EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium

A security auditor is examining a web server configuration and discovers that directory listing is enabled for several web directories. What is the primary security risk associated with enabling directory listing?

  1. AIt enables remote code execution on the server.
  2. BIt exposes sensitive files and directory structures to potential attackers.
  3. CIt makes the web server vulnerable to SQL injection attacks.
  4. DIt allows attackers to upload malicious files to the server.
Show answer & explanation

Correct answer: B. It exposes sensitive files and directory structures to potential attackers.

Enabling directory listing allows anyone to view the contents of a directory on the web server, including files and subdirectories. This can expose sensitive information, configuration files, backup files, or reveal the application's structure, providing valuable reconnaissance for an attacker.

Why the other options are wrong

  • A. Enabling directory listing does not directly lead to remote code execution, though information gained from it might assist in finding other vulnerabilities that do.
  • C. Directory listing is a server-side configuration issue, not directly related to SQL injection, which is a web application code vulnerability.
  • D. Directory listing only displays content; it does not inherently provide file upload capabilities.

Directory Listing

A web server configuration where browsing a directory URL without a specific file (e.g., `index.html`) displays a list of all files and subdirectories within that directory.

  • Also known as Directory Browsing or Indexing.
  • Exposes server structure and potentially sensitive files.
  • Should be disabled in production environments.

Memory trick: Listing directories is like leaving the 'secret' door open.

More Web Application Hacking questions