Unlimited WordPress themes, plugins & video downloads!

Research

Research – This paper describes several techniques for exposing file contents using the site search functionality. It is assumed that a site contains documents which are not visible/accessible to external users. Such documents are typically future PR items, or future security advisories, uploaded to the website beforehand. However, the site is also searchable via an internal search facility, which does have access to those documents, and as such, they are indexed by it not via web crawling, but rather, via direct access to the files. Therein lies the security breach.

This paper describes several techniques for exposing file contents using the site search functionality. It is assumed that a site contains documents which are not visible/accessible to external users. Such documents are typically future PR items, or future security advisories, uploaded to the website beforehand. However, the site is also searchable via an internal search facility, which does have access to those documents, and as such, they are indexed by it not via web crawling, but rather, via direct access to the files. Therein lies the security breach.

 

You can download it from the following link: https://packetstormsecurity.com/files/download/36370/022805.txt

Source: https://packetstormsecurity.com/files/36370/022805.txt.html

Related posts
Research

Research - CanSecWest 2013 Call For Papers

Research

Research - CarolinaCon 2017 Call For Papers

Research

Research - ccs4.html

Research

Research - cgi-explained.doc

Sign up for our Newsletter and
stay informed