HACK STEPS (continued)
■
Add to the lists of enumerated items any further potential names conjec-
tured on the basis of these. Also add to the file extension list common
extensions such as
txt
,
bak
,
src
,
inc
, and
old
, which may uncover the
source to backup versions of live pages, as well as extensions associated
with the development languages in use, such as Java and cs, which may
uncover source files that have been compiled into live pages (see the tips
described later in this chapter for identifying technologies in use). The
Paros tool carries out this test when used to perform a vulnerability scan
Do'stlaringiz bilan baham: