Web Security Test Learning----Information Disclosure Test __web

Source: Internet
Author: User
Tags exception handling

1, the configuration file key information is encrypted: such as database connection account password

2, page source code sensitive information: such as modify Password page changes to see the source code is not clear

3, code comments sensitive information: Does not include such as: Intranet IP address, SQL statements, passwords, physical path, etc.

4, exception handling sensitive information: Error request return does not contain sensitive information such as: Server version

5, WebService page information: such as Axis released happyaxis.jsp can not directly access

6. Web Server status information: Error parameter request

7, upload directory and temporary directory Access

8, log directory, log files clear information disclosure

9, the common file storage format (such as database connection information, source on behalf of the dock file, etc.)

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.