LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 03-23-2012, 09:16 PM   #1
spezticle
Member
 
Registered: May 2010
Distribution: Ubuntu 10.04
Posts: 30

Rep: Reputation: 0
error handling


so i'm not entirely sure how difficult this would be but i'm pretty sure it's possible.

Can I tell apache to report all '403 forbidden' errors as 404 not found?

I know i can do a custom errorpage but for somebody who is looking for errors or sniffing for certain directories they can easily figure out that it's actually a 403
 
Old 03-24-2012, 08:34 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
What's wrong with sending a "Forbidden" to the client? What do you think it reveals that you should deviate from the standard?
 
Old 03-24-2012, 11:28 PM   #3
spezticle
Member
 
Registered: May 2010
Distribution: Ubuntu 10.04
Posts: 30

Original Poster
Rep: Reputation: 0
good question.

Here's my thought process:
If somebody tries going to /phpmyadmin and it says "forbidden" they know it's there
but if they get an authentic 404 even though it is there and is forbidden, it could deter them from trying harder to access it through other exploits.

I got this idea from a phpbb3 mod that does a sort of the same thing but only relative to its own system.
http://www.phpbb.com/customise/db/mod/anti_snooping/
 
Old 03-25-2012, 05:32 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Hmm. The majority of scanning for low-hanging fruit is not an economical process nor does it need to be. It is done automatically and without logic so you should not assume the scanning software is smart enough to back off given a handful of 404s. Exploiting low-hanging fruit in the web stack means just throw a few, say WordPress plugin, exploits at it and see if one sticks. If none do then just move on to the next. So IMHO it's not worth the trouble.
 
1 members found this post helpful.
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how error handling is done in C crs_zxf Programming 10 01-05-2010 07:05 AM
Error Handling Techniques ( C ) Centinul Programming 6 10-12-2006 10:49 AM
libjpeg error handling luigi Programming 1 04-19-2005 04:43 AM
xinetd error handling iftiuk Linux - Networking 0 04-21-2004 02:32 PM
eval and try / error handling rajatgarg Programming 1 04-12-2004 08:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 06:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration