[wp-trac] [WordPress Trac] #42328: directory listing, missing index.html

WordPress Trac noreply at wordpress.org
Tue Oct 24 22:18:24 UTC 2017


#42328: directory listing, missing index.html
---------------------------+------------------------------
 Reporter:  rolandinsh     |       Owner:
     Type:  defect (bug)   |      Status:  new
 Priority:  normal         |   Milestone:  Awaiting Review
Component:  Rewrite Rules  |     Version:  4.8.2
 Severity:  normal         |  Resolution:
 Keywords:                 |     Focuses:  administration
---------------------------+------------------------------
Description changed by SergeyBiryukov:

Old description:

> On hostings where missing "Options -Indexes" (Apache) index.php file with
> "Silence is golden." could be an option or as discussed in
> https://core.trac.wordpress.org/ticket/4759 as it will work also on
> NGINX.
>
> While by default it's not a security issue, however, may lead to a
> discovery of private/non-for-public files.
>
> Directories:
> /wp-includes/
> /wp-content/uploads/
> /wp-content/languages/ (I know it's not by default here)
>
> possible related: https://core.trac.wordpress.org/ticket/17619

New description:

 On hostings where missing "Options -Indexes" (Apache) index.php file with
 "Silence is golden." could be an option or as discussed in #4759 as it
 will work also on NGINX.

 While by default it's not a security issue, however, may lead to a
 discovery of private/non-for-public files.

 Directories:
 /wp-includes/
 /wp-content/uploads/
 /wp-content/languages/ (I know it's not by default here)

 possible related: #17619

--

--
Ticket URL: <https://core.trac.wordpress.org/ticket/42328#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list