KathanP19 / HowToHunt

Collection of methodology and test case for various web vulnerabilities.
GNU General Public License v3.0
6.05k stars 1.73k forks source link

version leak #186

Closed TCode110 closed 3 years ago

TCode110 commented 3 years ago

step1. go to the target says- https://redacted.com step2. open view page source step3. check for path, directories step4. go that path says- https://redacted.com/theme/css/file.css step5. try to visit all directories and check it is accessible or not. step5. if it is give 403 step6. add %0, %m, %2e, says- https://redacted.com/%0theme and then check the response, it will show the running server name, and version information.

And check for also css path url, sometime there some path.