LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Bug Reports > full path disclosure on autoindex

Reply
 
Thread Tools Display Modes
  #1  
Old 11-02-2007, 01:36 AM
felosi felosi is offline
Senior Member
 
Join Date: Jun 2007
Posts: 249
Default full path disclosure on autoindex

For example if you chmod a directory 000 in order to disable it
Like this http://protectedhost.com/test/
http://sph1.net/test

Instead of giving a php error displaying full path it should simply give a forbidden error. It does the same any time it cannot read any folder, despite the contents

Is there any quick fix for this? Its somewhat of a security risk because it displays full path giving the sites username on the server.
Seems like it should invoke an error page instead of trying to open autoindex
Despite error reporting off will still show this

Last edited by felosi; 11-02-2007 at 01:45 AM..
Reply With Quote
  #2  
Old 11-02-2007, 05:04 AM
brrr brrr is offline
Senior Member
 
Join Date: Aug 2007
Posts: 94
Some suggestions...

Disable auto-index for that server. And your PHP error reporting settings in php.ini may also be a factor too - eg ensure display_errors = Off.

But yeah, when LSWS encounters a file-system resource that it has no permissions to access, I would have thought a 403 error would have come up despite every other setting on the server.
Reply With Quote
  #3  
Old 11-02-2007, 07:03 AM
felosi felosi is offline
Senior Member
 
Join Date: Jun 2007
Posts: 249
does the same despite display errors, the links I posted display errors is on. Which I really have to leave that on so people can see problems with their apps, sites, etc
bottom one is with error reporting off
Reply With Quote
  #4  
Old 11-02-2007, 07:50 AM
admin admin is offline
LiteSpeed Staff
 
Join Date: Apr 2006
Posts: 6
OK. We will set "display_errors = off" for the autoindex script.
Reply With Quote
  #5  
Old 11-02-2007, 07:51 AM
admin admin is offline
LiteSpeed Staff
 
Join Date: Apr 2006
Posts: 6
And the autoindex script will be changed not to show the error.
Reply With Quote
  #6  
Old 11-02-2007, 01:34 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
Changes has been made to the latest 3.3 build, you are welcome to give it a try.
Reply With Quote
  #7  
Old 11-04-2007, 08:05 AM
felosi felosi is offline
Senior Member
 
Join Date: Jun 2007
Posts: 249
Will give it a try tonight, been taking the weekend off. A much needed break, been working 7 days a week like 2 years now

Thanks guys
Reply With Quote
  #8  
Old 11-07-2007, 07:33 PM
felosi felosi is offline
Senior Member
 
Join Date: Jun 2007
Posts: 249
tried the 3.3 build, soon as I did, all sites got a 503 error and wouldnt load
Reply With Quote
  #9  
Old 11-07-2007, 08:17 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
Are you using PHP suExec on that server?
Reply With Quote
  #10  
Old 11-08-2007, 05:53 AM
felosi felosi is offline
Senior Member
 
Join Date: Jun 2007
Posts: 249
yeah, all of them I do
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 04:51 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.