Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
ShowSecurityErrorDetails = False but still error details are shown
#4
Hi Alexandre,

Update on the first issue about showing app path etc. My mistake. This information is only visible when testing from localhost.
I see the check on Host = <localhost> in TIWExceptionLogWorker.GetExceptionDetail().

Be notified that this 'Host' header field can be changed by an attacker. This way the information can still be visible outside 'localhost'...
Reply


Messages In This Thread
RE: ShowSecurityErrorDetails = False but still error details are shown - by jeroen.rottink - 04-07-2022, 09:45 AM

Forum Jump:


Users browsing this thread: 1 Guest(s)