Skip to content

A threat actor may list files on a misconfigured server

License

Notifications You must be signed in to change notification settings

qeeqbox/directory-listing

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 
 
 
 
 
 
 

Repository files navigation

A threat actor may list files on a misconfigured server.

Example #1

  1. Threat actor scans server for "index of"
  2. Threat actor finds misconfigured server and scrapes some sensitive data

Impact

High

Risk

  • Data theft

Redemption

  • Deactivate directory listing

ID

f51859e9-1f29-4224-accd-976ab70e81c1

References

Sponsor this project