Tips for searching the admin background

Source: Internet
Author: User

Purester blog

When we know the background directory of a website but cannot determine the background login file, we can try to add "."
For example, http://www.xxx.com/admin. after we open directory Listing Denied, the default homepage of this directory is not found,
Then we can change the address to www.xxx.com./admin. Note that there is a "." After com, so that we can directly jump to the login page.
In T00LS, it seems that this can only happen under IIS. I tried several sites and found that not all sites set up by IIS support this method.
For example, if you open http://www.hacksb.cn/admin, the directory Listing Denied is displayed. However, when "." is added, the Bad Request (Invalid Hostname) is displayed. That is, the domain name is not bound to the host.
Although it cannot be killed, it is a good technique. If you encounter such a situation, you can try this method.
I don't know how it works. If you know something about it, I hope you can give it to me.

 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.