Tuesday 21 May 2013

Disable Directory Listing in "APACHE" & "IIS" web server

Ex:  www.way2hacker.blogspot.in

like traversing directories trying www.way2hacker.blogspot.in/robots.txt 
there might be some probablity that an attacker tries to look for hidden directories and there is possibility of finding possible web configuration files.

TO DISABLE THIS :

In APACHE :

go to file called httpd.conf 
and search for :

Options Indexes FollowSymLinks

Now add "-" (hyfen) before Indexes , as shown below

Options -Indexes FollowSymLinks

In IIS : 

Open IIS Manager and navigate to manage then in "Feature View" Double Click "Directory browsing".
In "Actons" pane click Disable - if Directory browsing is enabled. 


If you like this Post , Subscribe to my blog below ... 



No comments:

Post a Comment