id: directory-listing info: name: Directory Listing Enabled author: theMiddle severity: low description: Directory Indexing is a web server feature that allows the contents of a directory to be displayed when no index file is present. This can be a security risk as it can expose sensitive files, old backup or unreferenced files. impact: | Sensitive files and directories may be exposed to unauthorized users. remediation: | Disable directory listing in the web server configuration. reference: - https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/04-Review_Old_Backup_and_Unreferenced_Files_for_Sensitive_Information - https://portswigger.net/kb/issues/00600100_directory-listing metadata: max-request: 2 tags: misc,generic,misconfig,fuzz,miscellaneous flow: | function target_is_in_scope(url) { if (url.startsWith(template.http_1_host) || url.startsWith("/")) { return true; } return false; } http(1); if(template.links) { var path_checked = []; var paths = []; for(i=0; iIndex of" case-insensitive: true - type: word part: header words: - "text/html" - type: status status: - 200 # digest: 4b0a00483046022100bf3abb30efea65d3777450c5714ebe448312e22da383052988a9fa179ea9c5b2022100885960a00ac1e8e5bb00b36bf9ba45cce77466505aac2e70eafbff1efad5f121:922c64590222798bb761d5b6d8e72950