S4E just found a high top 10 tcp port service scan
low·Information Scans·Updated Dec 16, 2023

Apache mod_negotiation filename bruteforcing vulnerability Scanner

Apache contains a mod_negotiation filename bruteforcing vulnerability.

Est. Time~5 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

mod_negotiation is an Apache module responsible for selecting the document that best matches the clients capabilities, from one of several available documents. If the client provides an invalid Accept header, the server will respond with a 406 Not Acceptable error containing a pseudo directory listing. This behaviour can help an attacker to learn more about his target, for example, generate a list of base names, generate a list of interesting extensions, look for backup files and so on.

Solution Advice

Disable the MultiViews directive from Apache's configuration file and restart Apache.You can disable MultiViews by creating a .htaccess file containing the following line:
Options -Multiviews

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Online Apache mod_negotiation filename bruteforcing vuln. Scanner | S4E