雑廉堂の雑記帳

nikto の吐き出したるもの

Webサーバの脆弱性チェックのために nikto をインストールして実行してみたのだけれど、英語のメッセージに萎えそうになりながらも、少し訳してみました。少し自信ないんですが日本語のドキュメントも少ないので一応覚書として・・

OSVDB-12184

PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.

http://osvdb.org/12184
DESCRIPTION

PHP contains a flaw that may lead to an unauthorized information disclosure.The issue is triggered when a remote attacker makes certain HTTP requests with crafted arguments,which will disclose PHP version and another sensitive information resulting in a loss of confidentiality.

SOLUTION

No patches are necessary to correct this issue. Set the "expose_php" setting to "Off" in the php.ini file, which will disable this functionality.

http://osvdb.org/3092
DESCRIPTION

A potentially interesting file, directory or CGI was found on the web server. While there is no known vulnerability or exploit associated with this, it may contain sensitive information which can be disclosed to unauthenticated remote users, or aid in more focused attacks.

SOLUTION

If the file or directory contains sensitive information, remove the files from the web server or password protect them.

モバイルバージョンを終了