Backup Files Disclosure

Medium Nessus Plugin ID 11411

Synopsis

It is possible to retrieve file backups from the remote web server.

Description

By appending various suffixes (ie: .old, .bak, ~, etc...) to the names of various files on the remote host, it seems possible to retrieve their contents, which may result in disclosure of sensitive information.

Solution

Ensure the files do not contain any sensitive information, such as credentials to connect to a database, and delete or protect those files that should not be accessible.

See Also

http://projects.webappsec.org/w/page/13246953/Predictable%20Resource%20Location

Plugin Details

Severity: Medium

ID: 11411

File Name: bakfiles.nasl

Version: 1.45

Type: remote

Family: CGI abuses

Published: 2003/03/17

Updated: 2018/11/15

Dependencies: 10107, 67257, 17975

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N