2019独角兽企业重金招聘Python工程师标准>>>
I have seen several recommendation to increase web application security by disabling directory browsing (for example pg 388 in IBM WebSphere Deployment and Advanced Configuration by Barcia, Hines, et al). However, none of these references provides a pointer to the configuration descriptor to accomplish this. Can anybody help on this?
Directory browsing is disabled by setting directoryBrowsingEnabled="false" in ibm-web-ext.xmi (IBM specific extensions of web.xml).
If you are using RAD6, WSAD, or the application assembly tool, setting the extensions is not a problem. If you don't have these tools, it is best to get a copy of ibm-web-ext.xmi from another application and modify it.