Web app error messages.



Hi all,

I have recently conducted a web application penetration test for a
client and I am a little stuck as to the resolution advice I need to
give.

I have highlighted, among other things, the enumeration of 'hidden'
directories within the app. This is normally conducted by finding
Access Denied or Forbidden messages, but I have come across the
following message:
"Virtual Directory Listing Denied."

That is all that is displayed on the page! They are using asp and IIS.

What I need to know is:
what exactly is creating the error message? IIS? ASP? etc.
How to create a bespoke error message or preferably redirect the user
to the home page?

Thanks in advance.

--
Lee J Lawson
leejlawson@xxxxxxxxx
leejlawson@xxxxxxxxxxxx

"Give a man a fire, and he'll be warm for a day; set a man on fire,
and he'll be warm for the rest of his life."

"Quidquid latine dictum sit, altum sonatur."

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



Relevant Pages

  • Re: Testing the user community
    ... Cenzic Hailstorm finds vulnerabilities fast. ... Click the link to buy it, try it or download Hailstorm for FREE. ... "Give a man a fire, and he'll be warm for a day; ...
    (Pen-Test)
  • Re: Good Pentesting checklist
    ... Cenzic Hailstorm finds vulnerabilities fast. ... Click the link to buy it, try it or download Hailstorm for FREE. ... "Give a man a fire, and he'll be warm for a day; ...
    (Pen-Test)
  • Re: D3/Linux program abort
    ... The fire is out and the trucks have left the scene, ... same sort of fire could occur anywhere. ... Most developers are ... error message so that we can get through diagnostics quickly and get ...
    (comp.databases.pick)
  • Help with combo box behaviour
    ... leave the combo box, go back and delete the entry using the backspace key, ... the error message will not fire when the Save&Close button is clicked. ... obviously can't because Debtor is a required field, ...
    (microsoft.public.access.forms)
  • Re: D3/Linux program abort
    ... The fire is out and the trucks have left the scene, ... same sort of fire could occur anywhere. ... error message so that we can get through diagnostics quickly and get ... There's also the "techno error" that developers tend to display when ...
    (comp.databases.pick)