Information Leakage from Public Information Systems
The first stage of attack is reconnaissance. Therefore don't give the enemy information they shouldn't have.
I photographed this public information screen at the weekend. It looks like it's part-way through being commissioned, but it was displaying important network information.
In this case I suspect the information isn't particularly helpful to someone who wants to display their own messages instead of the official ones, but it is leaking information about how the system works. This particular installation probably isn't part of the critical national infrastructure, but is any more case being taken there?
Web sites often give away too much information in their error messages, filenames, source code, headers and cookies. This information can be used to help compromise the site.
Posted on: 27 February 2009 at 06:38 hrs

Comments are filtered automatically and should appear shortly after they been checked.