|
|||||||||||
|
Re: [whisker] How to Analyse Whisker Report
From: rain forest puppy <rfp(at)wiretrip.net>
Date: Wed Jan 29 2003 - 04:23:17 EST On Wed, 29 Jan 2003, Indian Tiger wrote:
> But I feel there should be some short and sweet document or way to do
There is: http://www.google.com/search?q=security+<FILE> Where <FILE> is the file reported by whisker. Google returns a relevant document in the top 5 returns for each file you listed.
> Found URL: /_vti_inf.html
This is a FrontPage configuration file. It tells you FrontPage version and location information. Informational value only. > /_vti_bin/shtml.dll
Just FrontPage components. Depending on the version, there are various vulnerabilities.
> Found URL: /support/
This is just a potentially interesting directory. No immediate vulnerability (hence the "Informational" blurb). > The following cookies were encountered while scanning:
Nothing. Replay attacks won't provide anything, as there's no sensitive information associated with those cookies. It's purely informational. If you were curious, you'd take the returned cookie values and data mine them for possible predictable sequences...but since this is IIS, let me save you some time and tell you that they are sufficiently random. ;)
> What does "Server failure" mean?
It means the server returned a 5xx response, indicting there was an error with the CGI component. No immediate vulnerability...just (ab)normal response.
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:48 EDT |
||||||||||
|
|||||||||||