EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesEasy

A newly hired cybersecurity analyst is reviewing the organization's current footprinting countermeasures. They notice that public-facing web servers are still configured with verbose error messages that reveal database connection strings, internal file paths, and application versions. What is the primary risk associated with these verbose error messages, and what countermeasure should be immediately implemented?

  1. ARisk: SQL injection; Countermeasure: Implement a Web Application Firewall (WAF).
  2. BRisk: DDoS attacks; Countermeasure: Implement rate limiting.
  3. CRisk: Information disclosure (enumeration); Countermeasure: Configure custom, generic error pages.
  4. DRisk: Cross-Site Scripting (XSS); Countermeasure: Sanitize all user input.
Show answer & explanation

Correct answer: C. Risk: Information disclosure (enumeration); Countermeasure: Configure custom, generic error pages.

Verbose error messages directly lead to information disclosure, which is a form of enumeration. Attackers can use this leaked information (like database connection strings, internal paths, and application versions) to plan further attacks. Configuring custom, generic error pages prevents this leakage.

Why the other options are wrong

  • A. While verbose errors might assist in SQL injection by showing database types, the primary and direct risk is information disclosure, and a WAF is a broader protection, not a direct fix for verbose errors.
  • B. Verbose error messages do not directly lead to DDoS attacks; rate limiting is for preventing resource exhaustion.
  • D. Verbose errors are unrelated to XSS; input sanitization prevents XSS vulnerabilities.

Verbose Error Message Countermeasures

Verbose error message countermeasures involve configuring web applications and servers to display generic, non-informative error messages to users, thereby preventing the leakage of sensitive internal details like database connection strings, file paths, and application versions.

  • Sensitive information in errors aids attackers in enumeration and exploitation.
  • Custom error pages should be implemented to hide internal details.
  • Error logging should still capture full details internally for debugging.
  • A fundamental security hygiene practice for web applications.

Memory trick: Errors are secrets; show only a blank page, not the whole story.

More Reconnaissance Techniques questions