What makes websites vulnerable
Website vulnerable for following reasons
Intrusion Techniques (outcomes) (4)
Website Misconfigurations
Web Server Logs (4)
Artifacts to look at re Web servers (3)
- website content (possible for malicious content)
IIS Log File Contents
Apache Log File
- ideal for grep
3rd Party Tools examples
Log Location for IIS
C:\Windows\System32\LogFiles
%SystemDrive%\Inetpub\Logs\Logfiles
Microsoft FTP Status Codes: 200 226 250 331 332 421
200 - Command OK 226 - closing data connection (success) 250 - file action okay, completed 331 - user name ok, need pass 332 - need account for login 421 - connection closed, service not available
Microsoft IIS Status Codes: 200 201 401.1 401.3 403.1 403.2 403.3 403.14
200 - OK. The client request has succeeded. 201 - Created. 401.1 - Logon failed. 401.3 - Unauthorized due to ACL on resource. 403.1 - Execute access forbidden. 403.2 - Read access forbidden. 403.3 - Write access forbidden. 403.14 - Directory listing denied.
Web site intrusion Tactics