Ask A Question

Notifications

You’re not receiving notifications from this thread.

Overly Detailed Internal Error Messages

Chong Hwi asked in Rails

Errors which previously caused stack traces to be shown now only show the following generic error:
"The page you were looking for doesn't exist." However, the server responded with the response code "500 Internal Server Error". This is dangerous as an attacker can deduce the kind of input that causes the server to behave erratically.

I need help for the configuration to keep the generic error, but respond with response code 2XX or 3XX to close this Finding.

Reply

I need help please

Reply
Join the discussion
Create an account Log in

Want to stay up-to-date with Ruby on Rails?

Join 86,946+ developers who get early access to new tutorials, screencasts, articles, and more.

    We care about the protection of your data. Read our Privacy Policy.