OWASP Periodic Table of Vulnerabilities - Directory Indexing

From OWASP
Revision as of 13:00, 14 May 2013 by James Landis (Talk | contribs)

Jump to: navigation, search

Return to Periodic Table Working View

Contents

Directory Indexing

Root Cause Summary

A misconfigured server can show a directory listing, which could potentially yield sensitive information to an attacker.

Browser / Standards Solution

None

Perimeter Solution

  • Disable directory listings in the web- or application-server configuration by default.
  • Restrict access to unnecessary directories and files.
  • Create an index (default) file for each directory.

Complexity: Low
Impact: Low

Generic Framework Solution

None

Custom Framework Solution

None

Custom Code Solution

None

Discussion / Controversy

None

References

Information Exposure Through Directory Listing (Mitre)
Security Misconfiguration (OWASP)
Insecure Indexing (OWASP)