Sensitive Files
Although some of these are system files, they are included in this web section as they are the standard targets for Arbitrary File Read and LFI exploits.
Apache
Web Server Configuration
/etc/apache2/apache2.conf
/etc/apache2/sites-enabled/000-default.conf
/etc/httpd/conf/httpd.conf
/usr/local/apache2/conf/httpd.confWeb Server Logs
/var/log/apache2/access.log
/var/log/apache2/error.log
/usr/local/apache2/logs/access_log
/usr/local/apache2/logs/error_logWindows System Files
System Files
IIS Logs
Application Files
SAM Database (Encrypted passwords)
User Files
Last updated