Unlimited WordPress themes, plugins & video downloads!

Research

Research – This paper describes several techniques for exposing file contents using the site search functionality. It is assumed that a site contains documents which are not visible/accessible to external users. Such documents are typically future PR items, or future security advisories, uploaded to the website beforehand. However, the site is also searchable via an internal search facility, which does have access to those documents, and as such, they are indexed by it not via web crawling, but rather, via direct access to the files. Therein lies the security breach.

This paper describes several techniques for exposing file contents using the site search functionality. It is assumed that a site contains documents which are not visible/accessible to external users. Such documents are typically future PR items, or future security advisories, uploaded to the website beforehand. However, the site is also searchable via an internal search facility, which does have access to those documents, and as such, they are indexed by it not via web crawling, but rather, via direct access to the files. Therein lies the security breach.

 

You can download it from the following link: https://packetstormsecurity.com/files/download/36370/022805.txt

Source: https://packetstormsecurity.com/files/36370/022805.txt.html

Related posts
Research

Research - IDS Overview Whitepaper

Research

Research - IETF Internet-Draft On TCP Timestamps

Research

Research - ImmuniWeb Self Fuzzer Firefox Extension

Research

Research - Infection Guide Using Java/VbScript

Sign up for our Newsletter and
stay informed