📄 2062.txt
字号:
Rule:--Sid:2062--Summary:server performance and statistics package.--Impact:Information disclosure--Detailed Information:iPlanet web server uses the file .perf to display performance statisticsfor the server.An attacker can access the statistics for the server by making a requestfor the file .perf.--Affected Systems:iPlanet web servers using this object.--Attack Scenarios:The attacker merely needs to access http://www.foo.com/.perf--Ease of Attack:Simple--False Positives:None Known--False Negatives:None Known--Corrective Action:Disallow viewing of web server statistics from external sources.Remove the appropriate lines from the obj.conf file to disallow viewing of server performance statistics.--Contributors:Sourcefire Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -