Information Disclosure

Overview

Information disclosure will come in many different types and rank from Critical-Low. A lot of them won't lead to direct exploits but they're definitely things adversaries can put in their back pocket to use later

Example 1

Information disclosure via Calender form. Username enumeration was possible through the error
Evidence and Remediation

Example 2

More for when you're running low on findings and have time to check. Information is information

Information disclosure via web server
Evidence and Remediation

Last updated

Was this helpful?