Short Name |
HTTP:INFO-LEAK:DS-STORE |
---|---|
Severity |
Minor |
Recommended |
No |
Category |
HTTP |
Keywords |
Apple Macintosh OS X .DS_Store directory Listing |
Release Date |
2005/01/07 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to access the .DS_Store file on a web server. This file contains sensitive information including system configuration, installed applications, etc.
A vulnerability has been found in certain configurations of Macintosh OS X. A remote attacker may read obtain web directory content information by submitting a URL to the vulnerable host's web service of the following form: http://www.example.com/target_directory/.DS_store. This information could provide an attacker with sensitive information including system configuration, installed applications, etc. Properly exploited, this information could allow an attacker to further compromise the security of the host.