Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Common Directory Openings?


ghost's Avatar
0 0

Yeah, I'm kinda new to the whole hacking thing, but thanks to HBH I've picked up more information in a month than I have elsewhere in three months, nothing serious yet, just sort of taking a peek at various directories. I read in one of the web hacking articles a list of common directory openings, they were really great but I was wondering if anyone else could add any other common ones that work for them. So far we have:

admin bak test files include includes images members users tmp logs

Anyone wanna add to that?


ghost's Avatar
0 0

You could try robots.txt, then whatever you find in there might have sensitive info :p. But other then that, I got nothing considering what you already have.


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

files administration _vti_pvt _private backups backup sql mysql db database modules data temp


ghost's Avatar
0 0

i typed in hissite/robots.txt i get this

User-agent: * Disallow: /make_forum.php Disallow: /viewtopic.php Disallow: /viewforum.php Disallow: /index.php? Disallow: /posting.php Disallow: /groupcp.php Disallow: /search.php Disallow: /login.php Disallow: /post Disallow: /member Disallow: /profile.php Disallow: /memberlist.php Disallow: /faq.php

eh i dont get it no gd info there either i dont think lol


ghost's Avatar
0 0

Evilthoutz wrote: i typed in hissite/robots.txt i get this

User-agent: * Disallow: /make_forum.php Disallow: /viewtopic.php Disallow: /viewforum.php Disallow: /index.php? Disallow: /posting.php Disallow: /groupcp.php Disallow: /search.php Disallow: /login.php Disallow: /post Disallow: /member Disallow: /profile.php Disallow: /memberlist.php Disallow: /faq.php

eh i dont get it no gd info there either i dont think lol

oh, but it is good. :ninja: mess around with those scripts.


Uber0n's Avatar
Member
0 0

There are website scanners with built-in wordlists for common directory names.

I mostly use Intellitamper ;)


ghost's Avatar
0 0

Uber0n wrote:

I mostly use Intellitamper ;)

dont trust Intellitamper 100%.

take the site http://www.rancidrancid.com/ for instance. intellitampe returns the follwoing directories - /films/ /music/ /images/

but by checking the common directories we can find /admin/


Uber0n's Avatar
Member
0 0

minermonk wrote: take the site http://www.rancidrancid.com/ for instance. intellitampe returns the follwoing directories - /films/ /music/ /images/

but by checking the common directories we can find /admin/

Options > enable wordlist scan ;) otherwise it just reads from all pages ^^