Page 50 - Hands-On Bug Hunting for Penetration Testers
P. 50
Preparing for an Engagement Chapter 3
Sitemaps
Sitemaps are an absurdly simple way of doing basic research with zero effort. Doing a little
URL hacking with the TJUFNBQ YNM slug will often return either an actual XML file
detailing the site's structure, or a Yoast-or-other-seo-plugin-supplied HTML page
documenting different areas of the site, with separate sitemaps for posts, pages, and so on.
The following is an example of a Yoast-generated sitemap page:
It helpfully exposes the high-level structure of the site while allowing you to focus on
important points. Some areas can be skipped: the QPTU TJUFNBQ YNM and QPTU
TJUFNBQ YNM sections, listing the links to every blog post on the site, aren't useful because
every blog post will more or less have the same points of attack (comments, like/dislike
buttons, and social sharing).
[ 35 ]

