How to avoid apache2 revealing hidden directory and/or file structure
- by matnagel
When someone fetches a denied URL that exists, he gets:
Forbidden
You don't have permission to access /admin/admin.php on this server.
Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.9 with Suhosin-Patch Server
When someone goes to a URL that does not exist he will get:
Not Found
The requested URL /notexisting/notthere.php was not found on this server.
Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.9 with Suhosin-Patch Server
This way someone can find out information about the directory structure in an area, that is actually not open to the public. Is this true?
If I were paranoid, what could I do? Just curious.