Monday, April 25, 2005

full path disclosure in .jbf files

There is a full path disclosure in .jbf files. This is not a problem when used on a standalone pc, but it does become information disclosure when uploaded / used on a webserver...

GOogle: ext:jbf jbf
Results 1 - 100 of about 8,230

Or: JASC BROWS FILE  ext:jbf jbf

The first line of this file says "JASC BROWS FILE"
The second line of this file has the path info..

Example 1:

JASC BROWS FILE
\\File_server\WebSite\images\3D

Example 2:

JASC BROWS FILE
U:\u50_5\alephe\www_ned\icon\UBU05

Example 3:

JASC BROWS FILE
Z:\www

Small Business Server 2003

google: intitle:"Welcome to Windows Small Business Server 2003"



Or use JN's version (also SBS 2008):
inurl:ConnectComputer/precheck.htm | inurl:Remote/logon.aspx

Doggy cams :-)

Google: inurl:JPGLogin.htm
xxxxxx:80 : Server: GeoHttpServer
xxxxxx:80 : Title : singel-window-new-004-a


Phaser printers

Google: "display printer status" intitle:"Home"

Lexmark printers

intitle:"Lexmark *" inurl:port_0

3com OfficeConnect Wireless 11g Access Point

Google: intitle:"OfficeConnect Wireless 11g Access Point" "Checking your browser"

Google Inside Yo' Head

Google Hacking can be addictive..
It can even give you g00gle eyes :)

Image Hosted by ImageShack.us


Imaged created by Jimmy Neutron.

A new Googlehackers blog !

Hi and welcome here.

This blog will show you the latest discoveries of things (devices, pages, etc) found with Google Hacking.

We will post screenshots, tips and searches.

Have fun, do good.