plainblack.com
Username Password
search
Bookmark and Share
View All Tickets
Security issue - Awstats.pl reveals server info on error  (#8964)
Issue

The awstats.pl script that ships with the WRE will reveal configuration information about the server which could potentially be used to obtain server information by a hacker. Here's an example of the output:

Error: Couldn't open config file "awstats.www.nodomain.com.conf" nor "awstats.conf" after searching in path "/data/wre/prereqs/wwwroot,/data/wre/etc,/etc/awstats,/usr/local/etc/awstats,/etc,/etc/opt/awstats": No such file or directory

I didn't see a way to hide this via awstats configuration options so think it should be a customization of the script included in the WRE distribution. This appears to be the default behavior of awstats as can be seen by hacking the config option for the demo site -- http://www.nltechno.com/awstats/awstats.pl?config=HACKdestailleur.fr.

 

William

Solution Summary
Comments
JT
0
3/13/2009 10:57 am
Fixed in 0.9.0 and reported it to awstats people to hopefully get them to change it permanently.
Details
Ticket Status Resolved  
Rating0.0 
Submitted Byknowmad 
Date Submitted2008-10-23 
Assigned To unassigned  
Date Assigned2010-09-02 
Assigned By 
Severity Minor (annoying, but not harmful)  
What's the bug in? WRE  
WebGUI / WRE Version 0.8.5  
URLbugs/tracker/8964
Keywords
Ticket History
3/13/2009
10:57 AM
Resolved JT
10/23/2008
10:40 PM
Ticket created knowmad
© 2010 Plain Black Corporation | All Rights Reserved