Chúng không an toàn trong và của không ngăn chặn người dùng tải các tập tin nhất định hay truy cập vào một số nhiệm vụ thường còn lại để bảo vệ các biện pháp xây dựng trong phần mềm máy chủ Web hoặc bên thứ ba kịch bản, các mô-đun, hoặc các chương trình thiết kế đặc biệt cho mục đích đó. Họ có thể hiển thị thông tin giúp kẻ tấn công tìm hiểu chi tiết kỹ thuật cụ thể về máy chủ Web | Google Hacking Basics Chapter 3 101 They are not secure in and of do not prevent users from downloading certain files or accessing certain task is often left to the protection measures built into the Web server software or third-party scripts modules or programs designed specifically for that purpose. They can display information that helps an attacker learn specific technical details about the Web server. They do not discriminate between files that are meant to be public and those that are meant to remain behind the scenes. They are often displayed accidentally since many Web servers display a directory listing if a top-level index file and so on is missing or invalid. All this adds up to a deadly combination. In this section we ll take a look at some of the ways Google hackers can take advantage of directory listings. Locating Directory Listings The most obvious way an attacker can abuse a directory listing is by simply finding one Since directory listings offer parent directory links and allow browsing through files and folders even the most basic attacker might soon discover that sensitive data can be found by simply locating the listings and browsing through them. Locating directory listings with Google is fairly straightforward. Figure shows that most directory listings begin with the phrase Index of which also shows in the title. An obvious query to find this type of page might be ntitle which could find pages with the term index of in the title of the document. Remember that the period . serves as a single-character wildcard in Google. Unfortunately this query will return a large number of false positives such as pages with the following titles Index of Native American Resources on the Internet LibDex - Worldwide index of library catalogues Iowa State Entomology Index of Internet Resources Judging from the titles of these documents it is obvious that not only are these Web pages