[200 OK]: A Port80 Software Blog

We're all 200 OK: Web, HTTP and IIS Insights
posts - 199, comments - 719, trackbacks - 95

Error Messages: How to frame issues amidst hacker reconnaissance

Yes, you should be trapping errors that occur in Web sites and applications – and report back to the parties concerned with the error condition. 

It is good for your users, whose expectations should be managed and whose patience may be slim, even if you have a great site architecture/navigation/search/etc (older research suggests a 95% site abandon rate on an HTTP error, which feels right for an e-commerce site but is probably high for a B2B site or business application; of course, keeping all users on track is never a bad thing, even if the abandon rate is half that). 

It is equally good for you to track these errors on the Web server side as well and feed this info back into your development process to continually improve user experience and increase application efficiency. 

But it ain’t good if your displayed error messages tell hackers what you are doing from a security perspective.  Don’t be too nice or too descriptive in error handling messages on the public side, or you may be exposing a larger attack surface to hackers…

This excellent article by SPI Dynamics explores the topic in detail:
http://www.securitypark.co.uk/article.asp?articleid=25746&CategoryID=1

- Port80

posted on Tuesday, September 05, 2006 11:40 AM

Feedback

# re: Error Messages: How to frame issues amidst hacker reconnaissance

Here's another good read:

Gracefully Responding to Unhandled Exceptions - Displaying User-Friendly Error Pages

http://aspnet.4guysfromrolla.com/articles/090606-1.aspx
9/11/2006 10:10 AM | Chris @ Port80

# SEX SHOP

www./GJSAGGHASGHSAAS
4/23/2008 7:35 AM | SEX SHOP

# EROTİK SHOP

FGHFGFGFGH
4/23/2008 7:36 AM | EROTİK SHOP

# EROTİK ÜRÜNLER

XZXZXZZXXZZX
4/23/2008 7:37 AM | EROTİK ÜRÜNLER

Post Comment

Title:  
Name:  
Url:  
Comment:  
Verify:
(Enter the word as it appears in the box above.)