Guest wrote:Martok wrote:
is there any way to show the directory names in the virtual ~files.lst file?
Do you want to make it easy for hackers or for those who like to steal the contents from websites with a spider?
Rejetto, just did a test:
I protected all directories and files with a user/pass. Not logged in, HFS refused to show me the content of the protected directories; the desired behaviour.
Appending ~files.lst to the URL, like 127.0.0.1/private/~files.list, results in the full list of files in that protected directory, except the hidden ones. :eek:
As you can imagine, entering 127.0.0.1/private/listedfilename.ext gave access/DL of this files.
Can this ~files.lst command limited to allowed users only? In case it isn't possible, then the filelisting feature will override security, which isn't acceptable at all! :evil:
Same behaviour was found for the ~progress command.
All vistors of the site are able to see which files are up- & downloading, protected or not. Only credible users should see which files are transferred.
"Privacy is not a crime!"
The ~upload didn't show this behaviour, but just kicked the request.
Edit:
Is it a feature, bug or vulnerability?
I don't use the list command in my template (I don't see the sense of it), but because the ~files.lst commans still is available, for
me it's a vulnerability which can be exploited.
Just my 2 cents, keep up the good work :^: /edit