15–25 min Updated

Information Leakage

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Revealing system information helps an attacker learn about your tech stack.

Prevalence
Common
Exploitability
Easy
Impact
Worrying

What is information leakage?

Information leakage is an information disclosure vulnerability in which an application reveals details of its technology stack, such as server versions, verbose error messages, stack traces and internal file paths. The details do no harm alone, but attackers use them for reconnaissance, matching your software against known vulnerabilities to plan an attack.

What you'll learn

  • How attackers fingerprint your tech stack from headers, cookies and URLs
  • Why verbose error messages and leftover comments help an attacker
  • How to strip revealing details from responses before they reach the client

Where this lesson counts

OWASP Top 10

  • Information Leakage lab

    Look at your site the way an attacker doing reconnaissance would. The lab walks through the clues that give your stack away: server headers, file extensions in URLs, session cookie names, fingerprinting tools, verbose error pages, leftover code comments and metadata in uploaded files.

  • How to prevent Information Leakage

    The prevention guide covers eight approaches:

    • Disable the "Server" HTTP Header and Similar Headers
    • Use Clean URLs
    • Ensure Cookie Parameters are Generic
    • Disable Client-Side Error Reporting
    • Sanitize Data Passed to the Client
    • Obfuscate JavaScript
    • Sanitize Template Files
    • Ensure Correct Configuration of Your Web Root Directory
  • Information Leakage quiz

    Three questions. Passing marks the lesson complete.

Sources

  • User Enumeration

    Leaking username information on your site makes things much easier for hackers.

  • Lax Security Settings

    Improper security settings are a common cause of vulnerabilities.

  • Insecure Design

    Security begins before you start writing code.

  • Logging and Monitoring

    Comprehensive logging and monitoring will tell you what your site is doing at runtime, which is key to spotting security events.