{"id":17148,"date":"2024-11-25T07:50:23","date_gmt":"2024-11-25T05:50:23","guid":{"rendered":"https:\/\/cryptrz.org\/wordpress\/?p=17148"},"modified":"2025-05-14T05:43:32","modified_gmt":"2025-05-14T03:43:32","slug":"quest-ce-que-000root000","status":"publish","type":"post","link":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/","title":{"rendered":"Qu&rsquo;est-ce que 000~ROOT~000 ?"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Contexte<\/h2>\n\n\n\n<p>Il y a quelques mois j&rsquo;\u00e9tais tomb\u00e9 par hasard sur un tweet (Oui je sais, je devrais dire \u00ab\u00a0<a href=\"https:\/\/metro.co.uk\/2023\/07\/25\/twitter-x-elon-must-what-tweets-new-name-19188877\/\" target=\"_blank\" rel=\"noreferrer noopener\">post<\/a>\u00a0\u00bb depuis que Twitter est devenu X et que Elon est devenu humoriste mais on s&rsquo;en fout) destin\u00e9 principalement aux <a href=\"https:\/\/guardia.school\/metiers\/bug-bounty-hunter.html\" target=\"_blank\" rel=\"noreferrer noopener\">bug bounty hunters<\/a> et qui mentionnait un nom de dossier que je n&rsquo;avais jamais vu sur un serveur <a href=\"https:\/\/apache.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">Apache<\/a>. Il s&rsquo;agit de <strong>\/home\/000~ROOT~000<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/twitter.com\/NoRed0x\/status\/1827721373416038529?t=FYuBSLUZIYw9G7g-FmV2Zw\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" width=\"596\" height=\"684\" src=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-12.png\" alt=\"Tweet indiquant d'ajouter \u00b4home\/000~ROOT~000'dans nos wordlists de bug bounty hunters\" class=\"wp-image-17150\" srcset=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-12.png 596w, https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-12-261x300.png 261w\" sizes=\"auto, (max-width: 596px) 100vw, 596px\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Premiers tests<\/h2>\n\n\n\n<p>Plut\u00f4t que de l&rsquo;ajouter \u00e0 une <a href=\"https:\/\/github.com\/danielmiessler\/SecLists\" target=\"_blank\" rel=\"noreferrer noopener\">wordlist<\/a> pour faire du <a href=\"https:\/\/fr.wikipedia.org\/wiki\/Fuzzing\" target=\"_blank\" rel=\"noreferrer noopener\">fuzzing<\/a>, j&rsquo;ai simplement regard\u00e9 sur <a href=\"https:\/\/www.google.com\/search?q=%22home%2F000%7EROOT%7E000%22&amp;sca_esv=bb0627a757e7aa61&amp;sxsrf=ADLYWII2FP12nhqh4tizABdOkbyR_ltzwQ%3A1732465987693&amp;source=hp&amp;ei=Q1VDZ4qDJ6iChbIPntmwWQ&amp;iflsig=AL9hbdgAAAAAZ0NjU-w3rS3fPd4vcWSX90VGi0WFvFpr&amp;ved=0ahUKEwjKsJ3esvWJAxUoQUEAHZ4sLAsQ4dUDCBg&amp;uact=5&amp;oq=%22home%2F000%7EROOT%7E000%22&amp;gs_lp=Egdnd3Mtd2l6GgIYASITImhvbWUvMDAwflJPT1R-MDAwIjIGEAAYFhgeMgYQABgWGB4yBhAAGBYYHjIGEAAYFhgeMgsQABiABBiGAxiKBTILEAAYgAQYhgMYigUyCxAAGIAEGIYDGIoFMgsQABiABBiiBBiLAzILEAAYgAQYogQYiwMyCxAAGIAEGKIEGIsDSP8BUABYAHAAeACQAQCYAaIBoAGiAaoBAzAuMbgBA8gBAPgBAvgBAZgCAaACqQGYAwCSBwMwLjGgB88G&amp;sclient=gws-wiz\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a> ce qui ressortait. Pas mal de serveurs sont list\u00e9s.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"855\" height=\"901\" src=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-13.png\" alt=\"Recherche du chemin \u00b4home\/000~ROOT~000'sur Google\" class=\"wp-image-17153\" srcset=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-13.png 855w, https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-13-285x300.png 285w, https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-13-768x809.png 768w\" sizes=\"auto, (max-width: 855px) 100vw, 855px\" \/><\/figure>\n\n\n\n<p>Si on regarde un peu les premiers r\u00e9sultats, les dossiers syst\u00e8mes sont accessibles, tout comme ceux des utilisateurs. On peut rapidement voir quelques noms int\u00e9ressants comme <strong><a href=\"https:\/\/fr.wikipedia.org\/wiki\/Automatisme\" target=\"_blank\" rel=\"noreferrer noopener\">automation<\/a><\/strong>, <strong><a href=\"https:\/\/fr.wikipedia.org\/wiki\/Sauvegarde_(informatique)\" target=\"_blank\" rel=\"noreferrer noopener\">backup<\/a><\/strong>, <strong><a href=\"https:\/\/fr.wikipedia.org\/wiki\/AppArmor\" target=\"_blank\" rel=\"noreferrer noopener\">apparmor<\/a><\/strong>, <strong><a href=\"https:\/\/fr.wikipedia.org\/wiki\/Certificat_%C3%A9lectronique\" target=\"_blank\" rel=\"noreferrer noopener\">certificates<\/a><\/strong>, <strong><a href=\"https:\/\/fr.wikipedia.org\/wiki\/Cron\" target=\"_blank\" rel=\"noreferrer noopener\">cron<\/a><\/strong>, etc&#8230;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"539\" height=\"854\" src=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-14.png\" alt=\"Un des r\u00e9sultats trouv\u00e9s sur Google montrant le contenu de \u00b4home\/000~ROOT~000\u00b4. Certains noms comme automation ou backup peuvent attirer l'attention\" class=\"wp-image-17154\" srcset=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-14.png 539w, https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-14-189x300.png 189w\" sizes=\"auto, (max-width: 539px) 100vw, 539px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"987\" src=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-15.png\" alt=\"Un autre r\u00e9sultat trouv\u00e9 sur Google dont on voit aussi le contenu de \u00b4home\/000~ROOT~000'. Plusieurs choses attirent l'oeil comme pwd.lock, les ca-certificates ou les fichiers cron et crontab\" class=\"wp-image-17155\" srcset=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-15.png 571w, https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-15-174x300.png 174w\" sizes=\"auto, (max-width: 571px) 100vw, 571px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Analyse de la situation<\/h2>\n\n\n\n<p>Encore aujourd&rsquo;hui, m\u00eame si je comprends l&rsquo;utilit\u00e9 de ce dossier du point de vue d&rsquo;un hacker (\u00e9thique ou pas), pentester, ou hunter, pour trouver des informations utiles pour une future attaque, je ne suis pas s\u00fbr de comprendre l&rsquo;origine technique de ce ph\u00e9nom\u00e8ne. Je vais donc exposer ici mes \u00e9ventuelles suppositions en esp\u00e9rant que \u00e7a provoque un effet <a href=\"https:\/\/fr.wikipedia.org\/wiki\/M%C3%A9thode_du_canard_en_plastique\" target=\"_blank\" rel=\"noreferrer noopener\">rubber duck debugging<\/a>. N&rsquo;h\u00e9sitez pas \u00e0 apporter plus de pr\u00e9cision en commentaire si vous connaissez d\u00e9j\u00e0 ce sujet et que je passe \u00e0 c\u00f4t\u00e9 d&rsquo;un \u00e9l\u00e9ment important, je suis preneur.<\/p>\n\n\n\n<p>Les suppositions sont:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Un nom de r\u00e9pertoire personnalis\u00e9 Il est possible que <strong>000~ROOT~000<\/strong> soit un nom de r\u00e9pertoire personnalis\u00e9 cr\u00e9\u00e9 par un administrateur syst\u00e8me (m\u00eame si plusieurs sysadmins qui personnalisent de la m\u00eame mani\u00e8re en provoquant la m\u00eame faiblesse, c&rsquo;est peu probable), une application ou un script. La partie ~ROOT~ peut sugg\u00e9rer que le r\u00e9pertoire a quelque chose \u00e0 voir avec une fonction de niveau racine ou syst\u00e8me. Il peut s&rsquo;agir d&rsquo;un dossier utilis\u00e9 pour les sauvegardes, les journaux syst\u00e8me ou un r\u00e9pertoire de remplacement. <br><\/li>\n\n\n\n<li>R\u00e9pertoire de sauvegarde ou temporaire La convention de d\u00e9nomination <strong>000~ROOT~000<\/strong> peut indiquer un dossier de sauvegarde ou temporaire. Les chiffres 000 aux deux extr\u00e9mit\u00e9s peuvent repr\u00e9senter une sorte de syst\u00e8me de version ou de s\u00e9quen\u00e7age. Par exemple, un syst\u00e8me de sauvegarde peut g\u00e9n\u00e9rer des r\u00e9pertoires num\u00e9rot\u00e9s pour conserver plusieurs \u00e9tats de sauvegarde, et ROOT peut signifier qu&rsquo;il s&rsquo;agit de donn\u00e9es importantes au niveau du syst\u00e8me ou de la racine.<br><\/li>\n\n\n\n<li>R\u00e9pertoire du syst\u00e8me ou de l&rsquo;application web Il peut \u00e9galement s&rsquo;agir d&rsquo;un r\u00e9pertoire cr\u00e9\u00e9 par une application web, un syst\u00e8me de gestion de contenu (CMS) ou un syst\u00e8me d&rsquo;h\u00e9bergement web. Certains syst\u00e8mes de gestion de contenu ou d&rsquo;h\u00e9bergement utilisent des sch\u00e9mas de d\u00e9nomination bizarres pour stocker des configurations, des sauvegardes ou des fichiers sp\u00e9cifiques li\u00e9s au site. La partie ROOT peut faire r\u00e9f\u00e9rence au r\u00e9pertoire racine d&rsquo;une application ou d&rsquo;un site web sp\u00e9cifique.<br><\/li>\n\n\n\n<li>Anomalie du syst\u00e8me de fichiers ou du serveur Il est \u00e9galement possible qu&rsquo;il s&rsquo;agisse d&rsquo;un artefact ou d&rsquo;une erreur r\u00e9sultant d&rsquo;une mauvaise configuration du syst\u00e8me de fichiers, d&rsquo;un script ou d&rsquo;un processus automatis\u00e9. Si, par exemple, une application ou une t\u00e2che syst\u00e8me ne s&rsquo;est pas d\u00e9roul\u00e9e correctement, il peut en r\u00e9sulter un nommage inhabituel des r\u00e9pertoires.<br><\/li>\n\n\n\n<li>Tout simplement un <a href=\"https:\/\/fr.wikipedia.org\/wiki\/Lien_symbolique\" target=\"_blank\" rel=\"noreferrer noopener\">symlink<\/a>, m\u00eame si je vois pas dans quel contexte ce serait cr\u00e9\u00e9.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Que faire si votre serveur est impact\u00e9? <\/h2>\n\n\n\n<p>Si vous g\u00e9rez un ou plusieurs serveurs web, il serait pr\u00e9f\u00e9rable de v\u00e9rifier s&rsquo;il apparait sur Google en ajoutant le dork inurl et votre nom de domaine \u00e0 la recherche vue pr\u00e9c\u00e9demment: <\/p>\n\n\n\n<p><code>\"home\/000~ROOT~000\" inurl:\"example.com\"<\/code><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"872\" height=\"944\" src=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-18.png\" alt=\"Exemple de recherche Google cibl\u00e9e en utilisant le dork inurl pour v\u00e9rifier si le contenu de 'home\/000~ROOT~000' est disponible pour un site sp\u00e9cifique\" class=\"wp-image-17158\" srcset=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-18.png 872w, https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-18-277x300.png 277w, https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-18-768x831.png 768w\" sizes=\"auto, (max-width: 872px) 100vw, 872px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Si vous voyez votre site dans les r\u00e9sultats de recherche comme dans cet exemple ci-dessus, voici quelques possibles v\u00e9rifications \u00e0 effectuer afin d&rsquo;y rem\u00e9dier ou au moins d&rsquo;en limiter l&rsquo;impact (Comme je ne connais pas encore la raison pr\u00e9cise, ce sont plus des pr\u00e9cautions que de vraies rem\u00e9diations)<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>V\u00e9rifiez le contenu du r\u00e9pertoire<\/strong> : Si vous avez acc\u00e8s au syst\u00e8me, selon <a href=\"https:\/\/www.redhat.com\/fr\/topics\/cloud-computing\/iaas-vs-paas-vs-saas\" target=\"_blank\" rel=\"noreferrer noopener\">le type de serveur<\/a> que vous utilisez, examinez le contenu du r\u00e9pertoire <strong>home\/000~ROOT~000<\/strong>. Recherchez les fichiers qui pourraient indiquer son utilit\u00e9. Si le r\u00e9pertoire est vide ou contient des fichiers \u00e9tranges, cela peut indiquer un probl\u00e8me.<\/li>\n\n\n\n<li><strong>Examinez les journaux du serveur<\/strong> : V\u00e9rifiez les journaux du syst\u00e8me (tels que <strong>\/var\/log\/<\/strong> sous Linux) pour toute activit\u00e9 inhabituelle li\u00e9e \u00e0 ce r\u00e9pertoire. Cela peut vous aider \u00e0 d\u00e9terminer s&rsquo;il a \u00e9t\u00e9 cr\u00e9\u00e9 par un processus ou une application.<\/li>\n\n\n\n<li><strong>Analyses de s\u00e9curit\u00e9<\/strong> : Ex\u00e9cutez une analyse de s\u00e9curit\u00e9 sur le serveur pour v\u00e9rifier la pr\u00e9sence de logiciels malveillants ou d&rsquo;activit\u00e9s suspectes. Des outils tels que <a href=\"https:\/\/www.clamav.net\/\" target=\"_blank\" rel=\"noreferrer noopener\">ClamAV<\/a>, <a href=\"https:\/\/rkhunter.sourceforge.net\/\" target=\"_blank\" rel=\"noreferrer noopener\">rkhunter<\/a> ou <a href=\"https:\/\/www.chkrootkit.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">chkrootkit<\/a> peuvent aider \u00e0 d\u00e9tecter des compromissions potentielles.<\/li>\n\n\n\n<li><strong>V\u00e9rifier les probl\u00e8mes de configuration<\/strong> : V\u00e9rifiez si des applications ou des serveurs web (comme <strong>Apache<\/strong>) g\u00e9n\u00e8rent ou utilisent ce r\u00e9pertoire. S&rsquo;il est li\u00e9 \u00e0 une application web, examinez les fichiers de configuration pour comprendre pourquoi il est cr\u00e9\u00e9.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Que faire si votre site pr\u00e9f\u00e9r\u00e9 est impact\u00e9? <\/h2>\n\n\n\n<p>Si vous trouvez ce genre de dossier lors d&rsquo;un pentest ou d&rsquo;exploration random un peu pouss\u00e9e, prenez 5mn pour en faire part au(x) responsable(s) du site web. En g\u00e9n\u00e9ral on peut trouver un formulaire de contact ou une adresse email dans le menu principal ou en bas de page, vous aiderez probablement un sysadmin qui n&rsquo;\u00e9tait pas au courant de ce leak.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sur certains serveurs Apache on peut trouver un dossier \/home\/000~ROOT~000. Tentons de comprendre \u00e0 quoi il sert et le risque qu&rsquo;il pr\u00e9sente. &hellip; <a href=\"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/\" class=\"more-link\"><span class=\"readmore\">Continue reading<span class=\"screen-reader-text\">Qu&rsquo;est-ce que 000~ROOT~000 ?<\/span><\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[8,73,105,60],"tags":[120,121,122],"class_list":["post-17148","post","type-post","status-publish","format-standard","hentry","category-hacking","category-internet","category-linux","category-securite","tag-apache","tag-root","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Voyons ce qu&#039;est le dossier 000~ROOT~000 et comment il peut \u00eatre utile pour un bug bounty<\/title>\n<meta name=\"description\" content=\"Sur certains serveurs Apache on peut trouver un dossier \/home\/000~ROOT~000. Tentons de comprendre \u00e0 quoi il sert et le risque qu&#039;il pr\u00e9sente.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Voyons ce qu&#039;est le dossier 000~ROOT~000 et comment il peut \u00eatre utile pour un bug bounty\" \/>\n<meta property=\"og:description\" content=\"Sur certains serveurs Apache on peut trouver un dossier \/home\/000~ROOT~000. Tentons de comprendre \u00e0 quoi il sert et le risque qu&#039;il pr\u00e9sente.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/\" \/>\n<meta property=\"og:site_name\" content=\"Cryptrz\" \/>\n<meta property=\"article:published_time\" content=\"2024-11-25T05:50:23+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-14T03:43:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-12.png\" \/>\n\t<meta property=\"og:image:width\" content=\"596\" \/>\n\t<meta property=\"og:image:height\" content=\"684\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"cryptrz\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"cryptrz\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/\"},\"author\":{\"name\":\"cryptrz\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/#\\\/schema\\\/person\\\/24ebe8f2cc302fa3336ab7509a09b7ec\"},\"headline\":\"Qu&rsquo;est-ce que 000~ROOT~000 ?\",\"datePublished\":\"2024-11-25T05:50:23+00:00\",\"dateModified\":\"2025-05-14T03:43:32+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/\"},\"wordCount\":980,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/#\\\/schema\\\/person\\\/24ebe8f2cc302fa3336ab7509a09b7ec\"},\"image\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/image-12.png\",\"keywords\":[\"apache\",\"root\",\"vulnerability\"],\"articleSection\":[\"Hacking\",\"Internet\",\"Linux\",\"S\u00e9curit\u00e9\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/\",\"url\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/\",\"name\":\"Voyons ce qu'est le dossier 000~ROOT~000 et comment il peut \u00eatre utile pour un bug bounty\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/image-12.png\",\"datePublished\":\"2024-11-25T05:50:23+00:00\",\"dateModified\":\"2025-05-14T03:43:32+00:00\",\"description\":\"Sur certains serveurs Apache on peut trouver un dossier \\\/home\\\/000~ROOT~000. Tentons de comprendre \u00e0 quoi il sert et le risque qu'il pr\u00e9sente.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/image-12.png\",\"contentUrl\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/image-12.png\",\"width\":596,\"height\":684},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2024\\\/11\\\/25\\\/quest-ce-que-000root000\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Qu&rsquo;est-ce que 000~ROOT~000 ?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/#website\",\"url\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/\",\"name\":\"Cryptrz\",\"description\":\"Franck Ridel\",\"publisher\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/#\\\/schema\\\/person\\\/24ebe8f2cc302fa3336ab7509a09b7ec\"},\"alternateName\":\"Franck Ridel\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/#\\\/schema\\\/person\\\/24ebe8f2cc302fa3336ab7509a09b7ec\",\"name\":\"cryptrz\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/cover-design.jpg\",\"url\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/cover-design.jpg\",\"contentUrl\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/cover-design.jpg\",\"width\":1024,\"height\":1024,\"caption\":\"cryptrz\"},\"logo\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/cover-design.jpg\"},\"description\":\"Sysadmin de Luxembourg House of Cybersecurity fan d'open source et autres Unixeries\",\"sameAs\":[\"https:\\\/\\\/cryptrz.org\\\/wordpress\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/franck-ridel\\\/\",\"https:\\\/\\\/www.youtube.com\\\/@FranckRidel\",\"https:\\\/\\\/soundcloud.com\\\/franck-ridel-2\"],\"url\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/author\\\/cryptrz\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Voyons ce qu'est le dossier 000~ROOT~000 et comment il peut \u00eatre utile pour un bug bounty","description":"Sur certains serveurs Apache on peut trouver un dossier \/home\/000~ROOT~000. Tentons de comprendre \u00e0 quoi il sert et le risque qu'il pr\u00e9sente.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/","og_locale":"fr_FR","og_type":"article","og_title":"Voyons ce qu'est le dossier 000~ROOT~000 et comment il peut \u00eatre utile pour un bug bounty","og_description":"Sur certains serveurs Apache on peut trouver un dossier \/home\/000~ROOT~000. Tentons de comprendre \u00e0 quoi il sert et le risque qu'il pr\u00e9sente.","og_url":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/","og_site_name":"Cryptrz","article_published_time":"2024-11-25T05:50:23+00:00","article_modified_time":"2025-05-14T03:43:32+00:00","og_image":[{"width":596,"height":684,"url":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-12.png","type":"image\/png"}],"author":"cryptrz","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"cryptrz","Dur\u00e9e de lecture estim\u00e9e":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/#article","isPartOf":{"@id":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/"},"author":{"name":"cryptrz","@id":"https:\/\/cryptrz.org\/wordpress\/#\/schema\/person\/24ebe8f2cc302fa3336ab7509a09b7ec"},"headline":"Qu&rsquo;est-ce que 000~ROOT~000 ?","datePublished":"2024-11-25T05:50:23+00:00","dateModified":"2025-05-14T03:43:32+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/"},"wordCount":980,"commentCount":0,"publisher":{"@id":"https:\/\/cryptrz.org\/wordpress\/#\/schema\/person\/24ebe8f2cc302fa3336ab7509a09b7ec"},"image":{"@id":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/#primaryimage"},"thumbnailUrl":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-12.png","keywords":["apache","root","vulnerability"],"articleSection":["Hacking","Internet","Linux","S\u00e9curit\u00e9"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/","url":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/","name":"Voyons ce qu'est le dossier 000~ROOT~000 et comment il peut \u00eatre utile pour un bug bounty","isPartOf":{"@id":"https:\/\/cryptrz.org\/wordpress\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/#primaryimage"},"image":{"@id":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/#primaryimage"},"thumbnailUrl":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-12.png","datePublished":"2024-11-25T05:50:23+00:00","dateModified":"2025-05-14T03:43:32+00:00","description":"Sur certains serveurs Apache on peut trouver un dossier \/home\/000~ROOT~000. Tentons de comprendre \u00e0 quoi il sert et le risque qu'il pr\u00e9sente.","breadcrumb":{"@id":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/#primaryimage","url":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-12.png","contentUrl":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/11\/image-12.png","width":596,"height":684},{"@type":"BreadcrumbList","@id":"https:\/\/cryptrz.org\/wordpress\/2024\/11\/25\/quest-ce-que-000root000\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/cryptrz.org\/wordpress\/"},{"@type":"ListItem","position":2,"name":"Qu&rsquo;est-ce que 000~ROOT~000 ?"}]},{"@type":"WebSite","@id":"https:\/\/cryptrz.org\/wordpress\/#website","url":"https:\/\/cryptrz.org\/wordpress\/","name":"Cryptrz","description":"Franck Ridel","publisher":{"@id":"https:\/\/cryptrz.org\/wordpress\/#\/schema\/person\/24ebe8f2cc302fa3336ab7509a09b7ec"},"alternateName":"Franck Ridel","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptrz.org\/wordpress\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":["Person","Organization"],"@id":"https:\/\/cryptrz.org\/wordpress\/#\/schema\/person\/24ebe8f2cc302fa3336ab7509a09b7ec","name":"cryptrz","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/09\/cover-design.jpg","url":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/09\/cover-design.jpg","contentUrl":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/09\/cover-design.jpg","width":1024,"height":1024,"caption":"cryptrz"},"logo":{"@id":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/09\/cover-design.jpg"},"description":"Sysadmin de Luxembourg House of Cybersecurity fan d'open source et autres Unixeries","sameAs":["https:\/\/cryptrz.org\/wordpress","https:\/\/www.linkedin.com\/in\/franck-ridel\/","https:\/\/www.youtube.com\/@FranckRidel","https:\/\/soundcloud.com\/franck-ridel-2"],"url":"https:\/\/cryptrz.org\/wordpress\/author\/cryptrz\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/posts\/17148","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/comments?post=17148"}],"version-history":[{"count":17,"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/posts\/17148\/revisions"}],"predecessor-version":[{"id":18057,"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/posts\/17148\/revisions\/18057"}],"wp:attachment":[{"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/media?parent=17148"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/categories?post=17148"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/tags?post=17148"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}