When a web server or file-server application has directory listing enabled and no index file is present, it renders a browsable list of the directory's contents. That discloses every file in the path, including backups, archives, source, and configuration files that were never meant to be linked or indexed.
# Spot autoindex pages and spider them
curl -s http://<target>/files/ | grep -i 'Index of'
feroxbuster -u http://<target>/ -x bak,zip,old,txt,conf
Exploitation notes#
- The classic "Index of /" page exposes files by browsing; combine with content discovery to find listed directories.
- Look specifically for backups (
.bak,.zip,.old), source, and config files whose contents hold credentials. - A listed upload directory is a hint that upload is possible; see File upload to RCE.