WCF Directory Listing

The attacker can deduce web folder directory and its content information in order to use further attacks such as credential stealing



Fix Cost


Trust Level


Potentially sensitive information can be disclosed to the attackers in various ways. Listing the content of the web application directories is one of the most easiest ways for attackers to deduce these possibly sensitive information.

In order to browse web app root directory during debugging WCF allow directory listing by default with a configuration below;

<modules runAllManagedModulesForAllRequests="true" />
<directoryBrowse enabled="true" />

