Information Leakage
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Revealing system information helps an attacker learn about your tech stack.
- Prevalence
- Common
- Exploitability
- Easy
- Impact
- Worrying
What is information leakage?
Information leakage is an information disclosure vulnerability in which an application reveals details of its technology stack, such as server versions, verbose error messages, stack traces and internal file paths. The details do no harm alone, but attackers use them for reconnaissance, matching your software against known vulnerabilities to plan an attack.
What you'll learn
- How attackers fingerprint your tech stack from headers, cookies and URLs
- Why verbose error messages and leftover comments help an attacker
- How to strip revealing details from responses before they reach the client
Where this lesson counts
OWASP Top 10
Default accounts, verbose errors, unhardened parsers and permissive headers leave the door open.
Learn more about A02Errors and edge cases that fail open, leak internals or leave the system in an unsafe state.
Verbose error pages that leak stack traces are the textbook mishandled exceptional condition.
Learn more about A10This lesson includes
-
Information Leakage lab
Look at your site the way an attacker doing reconnaissance would. The lab walks through the clues that give your stack away: server headers, file extensions in URLs, session cookie names, fingerprinting tools, verbose error pages, leftover code comments and metadata in uploaded files.
-
How to prevent Information Leakage
The prevention guide covers eight approaches:
- Disable the "Server" HTTP Header and Similar Headers
- Use Clean URLs
- Ensure Cookie Parameters are Generic
- Disable Client-Side Error Reporting
- Sanitize Data Passed to the Client
- Obfuscate JavaScript
- Sanitize Template Files
- Ensure Correct Configuration of Your Web Root Directory
-
Information Leakage quiz
Three questions. Passing marks the lesson complete.
Sources
Related lessons
Browse all 45 lessons
User Enumeration
Leaking username information on your site makes things much easier for hackers.
Lax Security Settings
Improper security settings are a common cause of vulnerabilities.
Insecure Design
Security begins before you start writing code.
Logging and Monitoring
Comprehensive logging and monitoring will tell you what your site is doing at runtime, which is key to spotting security events.