Login     Register
Select Website 

Recruitment Directory's Blog - Australia's #1 Recruitment Technology Blog!

Back to Menu Back to Menu


How secure is your Recruitment website? Part 1 - Server Directory Listings

Author: Thomas Shaw
Date: 9:08pm Thursday 28 May 2009

  Email Article Email Article   SMS Article SMS Article   Print Article Print Article

Every day, I am informed of another insecure recruitment website. How could this still be possible? The economic downturn has lead to an increase in data theft, with recruitment agencies one of the easiest targets. Information is an asset that, like other important business assets, has value.

Remember the issues with Monster? RCSA? CareerOne? NSW Government?

Websites are built with a structure - they contain files and folders. Hackers can deconstruct your website structure by reverse engineering the source code, or simply reading the robots.txt file.

Try this basic test…

In your web browser enter your URL/images/ - just the name of your images folder, nothing else afterwards except for the trailing /

If you see a “Forbidden” or 403 error message, that’s normal, but if you see a list of files and folder names, it means that your server is configured to allow for directory browsing!

Also try other folder names such as images, conn, includes, modules, system, admin, administration, secure, css, js, javascripts, clients, resumes, documents, scripts

You need to contact your website developer or server host to have your server directory listings turned OFF


Protecting your directories from being listed by your website's visitors does not, in and of itself, make your website more secure. At best, it's security by obscurity - that is, you hope that by hiding stuff from view, visitors will not be able to get access to your files.



Direct URL: http://www.recruitmentdirectory.com.au/Blog/how-secure-is-your-recruitment-website-part-1-server-directory-listings-a191.html

Tags: server directory listings monster careerone insecure job board recruitment website rcsa hacking security

Comments Hide Comments (0)

Feel free to join in on the conversation. All comments are moderated before publishing. Comments posted by subscribers don't necessarily reflect the views of Recruitment Directory.

Your Name: * Required
Your Email Address: * Required
Website URL:
Comments: * Required
 


Back to Menu Back to Menu



Random Blog Articles

SEO Glossary
Published: 5:16pm Wednesday 27 May 2009

Problems with Mobile Recruiting
Published: 11:30pm Sunday 02 August 2009

Creating a Job Search Widget
Published: 7:40pm Tuesday 22 September 2009

Social Recruiting 101
Published: 2:03pm Thursday 11 June 2009

How secure is your Recruitment website? DDoS Attacks
Published: 11:58am Tuesday 17 November 2009


Newsletter Mailing List

Stay informed of current news, upcoming events and promotional offers.

To subscribe to our mailing list, enter your email address below.

Latest Blog Comments

Andrea - 5:56pm Thursday 11 March 2010
Bluetooth Marketing for Career Expos/Job Fairs

Amelia - 9:18am Saturday 06 March 2010
10 Things We Hate About Recruitment Companies

Gareth Jenkins - 9:32pm Wednesday 03 March 2010
Mobile Device Statistics & Mobile Application behaviour. AdMob Mobile Metrics report

Brian - 8:34pm Wednesday 03 March 2010
Cut the fat. 1 job per job advert

Ann - 9:56am Tuesday 02 March 2010
Recruiters decrease the use of Niche Job Boards, Social Networking sites and Refer a Friend Incentives to source candidates?

AER Head - 10:56am Friday 26 February 2010
Job Board Statistics - January 2010

Kelly Magowan - 7:09pm Tuesday 23 February 2010
Congratulations Thomas. Top 25 Most Influential Online Recruiters!

Clayton Wehner - 1:26pm Tuesday 23 February 2010
Congratulations Thomas. Top 25 Most Influential Online Recruiters!

Michelle Rea - 10:30pm Monday 22 February 2010
Creating an iphone enabled job site

Jay Weerasekara - 6:55pm Monday 22 February 2010
Congratulations Thomas. Top 25 Most Influential Online Recruiters!

Upcoming Webinars