Jump to content

full path disclosure


php_novice2007

Recommended Posts

  • 1 month later...

I don't have a solution to the problem as I have the exact same problem, and question.  Is there some way to prevent full path disclosure?  For the last post, what it is, where I have seen it anyway, is if there is an error message it will show the full path of where the file is that contains the error.  This gives hackers more information about the server and your file structure.  So...is there anyone out there willing to share how to prevent this?  Thanks.

 

Kevin

Link to comment
Share on other sites

Another security myth that needs a bit of debunking here...

 

Full path disclosure in itself is not a security concern. Due to the generalized way many servers setup web hosting accounts, the full path itself could be guessed QUITE EASILY in a lot of cases.

 

Anyways, to repeat... knowing the full path to your file system is NOT a security concern.

 

It only becomes a tool for a hacker if he successfully breaches other parts of your security. If you code correctly and have reasonable security measures already in place, a potential evil-doer can do nothing armed only with full path information.

 

PhREEEk

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.