What it checks
Exposed files
Files that were never meant to be public but can be downloaded by anyone.
How it is checked
Sentinel asks for a fixed list of file names that are often left behind. It reports one only when what comes back is really that kind of file, and only when your site does not answer every made-up address the same way.
- Left-behind files. A fixed list of file names: version-control folders, settings files, backups, database dumps and keys.
- Folder listings. Whether folders on the site show a list of their files.
What it can find
Your site's source code can be downloaded by anyone
Fix nowSomeone could take data or control of the site today.
- What it is
- The hidden folder that a developer's version-control tool keeps is on the public site. From it, the whole history of the site's code can be rebuilt.
- Why it matters
- Source code usually contains passwords and keys, and shows an attacker exactly where the weak points are.
- How to fix it
- Block access to /.git in the web server settings, or deploy the site without that folder. Then change every password and key that appears anywhere in the code's history.
A file of passwords and keys can be read by anyone
Fix nowSomeone could take data or control of the site today.
- What it is
- A settings file that normally holds database passwords and secret keys is being served to anyone who asks for it.
- Why it matters
- Whoever reads it can sign in to your database and the services your site uses.
- How to fix it
- Move the file outside the public folder, or block it in the web server settings. Then change every password and key it contains, because it must be assumed they were copied.
A backup copy of your site's settings can be read by anyone
Fix nowSomeone could take data or control of the site today.
- What it is
- A spare copy of the site's settings file was left on the server under a name the server shows as plain text, database password included.
- Why it matters
- Whoever reads it can sign in to your database.
- How to fix it
- Delete the backup file from the server. Then change the database password and any keys in it.WordPress: this is usually an editor's leftover copy of wp-config.php. Delete it, change the database password at the host, and replace the security keys.
A copy of your database can be downloaded by anyone
Fix nowSomeone could take data or control of the site today.
- What it is
- A database export was left in the public folder of the site.
- Why it matters
- It can contain every customer record, order and password the site holds. Depending on where you are, a leak like this may have to be reported.
- How to fix it
- Delete the file from the server. Check the access logs for downloads. If customer data was in it, get advice on your duty to tell the people affected.
A backup archive of your site can be downloaded by anyone
Fix soonA real weakness that an attacker would look for.
- What it is
- A compressed backup file sits in the public folder of the site under a name that is easy to guess.
- Why it matters
- Site backups usually contain the code, the settings with their passwords, and often the database.
- How to fix it
- Delete the file from the server and store backups somewhere that is not public. Change the passwords the backup contains.
A private key can be downloaded from your site
Fix nowSomeone could take data or control of the site today.
- What it is
- A private key file is being served to anyone who asks for it.
- Why it matters
- A private key is a password for a server or a certificate. With it, someone can sign in as you or impersonate the site.
- How to fix it
- Delete the file from the server. Create a new key and remove the old one from every server and service that trusted it.
A file of user names and scrambled passwords can be read by anyone
Fix soonA real weakness that an attacker would look for.
- What it is
- The file a web server uses to check passwords for a protected area is itself publicly readable.
- Why it matters
- The passwords are scrambled, but weak ones can be recovered, and the user names are in the clear.
- How to fix it
- Move the file outside the public folder or block it in the web server settings, then change those passwords.
A hidden file lists the contents of a folder on your site
Worth tidyingGood practice that is missing.
- What it is
- A hidden file that Mac computers create was uploaded with the site. It lists the names of the files in that folder.
- Why it matters
- It can reveal files that are not linked from anywhere and were not meant to be found.
- How to fix it
- Delete the file from the server and stop uploading it with the site.
A folder on your site shows a list of everything in it
Should fixMakes an attack easier or more damaging.
- What it is
- Opening a folder's address shows a list of its files instead of a page.
- Why it matters
- Anyone can browse the folder and find files that were never linked: old backups, uploads, private documents.
- How to fix it
- Turn off directory listing in the web server settings. On Apache that is Options -Indexes; on nginx, autoindex off.