Information disclosure: the small leaks that help attackers
Not every vulnerability is a way straight in — some simply hand an attacker information that makes every other attack easier. A penetration test looks for information disclosure and other common web weaknesses.
This covers things like:
- Error messages that reveal software versions, file paths or database detail.
- Comments, backup files, or debug output left accessible.
- Metadata and responses that expose how the site is built.
- Any signal that tells an attacker where to aim next.
Individually these can look harmless, which is why they are easy to leave in place. But reconnaissance is the first stage of any real attack, and the less your site volunteers, the harder it is to target. The tester notes what your site is unintentionally revealing, and the report explains how to reduce that footprint.

0 comments
Sign in with your TDesk account to comment.