Jump to content

How can I eliminate "Full path disclosure" bugs?


chantown

Recommended Posts

1. No, not really.... no one can do anything directly to you using only full path disclosure (FPD). FPD only becomes a problem if used in conjunction with another vulnerability. In fact, a large majority of servers use very similar pathing for user files, so in these cases, FPD can be easily guessed. This isn't a problem unless you have other insecurities.

 

2. Absolutely, and is recommended for production servers. Set display_errors = Off in php.ini

 

PhREEEk

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.