Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos

Security Basics: Re: Coldfusion Path Disclosure Vulnerability, Help Required

Re: Coldfusion Path Disclosure Vulnerability, Help Required

From: Clinton Moore <clintonmoore_at_gmail.com>
Date: Fri, 4 Mar 2005 17:49:32 -0500

Most web servers install to a default path. If an attacker could
glean the physical path of the web server, then one could assume you
used the default installation of "web server X version Y" and work
from there on known issues with your particular server. Also, just as
a basic rule the less information you give out the better. I am sure
there are other reasons, but none pop out at me at the moment.

-Clint
Received on Mar 07 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]