Slashdot Mirror


New Web Application Attack - Insecure Indexing

An anonymous reader writes "Take a look at 'The Insecure Indexing Vulnerability - Attacks Against Local Search Engines' by Amit Klein. This is a new article about 'insecure indexing.' It's a good read -- shows you how to find 'invisible files' on a web server and moreover, how to see contents of files you'd usually get a 401/403 response for, using a locally installed search engine that indexes files (not URLs)."

7 of 120 comments (clear)

  1. but its fixed in firefox now by Prophetic_Truth · · Score: 2, Funny

    right?

    --
    time is a perception of a being's consciousness
    time is your 6th sense, the wierd ones are 7+
  2. should have been from.... by Anonymous Coward · · Score: 5, Funny

    the department-of-the-bleedingly-obvious...

  3. sounds like fun by h4ter · · Score: 2, Funny

    The attacker first loops through all possible words in English...

    I get the idea this might take a while.

    1. Re:sounds like fun by h4ter · · Score: 2, Funny

      Wait a minute. All possible? Couldn't be satisfied with just actual words? This is going to take a lot longer than I first thought.

      (Sorry for the reply to self. It's like my own little dupe.)

  4. does this mean more PRON? by jephthah · · Score: 2, Funny

    bastards always hiding their stash. this'll show 'em

  5. application in porn by Anonymous Coward · · Score: 1, Funny

    my mind being the way it is, i can't help but think of an application for this in porn ;). a lot of porn sites have extensive free previews, but its hard for someone to find all the free preview pics for a certain site (useful especially for a single model's site) unless you can find a direct link to every single unique free preview gallery from somewhere, and you'll undoubtedly miss some good stuff. i want to see a firefox extension that gets me all the free pics from a given site damnit!

  6. New option for robots.txt by michelcultivo · · Score: 5, Funny

    Please put this new undocumented tag on your robots.txt file: "hackthis=false" "xss=false" "scriptkiddies=log,drop" And all you problems will be solved.