Courses:

Offensive Countermeasures: The Art Of Active Defense: SANSFIRE June 15-16, Blackhat USA July 27-28 & 29-30


Defensive Countermeasures: Foundations for Becoming A Devious Defender: Blackhat USA July 27-28 & 29-30


Conferences:

Check out the entire PaulDotCom crew at BsidesRI June 14-15th!



Subscribe:

Blog:
Videos:
Podcast:


PaulDotCom EspaƱol


Hack Naked TV


Hack Naked At Night


Stogie Geeks


Sponsored By:


www.coresecurity.com


www.tenablesecurity.com


www.sans.org



Follow Us On:


twitter.com/pauldotcom

PaulDotCom YouTube Channel


PaulDotCom Security Weekly - Episode 60 - February 8, 2007

| | Comments (2)
Live from the PaulDotCom Security Weekly Studio....

Hosts: Larry "Uncle Larry" Pesce, Paul "PaulDotCom" Asadoorian, Nick "Twitchy" Depetrillo, Joe "Mr. C" Conlin
Email: psw@pauldotcom.com

Direct Audio Download

(Bandwidth provided by OSHEAN)

Audio Feeds:

2 Comments

Well, here are some plugins that could give you interesting info, I dunno which ones you want exactly:

Nessus Plugin 24004 -> It enumerates WebDAV-enabled directories.
Nessus Plugin 10704 -> Apache Directory Listing
Nessus Plugin 10526 -> IIS : Directory listing through WebDAV
Nessus Plugin 10505 -> Directory listing through WebDAV
Nessus Plugin 10121 -> /scripts directory browsable

Here are a few of the Nessus plugins that allow directory traversal.

Nessus Plugin ID 11032

Description:

This plugin attempts to determine the presence of various
common dirs on the remote web server

--------------------------
Nessus Plugin ID 14229

Description:

The remote web server is vulnerable to a path traversal vulnerability.

An attacker may exploit this flaw to read arbitrary files on the remote
system with the privileges of the http process.

------------------------------
Nessus Plugin ID 10526

Description:

It is possible to retrieve the listing of the remote
directories accessible via HTTP, rather than their index.html,
using the Index Server service which provides WebDav capabilities
to this server.

This problem allows an attacker to gain more knowledge
about the remote host, and may make him aware of hidden
HTML files.