Backup Files Disclosure
Medium Nessus Plugin ID 11411
SynopsisIt is possible to retrieve file backups from the remote web server.
DescriptionBy appending various suffixes (ie: .old, .bak, ~, etc...) to the names of various files on the remote host, it seems possible to retrieve their contents, which may result in disclosure of sensitive information.
SolutionEnsure the files do not contain any sensitive information, such as credentials to connect to a database, and delete or protect those files that should not be accessible.