Search:     Advanced search
server monitoring

Robots.txt Information Disclosure

Article ID: 10302
Last updated: 27 Jan, 2009
Views: 686
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Robots.txt Information Disclosure

This script is Copyright (C) 2005-2006 Tenable Network Security

FamilyCGI abuses
Plugin ID10302
Bugtraq ID
CVE ID

Description:

Synopsis :

The remote web server contains a robots.txt file.

Description :

The remote host contains a file named robots.txt that is intended to
prevent web robots from visiting certain directories in a web site for
maintenance or indexing purposes. A malicious user may also be able to
use the contents of this file to learn of sensitive documents or
directories on the affected site and either retrieve them directly or
target them for other attacks.

See also :

http://www.robotstxt.org/wc/exclusion.html

Solution :

Review the contents of the sites robots.txt file, use Robots META tags
instead of entries in the robots.txt file, and/or adjust the web
servers access controls to limit access to sensitive material.

Risk factor :

None
This article was:   Helpful | Not Helpful
Prev   Next
eFiction < 2.0.2 Multiple Remote Vulnerabilities (SQLi, XSS,...     PhpGroupWare unspecified remote file include vulnerability