top | item 39899860

(no title)

lwilli | 1 year ago

This is ironic... https://owasp.org/Top10/A05_2021-Security_Misconfiguration/

discuss

order

hypeatei|1 year ago

Disabling directory listing/indexes is the first thing on a "web server hardening" checklist, or so I thought...

thinking_monkey|1 year ago

One would think so. I remember looking through my very first hosting provider's settings page for my site and saw that "Directory Listing" (or similar) was "On". I thought to myself "Well that doesn't sound right, if it means what it sounds like it means." I Googled and that's what it meant. I turned it off. So if a complete newb setting up his first website thought it was a bad idea, one would think, like you said, that a cyber security company would know to disable it (or double and triple check that it's disabled). With all that said, hopefully this is an April Fool's prank.