September 30, 2003E-commerce > Google as a Hacking ToolGoogler explains how to find unprotected Web directories using everyone's favorite search engine. This has been common knowledge for the search savvy for some time, but now it's getting more press. You can easily query Google to find doors left open by webmasters. I call it "Google keychain" because it's one (search) string that has keys to many doors :) Here's why this exploit works. Normally, users can enter a directory name in a URL (such as http://www.lesjones.com/images for the images directory). Notice that no file was speficied in the URL. Apache will look for a default file in that directory, such such as index.html, default.htm, or other files defined in the httpd.conf file. If there is no default file present, Apache may display the contents of the directory, depending on the configuration settings. The default is to display files in the directory. To keep that from happening, open the httpd.conf file, disable the IndexOptions directive, and restart Apache. (Details at Apache.org.) If anyone tries to access a directory without a default file, they'll get a 403 Forbidden error, like this one. There's an older exploit involving Web-enabled FileMaker Pro databases, though I can't seem to find the details right now. When a FileMaker Pro database is Web-enabled, it has a default welcome message. If the database isn't password-protected, search engines will index that message, and hackers can search for that message on Google and other search engines. Posted by lesjonesComments
Post a comment
|
Search
Sponsors
Archives
Every post A&E - (205) Best Of - (54) Blogging - (252) Comic Books - (30) Dancing Baloney - (26) Dear Lazyweb - (17) E-commerce - (159) East Tennessee - (283) Economics - (93) Environment - (71) European Union - (38) Everything's Illegal - (5) Family Tree - Moore Side - (6) Food & Drink - (77) Funny Ha-Ha - (164) Guns - (390) Health Care - (43) Home Life - (263) John Kerry - (1) Johnia Berry - (48) Macular Degeneration - (11) Media Behaving Badly - (56) Middle East - (47) Misc - (105) Mortgage Crisis - (3) Municipal Wi-Fi - (17) News - (304) Nifty - (97) Photos - (34) Political Survival Kit - (16) Politics - (60) Polls - (19) Population - (31) PSAs - (11) Quotes - (195) Rocky Top Brigade - (38) Science - (126) Scratch Pad - (5) Seventies - (3) Social Security - (9) Star Wars - (54) Tech - (111) The Usual Suspects - (15) Timothy Treadwell - (6) Travel - (60) True Crime - (69) Word of the Day - (98) |