EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium

A penetration tester is performing a black-box assessment against a client's web application. They discover that the web server is configured to display detailed server error messages, including software versions and internal file paths, when an invalid request is made. Which of the following enumeration countermeasures would best mitigate this information leakage?

  1. AImplement a Web Application Firewall (WAF)
  2. BDisable directory listing
  3. CEnforce strong password policies
  4. DConfigure custom error pages
Show answer & explanation

Correct answer: D. Configure custom error pages

Custom error pages prevent detailed server information from being displayed to users or attackers, thereby mitigating information leakage through verbose error messages. This directly addresses the problem of revealing software versions and file paths.

Why the other options are wrong

  • A. A WAF can block malicious requests but doesn't inherently prevent the server from generating verbose error messages for legitimate but malformed requests.
  • B. Disabling directory listing prevents attackers from browsing server directories but doesn't address information leaked through explicit error messages.
  • C. Strong password policies are crucial for authentication security but are unrelated to preventing verbose error message leakage.

Verbose Error Message Countermeasures

Strategies to prevent web applications and servers from revealing sensitive system information (like software versions, stack traces, or internal paths) in error messages to unauthorized users.

  • Reduces attack surface by hiding details.
  • Prevents attackers from gaining insights into system architecture.
  • Typically involves custom error handling and generic messages.

Memory trick: Hide the details, don't just block the door.

More Reconnaissance Techniques questions