<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Sk9</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Sk9"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Sk9"/>
		<updated>2026-04-04T14:58:15Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Forced_browsing&amp;diff=19884</id>
		<title>Forced browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Forced_browsing&amp;diff=19884"/>
				<updated>2007-07-15T17:19:58Z</updated>
		
		<summary type="html">&lt;p&gt;Sk9: /* Attack Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Attack}}&lt;br /&gt;
&lt;br /&gt;
==Attack Description==&lt;br /&gt;
&lt;br /&gt;
Forced browsing is a technique used by attackers to gain access to resources that are not referenced, but are nevertheless accessible.&lt;br /&gt;
&lt;br /&gt;
One technique is to manipulate the URL in the browser by deleting sections from the end until an unprotected directory is found. A related technique is to use a scanning tool like [http://www.ngolde.de/w3bfukk0r.html w3bfukk0r] or [[nikto]] to request common directories until a hidden file or directory is found.&lt;br /&gt;
&lt;br /&gt;
Another technique is to use manual penetration testing to attempt access to resources that are not referenced in the application. For example, an attacker might use [[WebScarab]] to change request parameters that specify the target resource.&lt;br /&gt;
&lt;br /&gt;
==Related Threats==&lt;br /&gt;
&lt;br /&gt;
==Related Vulnerabilities==&lt;br /&gt;
&lt;br /&gt;
[[Failure to verify authorization]]&lt;br /&gt;
&lt;br /&gt;
[[Failure to disable directory listings]]&lt;br /&gt;
&lt;br /&gt;
==Related Countermeasures==&lt;br /&gt;
&lt;br /&gt;
[[:Category:Access Control | Access Control]]&lt;br /&gt;
&lt;br /&gt;
{{Template:Stub}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Attack]]&lt;/div&gt;</summary>
		<author><name>Sk9</name></author>	</entry>

	</feed>