ZooWork
ZooWork Market · Skill

detecting-directory-listing

Probe a target for directories that return auto-generated index listings instead of denying or serving a specific file — exposes the full file tree under any reachable directory, including files the application never linked to. Use when: post-deploy verification on a static-asset host, security audit before SOC2, or following up on a finding from skill #6 (exposed-files) where a backup-file path returned 200 with HTML body instead of the expected file content (suggests autoindex serving a directory listing). Threshold: any directory-shaped path returns 200 with HTML body matching the framework-specific autoindex fingerprint (nginx fancyindex, Apache mod_autoindex Index of/, Caddy browse, Lighttpd mod_dirlisting, etc.). Trigger with: "directory listing check", "autoindex detection", "open directory scan".

◇
jeremylongshore
jeremylongshore-claude-code-plugins-plus-skills-detecting-directory-listing · v3.0.0-dev
分类devops-cloud
安装次数10
更新时间2026-09-12T03:26:49.878Z
校验状态待验证
securityinformation-disclosureautoindexpentest