-1

My company web application had a penetration testing done and there's a risk found is regarding the hidden directory:

I don't think there's any folder of that name in the application.

So, the question is where did all those folder come from? and how to mitigate this issue?

extra info: using Apache HTTP server on web server and Apache Tomcat on application server.

Mark Henderson
  • 68,823
  • 31
  • 180
  • 259
John
  • 91
  • 2
  • 2
  • 7

1 Answers1

0

They are probably re-written addresses. Check your htaccess files and your website configuration files for rewrite rules or virtual directories.

Mark Henderson
  • 68,823
  • 31
  • 180
  • 259