iEntry 10th Anniversary RSS Newsletter Advertising
Join the WebProWorld Forum!

How Google Can Find Your Secret Page

Amazingly enough, some webmasters haven't learned about Google yet, and how easy it is to retrieve pages that have been poorly protected from being viewed.

When the blogger behind the brand new EvolvedLight blog wanted to find out more information regarding an accident at Alton Towers amusement park in Staffordshire, England, the quest for information led to the park's media page.

"This site is for Media use only. To gain an access password please call 01538 704015," reads the page. Instead, the blogger turned to the ubiquitous Google to indulge in a little Google hacking.

In looking at the source code, one section revealed that whatever is entered as a password would trigger a redirect to a page named {password}.html. The right password would reveal the press page.

So the blogger sent Google a simple search string: * site:http://press.altontowers.com and guess what was revealed as the third result in the SERPs?

"Welcome to the Alton Towers Press Site," said the revealed page, called pressxpsa.html. That means the password would be pressxpsa.

And indeed it is. To call this a poorly designed page would be an insult to poorly designed pages everywhere. In the interest of helping out someone in need, here is a Microsoft link on securing ASP pages for the amusement park's Windows Server 2003 host running IIS 6.

---
Tag:

Add to Del.icio.us | Digg | Yahoo! My Web | Furl

Bookmark WebProNews:

David Utter is a staff writer for WebProNews covering technology and business.

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
2 + 8 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.
Featured Headline
FriendFeed Offers Real-Time Search
Results Actually Roll In
2 comments | 14 hours ago
 
Subscribe to WebProNews


Send me relevant info