Identifying hidden contents

Practically speaking, the big question that you will ask yourself is, what do I need to find? You will need a solid checklist to refer to when it's time for your web intrusion test. That being said, here's a checklist that you can use for this step in the workflow:

  1. Robots.txt file
  2. Backup files (.bak, .old)
  3. Other interesting files (.xls, .doc, .pdf, .txt)
  4. Administration URL (for example, phpmyadmin, wp-admin)
  5. Debugging leftover pages and URLs
  6. Is CMS used? (WordPress)

If you find any item in the preceding list, check its contents for juicy information, including:

  • Personal information
  • Email addresses
  • Credentials
  • An entry point to another system (for example, WordPress)
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.144.86.134