index files and directory listing

index files and directory listing

ໂດຍ Séverin Terrier -
ຈຳນວນການຕອບກັບ: 4
ຮູບພາບຂອງ Documentation writers ຮູບພາບຂອງ Particularly helpful Moodlers ຮູບພາບຂອງ Testers ຮູບພາບຂອງ Translators
Hello,

in Moodle, some directories have useful index.php files (files/, group/, admin/, ...), some other have index.html files, just to avoid directory listing (enrol/, filter/, lib/, ...).

But there are also some other directories that have no index.* file (calendar/, question/, ...)

Wouldn't it be more logic to adopt the same thing everywhere, to avoid directory listing ?

Séverin
ການຈັດອັນດັບສະເລ່ຍ: -
ໃນການຕອບກັບຫາ Séverin Terrier

Re: index files and directory listing

ໂດຍ Nicolas Martignoni -
ຮູບພາບຂອງ Core developers ຮູບພາບຂອງ Documentation writers ຮູບພາບຂອງ Particularly helpful Moodlers ຮູບພາບຂອງ Plugin developers ຮູບພາບຂອງ Testers ຮູບພາບຂອງ Translators
Hi Séverin,
I had the same feeling: see MDLSITE-183.
ການຈັດອັນດັບສະເລ່ຍ: -
ໃນການຕອບກັບຫາ Nicolas Martignoni

Re: index files and directory listing

ໂດຍ Séverin Terrier -
ຮູບພາບຂອງ Documentation writers ຮູບພາບຂອງ Particularly helpful Moodlers ຮູບພາບຂອງ Testers ຮູບພາບຂອງ Translators
Hi Nicolas,

i know there's nothing really serious about security, and people shouldn't see these type of URLs, but just don't understand why some directories have index.html file (even void), and some other don't...
ການຈັດອັນດັບສະເລ່ຍ: -
ໃນການຕອບກັບຫາ Séverin Terrier

Re: index files and directory listing

ໂດຍ Eloy Lafuente (stronk7) -
ຮູບພາບຂອງ Core developers ຮູບພາບຂອງ Documentation writers ຮູບພາບຂອງ Moodle HQ ຮູບພາບຂອງ Peer reviewers ຮູບພາບຂອງ Plugin developers ຮູບພາບຂອງ Testers
Hi Séverin,

if I'm not wrong... only directories able to contain "plugins" are protected from listing by using those index.html files.

For example modules, blocks, filters, authentication and enrolment methods...

That will prevent public disclosure about what custom (contrib, own...) modules are being used in your site.

The rest is, simply, Moodle. And everybody can see its contents by downloading it. So it isn't protected.

Ciao ຍິ້ມ

ການຈັດອັນດັບສະເລ່ຍ: -