** Digit-Labs Security Advisory (http://www.digit-labs.org/) ** Advisory Name: VS.net Web Project file reveals Website structure Release Date: 22.Aug-2002 Application: Microsoft Visual Studio .NET Platform: All supporting VS.NET Severity: Low Author(s): GoLLuM.no [mailto:gollum@digit-labs.org] Vendor Status: Unknown Description: When creating a new Web project Microsoft Visual Studio creates a file called *.vbproj in the Web root directory. This file contains the filenames of all the files in the project, thus revealing the Web site file-structure. The name of the project is the same as the name of the *.vbproj file, thus if your project is named "myproj" your Web project file is named "myproj.vbproj". Access to this Web project file would then be through http://target/myproj.vbproj, often you will see that the virtual directories and the project name is the same, ex. http://target/newproject/newproject.vbproj . Example of Web project content: ... ...