Information Disclosure


Overview

Information Disclosure may result when internal information is disclosed to the user-agent (browser). These paths can be used in other attacks.

YouTubeVideo Tutorials

Discovery Methodology

Attempt to discover if it is possible to cause errors by injecting all input parameters with characters that are reserved in various contexts. Search web page sources (view source) for internal information disclosure. Search for custom administrative pages and administrative consoles such as phpMyAdmin installations.

Exploitation

Search pages with and without injection. Use the grep feature of Burp-Suite to seach for inappropriate information. Search for known common administrative consoles such as phpMyAdmin installations, Drupal and Wordpress consoles.

Videos


YouTubeHow to grab robots.txt file with CURL
YouTubeHow to list HTTP Methods with CURL
YouTubeHow to list HTTP Methods with NMap
YouTubeDetermine HTTP Methods using Netcat
YouTubeHow to grab HTTP Server Banners with CURL
YouTubeHow to grab HTTP Server Banners with NMap
YouTubeDetermine Server Banners using Netcat, Nikto, and w3af
YouTubeUsing Nmap to Fingerprint HTTP servers and Web Applications
YouTubeFinding Comments and File Metadata using Multiple Techniques
YouTubeHow to Sweep a Web Site for HTML Comments
YouTubeHow to Install dirb on Linux
YouTubeHow to Use dirb to Locate Hidden Directories on a Web Site
YouTubeHow to Install OWASP DirBuster on Linux
YouTubeHow to use OWASP DirBuster to Discover Hidden Directories on Web Sites
YouTubeHow to Create Wordlists from Web Sites using CEWL