Page 50 - Hands-On Bug Hunting for Penetration Testers
P. 50

Preparing for an Engagement                                                 Chapter 3

            Sitemaps

            Sitemaps are an absurdly simple way of doing basic research with zero effort. Doing a little
            URL hacking with the  TJUFNBQ YNM slug will often return either an actual XML file
            detailing the site's structure, or a Yoast-or-other-seo-plugin-supplied HTML page
            documenting different areas of the site, with separate sitemaps for posts, pages, and so on.

            The following is an example of a Yoast-generated sitemap page:







































            It helpfully exposes the high-level structure of the site while allowing you to focus on
            important points. Some areas can be skipped: the QPTU TJUFNBQ  YNM and QPTU
            TJUFNBQ  YNM sections, listing the links to every blog post on the site, aren't useful because
            every blog post will more or less have the same points of attack (comments, like/dislike
            buttons, and social sharing).







                                                    [ 35 ]
   45   46   47   48   49   50   51   52   53   54   55