Esta conversación ha sido bloqueada debido a la inactividad. Cree una nueva publicación.
Nivel 1
Nivel 2
Iniciar sesión en la comunidad
Iniciar sesión para ver todas las insignias
Esta conversación ha sido bloqueada debido a la inactividad. Cree una nueva publicación.
Hi All - We are using OWASP ZAP open source tool to find the vulnerability in the websites and the result doesn't show the paths supposed to be blocked from dispatcher side [0]. When we were in AMS platform - Adobe CSE used to perform the security vulnerability scan on a monthly basis and shares the paths should be blocked from dispatcher like [0] if they find anything.
Can you please suggest a tool that tells what are all the paths supposed to be blocked from dispatcher side (to improve the security of the website)
[0]
/content.json
/content.1.json
/content.infinity.json
/content.xml
/content.1.xml
/content.feed.xml
Regards,
Raja
¡Resuelto! Ir a solución.
Vistas
Respuestas
Total de me gusta
Hi @Raja-Karuppsamy ,
You can prepare the custom script like mentioned below and validate ,it none of the urls should return 200.
https://hashimkhan.in/2018/03/13/tool-for-dispatcher-security/
Vistas
Respuestas
Total de me gusta
Hi @Raja-Karuppsamy ,
You can prepare the custom script like mentioned below and validate ,it none of the urls should return 200.
https://hashimkhan.in/2018/03/13/tool-for-dispatcher-security/
Vistas
Respuestas
Total de me gusta
Thanks @Kishore_Kumar_ - we will check this.
Vistas
Respuestas
Total de me gusta
Hi @Raja-Karuppsamy,
You can refer the Adobe documentation https://experienceleague.adobe.com/docs/experience-manager-dispatcher/using/configuring/dispatcher-c... which lists the paths which should be blocked from dispatcher.
Hope it helps!
Regards,
Manpreet
Vistas
Respuestas
Total de me gusta
Thanks for your response - we have already blocked all the paths mentioned in above mentioned Adobe document, but still we have to run the security scan every quarter to identify the vulnerabilities in AEM.
Vistas
Respuestas
Total de me gusta
Vistas
me gusta
Respuestas
Vistas
me gusta
Respuestas
Vistas
me gusta
Respuestas