[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#516659: ITP: w3bfukk0r -- scan webservers for hidden?directories (forced browsing)



Hi,
* Noah Slater <nslater@tumbolia.org> [2009-02-25 01:32]:
> On Tue, Feb 24, 2009 at 09:17:35PM +0100, Holger Levsen wrote:
> > > (As Noah Slater pointed out, it's hard to lose a directory on your
> > > own machine...)
> >
> > you can loose access to your machine...
> 
> At which point you may as well call it someone else's machine.

There is a difference from using a root account on a shared 
hosting system to detect weaknesses or to use the limited 
abilities an attacker has from a pentesting standpoint.

Cheers
Nico
-- 
Nico Golde - http://www.ngolde.de - nion@jabber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgp0YIvijhWRC.pgp
Description: PGP signature


Reply to: