Is MANIFEST a Security Risk?

lotusone

Joined: 2005-12-28
Posts: 3
Posted: Wed, 2005-12-28 17:46

Could a dedicated individual get vulnerability info from this file (e.g. filesizes pertaining to a particular version). There was no mention of deleting it in the security "how to."

 
valiant

Joined: 2003-01-04
Posts: 32509
Posted: Wed, 2005-12-28 18:19

it's not a direct security risk. but it's true that one could deduce from the MANIFEST files to what version of g2 someone is using.
which doesn't harm anyone, but you wouldn't want everyone to know what version you're using. i'll update the security article on codex.
thanks.