Root directory listing = security hole

topic posted Fri, May 26, 2006 - 1:52 AM by  fish
Hi!

I read an article recently about a bug in the windows version of Apache where Apache would list the root directory of the server when it would encounter something like this:

http://webserversname///////////////////////////////////////////////////////////

'The trailing slashes could cause Apache to list the root directory of the server'

So i'm not a Windows user when it comes to Apache, i've got it running under Redhat 8, and it's version 2.0.40, and guess what; it does the same thing!

Has anyone experienced this before? I guess i need newer software, but preferrably a patch if there is any.

Thanks..
posted by:
fish
Netherlands

Recent topics in "Apache Web servers"

Topic Author Replies Last Post
New mac dev help needed jedi 1 August 11, 2007
can you be on call for this server and make some easy cash? 0 June 13, 2007
hosting reliability and live support 4 February 10, 2007
mySQL nat 2 November 29, 2006
apache config problem Ruku 1 April 19, 2006