Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Bài tập: Cho kết quả Scan bằng Nikto dưới đây
- - Nikto v2.1.6
- ---------------------------------------------------------------------------
- + Target IP: 103.255.237.87
- + Target Hostname: tocotocotea.com
- + Target Port: 80
- + Start Time: 2017-10-26 21:26:42 (GMT7)
- ---------------------------------------------------------------------------
- + Server: Apache
- + Cookie PHPSESSID created without the httponly flag
- + Cookie language created without the httponly flag
- + Cookie currency created without the httponly flag
- + The anti-clickjacking X-Frame-Options header is not present.
- + The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
- + The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
- + /admin/config.php: PHP Config file may contain database IDs and passwords.
- + /webmail/blank.html: IlohaMail 0.8.10 contains an XSS vulnerability. Previous versions contain other non-descript vulnerabilities.
- + /securecontrolpanel/: Web Server Control Panel
- + /webmail/: Web based mail package installed.
- + /config.php: PHP Config file may contain database IDs and passwords.
- + OSVDB-3233: /mailman/listinfo: Mailman was found on the server.
- + OSVDB-2117: /cpanel/: Web-based control panel
- + OSVDB-3092: /admin/: This might be interesting...
- + OSVDB-3092: /download/: This might be interesting...
- + /error_log: PHP include error may indicate local or remote file inclusion is possible.
- + OSVDB-3092: /img-sys/: Default image directory should not allow directory listing.
- + OSVDB-3093: /admin/index.php: This might be interesting... has been seen in web logs from an unknown scanner.
- + OSVDB-3093: /webmail/lib/emailreader_execute_on_each_page.inc.php: This might be interesting... has been seen in web logs from an unknown scanner.
- Câu hỏi:
- a. Liệt kê những đường dẫn nhạy cảm của web mà ta đã dò được
- b. Phân tích mức độ nhạy cảm của từng đường dẫn
- Ví du: Đường dẫn /webmail/ cho ta biết, có 1 dịch vụ thư điện tử được cài trên máy chủ này
Advertisement
Add Comment
Please, Sign In to add comment