douqianmin5367 2016-06-27 03:42
浏览 8
已采纳

披露php文件名称的安全风险

I am developing a web application using a laptop server wamp. when I inspect my page using DevTools on chrome, i can still see the name of the php files (with their extensions). is disclosing the php files name of my application risky? if yes how can I hide them?

thanks.

  • 写回答

1条回答 默认 最新

  • duanpuchen3142 2016-06-27 04:04
    关注

    Exposing filenames do not imply any major risks, but can have more subtle risks though.

    For instance, your website cannot be hacked just by knowing filenames, but "config.php" is surely catchy once a webshell has been uploaded. You should be fine otherwise.

    If you're still paranoid, as arkascha pointed in the comments URL Rewriting can come in handy.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 关于#hadoop#的问题
  • ¥15 (标签-Python|关键词-socket)
  • ¥15 keil里为什么main.c定义的函数在it.c调用不了
  • ¥50 切换TabTip键盘的输入法
  • ¥15 可否在不同线程中调用封装数据库操作的类
  • ¥15 微带串馈天线阵列每个阵元宽度计算
  • ¥15 keil的map文件中Image component sizes各项意思
  • ¥20 求个正点原子stm32f407开发版的贪吃蛇游戏
  • ¥15 划分vlan后,链路不通了?
  • ¥20 求各位懂行的人,注册表能不能看到usb使用得具体信息,干了什么,传输了什么数据