amal Mohammad Al Hajeri <amal () nis etisalat ae>

 and how can we mitigate the risk of using such techniques? did anyone
succeed in using
the local search engine as a proxy to attack other targets?

Try disabling indexing (apache: Option -Indexes) for as much directories
as possible and not using/protecting critical files under the webserver
(ch)root diretory.

Regards,
vmm.

__________________________________________________________________
Get Tiscali Broadband From £15:99
http://www.tiscali.co.uk/products/broadband




Current thread: