Penetration Testing mailing list archives

Re: Nikto Result


From: Matt Gardenghi <mtgarden () gmail com>
Date: Tue, 15 Dec 2009 09:30:58 -0500

It's moments like this that make me enjoy pentesting.  :-)

Also, you should always reference:
http://www.phenoelit-us.org/dpl/dpl.html
http://cirt.net/passwords

There are plenty more, but those are good starts.

Manuals for the apps will often give you the defaults as well.

Koen Bossaert wrote:
Hi,

That's a default username and clear text password you found and
Intershop is the product.
See http://www.passwordsdatabase.com/vendor/intershop
If that password doesn't work to log in, try without the s.

Koen

On Fri, Dec 11, 2009 at 9:23 AM, Zaki Akhmad <zakiakhmad () gmail com> wrote:
Hello,

I have this nikto result and I need help what does it mean:

+ Default account found for 'Members Only' at /webadmin/ (ID
'operator', PW '$schwarzepumpe'). Intershop
+ ERROR: Unable to authenticate to "Members Only"
+ ERROR: Unable to authenticate to "Members Only"

What is $schwarzepumpe? Is it encrypted password?
Then what is Intershop?

--
Zaki Akhmad

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------



------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
http://www.iacertification.org
------------------------------------------------------------------------



------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
http://www.iacertification.org
------------------------------------------------------------------------


Current thread: