Information Leakage
Information Leakage in software testing refers to the unintended or unauthorized exposure of sensitive, confidential, or internal information through an application or system. This type of vulnerability occurs when the software inadvertently reveals details that could be exploited by malicious actors to compromise security, gain unauthorized access, or undermine user privacy.
Types of Leaked Information:
Information leakage can involve various types of data, including:
- System Information: Server names, IP addresses, database schemas, or software versions.
- Debugging Details: Stack traces, error codes, or unhandled exceptions revealing internal logic.
- User Data: Credentials, session tokens, or Personally Identifiable Information (PII).
- Configuration Details: API keys, environment variables, or encryption keys.
- Metadata: Hidden data in headers, cookies, or URLs that may expose operational insights.
Common Sources of Leakage:
Information leakage often stems from:
- Error Messages: Detailed error responses exposing system internals.
- Unsecured Logs: Log files containing sensitive data accessible to unauthorized users.
- API Responses: APIs returning excessive or unnecessary data in their responses.
- Debugging Features: Enabled debug modes revealing internal states or configurations.
- Insecure Direct Object References (IDOR): Direct exposure of internal identifiers, such as file paths or database keys.





