lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
From: nicob at nicob.net (Nicob)
Subject: Temporary Files and Web Sites (swp, ~, etc)

Le jeu 12/08/2004 ? 08:45, bugtraq@...ondsecurity.com a ?crit :

> There isn't much you can do beside:
> 1) Avoid leaving these files behind
> 2) Make rules in Apache/whatever to block access to .swp, ~, etc files.

The babelweb scanner [1] is already looking for backup files under the
webroot. Tested extensions : '.old', '.bak', '~', '.orig', '.backup',
'.bad'


[1] : http://www.hsc.fr/ressources/outils/babelweb/download/README
-- 
Nicob <nicob@...ob.net>


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ