|
Penetration Testing
Scanner for old files (.bak, ~, .old, etc.) Jun 30 2009 12:47PM Juan Kinunt (kinunt gmail com) (12 replies) RE: Scanner for old files (.bak, ~, .old, etc.) Jul 01 2009 02:01PM Tal Argoni (tala 2bsecure co il) Re: Scanner for old files (.bak, ~, .old, etc.) Jul 01 2009 03:16AM Nikhil Wagholikar (visitnikhil gmail com) (1 replies) Re: Scanner for old files (.bak, ~, .old, etc.) Jul 02 2009 04:34PM Jeremy Brown (0xjbrown41 gmail com) Re: Scanner for old files (.bak, ~, .old, etc.) Jun 30 2009 04:56PM John Lampe (jwlampe tenablesecurity com) Re: Scanner for old files (.bak, ~, .old, etc.) Jun 30 2009 04:50PM Benjamin Greenfield (bcg struxural com) Re: Scanner for old files (.bak, ~, .old, etc.) Jun 30 2009 04:27PM Todd Haverkos (infosec haverkos com) Re: Scanner for old files (.bak, ~, .old, etc.) Jun 30 2009 04:05PM Rogan Dawes (lists dawes za net) Re: Scanner for old files (.bak, ~, .old, etc.) Jun 30 2009 03:37PM pUm (hijacka googlemail com) (1 replies) Re: Scanner for old files (.bak, ~, .old, etc.) Jul 01 2009 04:11PM SD List (list security-database com) Re: Scanner for old files (.bak, ~, .old, etc.) Jun 30 2009 03:34PM Andres Riancho (andres riancho gmail com) Re: Scanner for old files (.bak, ~, .old, etc.) Jun 30 2009 03:23PM Sandro Gauci (sandro enablesecurity com) |
|
|
Privacy Statement |
> Hi,
>
> I would like to know if anyone knows a tool that first spiders the web
> in order to enumerate al files and scripts it detects and then look
> for this same files but with another extension. For example, first
> spiders the web and enumerate:
>
> index.php
> news.php
> cart.php
>
> And then looks for index.php.bak, index.php.inc, index.php~,
> index.bak, index.old, etc.
>
> This tool will be useful supossing that programmers tend to change the
> extension of the file to store old files.
>
> I know Nikto, Wikto, etc... but this tools look for predefined files
> and I would like to target already existing files but with different
> extension.
>
> If the tool does not exist I'll try to code something.
>
> Thanks.
Hi Juan,
Burp Intruder can be a useful choice, see the cluster bomb function at
http://portswigger.net/intruder/help.html
Best regards,
Gabriele
--
Cordiali saluti
Gabriele Zanoni
Secure Network S.r.l.
Via Venezia, 23 - 20099 Sesto San Giovanni (MI) - Italia
Tel: +39 02.24126788 Mobile: +39 340.4820795
email: g.zanoni (at) securenetwork (dot) it [email concealed]
web: www.securenetwork.it
------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board
Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
http://www.iacertification.org
------------------------------------------------------------------------
[ reply ]