WebApp Sec mailing list archives

RE: security of _notes dirs


From: michael acadia <macadia () macadia net>
Date: Mon, 12 Sep 2005 10:14:20 -0700

You should also look for any folders named _mmServerScripts. The scripts
in this folder are used by Dreamweaver to support database connections
during development and should be removed from production sites.

See http://www.macromedia.com/go/tn_19214

-Michael


-------- Original Message --------
Subject: RE: security of _notes dirs
From: "Griffiths, Ian" <Ian.Griffiths () liv-coll ac uk>
Date: Mon, September 12, 2005 10:44 am
To: "webapp" <webappsec () securityfocus com>

If its written by humans then yes of course, passwords, clues about file
structure, girlfriends phone number, whatever.

-----Original Message-----
From: Mailing List [mailto:maillist () freedomsoftware co uk] 
Sent: 12 September 2005 10:55
To: webapp
Subject: security of _notes dirs


Hi
I've been looking through a site and found a load of _notes directories
containing .mno files. I know that these are created by dreamweaver and
can contain design notes.

None of the files I've found in the directories on this server have
contained anything that could affect security but is there the potential
for them to contain interesting security info?

Robin


Current thread: