| Server misconfiguration | Leftover defaults (sample content, default accounts, version banners) give out information or access nobody meant to publish. | Version strings in response headers, default install pages still reachable | A hardened baseline, re-checked after every change |
|---|
| Directory traversal | Path references in a request are resolved without confinement, so the server hands back files it was never meant to publish. | Access-log entries naming system files or parent directories, often encoded | Current server patches, a low-privilege service account, file permissions that keep system files unreadable to it |
|---|
| HTTP response splitting | Input copied into a response header carries line breaks, so the server emits headers, or a second response, someone else wrote. | Headers or cookies the application never sets; encoded CR and LF characters in parameters | Reject or encode CR and LF in header values |
|---|
| Web cache poisoning | A shared cache stores a harmful response and serves it to every later visitor, because the response varies with an input the cache key ignores. | Many users see the same wrong content at once; a purge clears it | Key the cache on every input that changes the response; drop unexpected headers |
|---|
| DNS server hijacking | The site's name resolves to a server the owner does not control, via a compromised DNS server or a weakly protected registrar account. | Traffic to the real server drops; users report a lookalike site or certificate warnings | Registrar lock, MFA on DNS accounts, DNSSEC, alerts on record changes |
|---|
| Website defacement | Visible content is replaced: an outcome reached through another weakness, usually write access to content. | Altered pages, file-integrity alerts | File integrity monitoring, clean backups, then trace the entry point |
|---|
| Web server DoS | Connections, threads or bandwidth run out and real visitors are refused; slow-rate variants hold connections open with requests that never finish. | Connection slots full at modest bandwidth, or a flood from many sources | Timeouts, per-client limits, upstream DDoS scrubbing |
|---|
| Password attacks on admin services | Repeated login guesses against exposed remote-administration or control-panel logins with weak or default passwords. | Bursts of failed logins; logins at odd hours | Lockout, MFA, admin interfaces on a management network only |
|---|
| Directory brute forcing | Automated requests for guessable paths find content that is published but unlinked, where obscurity stood in for access control. | A spike of 404s from one client across many paths | Remove what should not be served; access control on sensitive paths |
|---|