Menu

#3 "Hide From Robots" option

open
nobody
None
4
2007-09-05
2007-09-05
Kramer
No

A configuration option should exist to completely hide Indexior from web robots.

Identification of robots could be done on a UserAgent/IP range basis. We would certainly want to include robots which do not respect robots.txt with possible malicious intent, if possible.

The purpose is not to hide certain FILES or DIRECTORIES from the robot - but to entirely hide the existence of the script.

While we agree not to believe in "security through obscurity," we also must agree that obscurity can be helpful.

An example of the usefulness of this feature would be:

1) A dangerous exploit is found in Indexior.
2) A malicious person searches for installations of Indexior in a search engine in order to exploit the myriads of servers now vulnerable.
3) Those who hid their installation from robots will be hardest to find, and thus, least likely to be exploited.

Discussion


Log in to post a comment.