2PTTechnology

The platform that enables you to build rich, interactive communities
Welcome to 2PTTechnology Sign in | Join | Help
in Search

Directory Browsing & Vulnerability in IIS (missing default document)

Last post 04-24-2007, 2:46 PM by Anonymous. 0 replies.
Sort Posts: Previous Next
  •  04-24-2007, 2:46 PM 44

    Directory Browsing & Vulnerability in IIS (missing default document)

    I’ve created a web site that is maintained by another (admin)website so basically if you look at the IIS, than you would see that

    I have a virtual folder within a virtual folder. The site is hosted on GoDaddy (whose customer service is laughable) and when I look at the IIS settings it automatically has directory browsing set to true. 

    Now since I didn’t follow their instructions and didn’t create a default.aspx, whenever I go to the admin site, the entire directory shows up. So anyone visiting is allowed access to the hypertext listing of the files and subdirectories in the virtual directory. Which is not good. So here is my question if I create a default.aspx should all my worries go away? Or is there a way that anyone can just look at the entire structure of my site even if a default.aspx exists?

     

    any ideas?

View as RSS news feed in XML
Powered by Community Server (Personal Edition), by Telligent Systems