Re: Re: Script Visability and Security

by echo (Pilgrim)
on Sep 18, 2001 at 11:24 UTC ( #113059=note: print w/replies, xml ) Need Help??

in reply to Re: Script Visability and Security
in thread Script Visability and Security

If the cgi environment is set up correctly, advertising the location of the script has no effect on security.

True, and this is the well-known There's no security through obscurity. However revealing such information is still a bad idea. Although it may not have a direct effect on this CGI script, it does reveal private information about the server which may be used to exploit another vulnerability, in another program or script. Think of a potential attacker quietly collecting all sorts of tidbits about how the server is layed out. Each piece of information is not a security issue in itself, but in the end it all adds up and can provide the attacker with enough information to compromise the system. That is why disclosing file system paths is never a good idea, and such bugs are a frequent topic on Bugtraq.

