terrylinooo / shieldon

Web Application Firewall (WAF) for PHP.
https://shieldon.io
MIT License
849 stars 98 forks source link

Demo server running with debug mode on #59

Closed un1r8okq closed 10 months ago

un1r8okq commented 1 year ago

Issue

When I visited https://shieldon.io/demo/report/operation/#context, I saw a stack trace. This leaks sensitive information about the web server such as:

This is helpful for attackers in exploiting bugs in the server.

image

Suggested fixes

  1. Set the environment variable DEBUG_MODE = OFF
  2. Set the environment to production
github-actions[bot] commented 10 months ago

This issue is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 7 days.

github-actions[bot] commented 10 months ago

This issue was closed because it has been inactive for 14 since being marked as stale.