Directory Listening

Disclosed: 2016-09-14 15:07:28 By kiraak-boy To gocd
Unknown
Vulnerability Details
Hello Team, Found Directory Listening : http://IP:8153/go/NOTICE/ {F105317} There is not usually any good reason to provide directory listings, and disabling them may place additional hurdles in the path of an attacker. This can normally be achieved in two ways: Configure your web server to prevent directory listings for all paths beneath the web root; Place into each directory a default file (such as index.htm) that the web server will display instead of returning a directory listing. Thanks! Best, Arbaz
Actions
View on HackerOne
Report Stats
  • Report ID: 151772
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report