Login     Register
Select Website 

Recruitment Directory's Blog - Australia's #1 Recruitment Technology Blog!

Back to Menu Back to Menu

How secure is your Recruitment website? Part 1 - Server Directory Listings

Posted By: Thomas Shaw, 9:08pm Thursday 28 May 2009    Email Article    Print Article

Every day, I am informed of another insecure recruitment website. How could this still be possible? The economic downturn has lead to an increase in data theft, with recruitment agencies one of the easiest targets. Information is an asset that, like other important business assets, has value.

Remember the issues with Monster? RCSA? CareerOne? NSW Government?

Websites are built with a structure - they contain files and folders. Hackers can deconstruct your website structure by reverse engineering the source code, or simply reading the robots.txt file.

Try this basic test…

In your web browser enter your URL/images/ - just the name of your images folder, nothing else afterwards except for the trailing /

If you see a “Forbidden” or 403 error message, that’s normal, but if you see a list of files and folder names, it means that your server is configured to allow for directory browsing!

Also try other folder names such as images, conn, includes, modules, system, admin, administration, secure, css, js, javascripts, clients, resumes, documents, scripts

You need to contact your website developer or server host to have your server directory listings turned OFF


Protecting your directories from being listed by your website's visitors does not, in and of itself, make your website more secure. At best, it's security by obscurity - that is, you hope that by hiding stuff from view, visitors will not be able to get access to your files.



Article URL: http://www.recruitmentdirectory.com.au/Blog/how-secure-is-your-recruitment-website-part-1-server-directory-listings-a191.html

Article Tags: server directory listings monster careerone insecure job board recruitment website rcsa hacking security

Comments Hide Comments (0)

Feel free to join in on the conversation. All comments are moderated before publishing. Comments posted by subscribers don't necessarily reflect the views of Recruitment Directory.

Your Name: * Required
Your Email Address: * Required
Website URL:
Comments: * Required
 


Back to Menu Back to Menu



Random Blog Articles

10 Things We Hate About Recruitment Companies
Published: 6:42pm Tuesday 07 July 2009

Creative Thinking and Problem Solving
Published: 10:22pm Sunday 09 May 2010

Job Board Updates - MyCareer jobs on CareerOne
Published: 11:00am Friday 12 December 2008

Recruitment and Social Media
Published: 7:00pm Wednesday 08 April 2009

Prepare yourself for the job searching process
Published: 11:57pm Thursday 26 March 2009


Newsletter Mailing List

Stay informed of current news, upcoming events and promotional offers.

Top 25 Most Influential

Latest Blog Comments

frustrated jobseeker - 1:27pm Tuesday 31 August 2010
Are you a Social Recruitment wanker?

Jason - 11:16am Wednesday 18 August 2010
IT Video Resume - Killa Appz

David Lyons - 5:17pm Friday 13 August 2010
Plan for the worst

DmitryK - 6:06pm Monday 09 August 2010
OWASP Top 10 and your Recruitment Website - Part 1

Jim Manico - 5:28pm Monday 09 August 2010
OWASP Top 10 and your Recruitment Website - Part 1

Steve Ludlow - 12:28pm Friday 06 August 2010
Are you a Social Recruitment wanker?

Brad Stewart - 10:45am Tuesday 03 August 2010
2010 Email Marketing Benchmark Report - HR/Recruitment Sector

Adam Crow - 5:23am Tuesday 03 August 2010
Plan for the worst

BryanB - 8:23am Friday 23 July 2010
Job ad of the month - I'm tired of writing boring adverts for boring Recruitment Consultants

robyn - 11:11pm Thursday 22 July 2010
Social Recruiting is a dirty word

Upcoming Webinars