Skip to main content
ArcBlock Community

Server software and technology found by penetration test

Harumi
Developers
blocklet-serverrejectedsecurity

i do a penetration test and scanning which is has server software and techonology found which is easier by the attackers to find out what do the website use to develop this website the scanning is on https://www.arcblock.io/en i found this info:

Server software and technology found

Sort bySoftware / Versionin ascending orderSort byCategoryin ascending order
Amazon CloudfrontCDN
EmotionJavaScript frameworks, Development
Google Font APIFont scripts
Amazon Web ServicesPaaS
AWS Certificate ManagerSSL/TLS certificate authorities
core-js 3.38.0JavaScript libraries
HTTP/3Miscellaneous
MUIUI frameworks
Open GraphMiscellaneous
React 18.3.1JavaScript frameworks
HSTSSecurity

vulnerability: i noticed that the info of all programs that used to run the website is exposed, this make attackers easier to gaining information of what the website use to run or develop the website

Risk: the risk is the attacker can run a specific program to exploit a specific version of the programs that being used

Solution: i recommend you to eliminate the information which permits the identification of software platform, technology, server and operating system: HTTP server headers, HTML meta information, etc.

1 reply

wangshijun14 months ago

This is information that can be shared publicly.

Reply