跳到主要内容
ArcBlock Community

robot.txt found open to everyone on aigne

Harumi
开发者
blocklet-serverqualifiedrewardedsecurity

image.png

Vulnerability description: i found the robots.txt on the target server. This file instructs web crawlers what URLs and endpoints of the web application they can visit and crawl. Website administrators often misuse this file while attempting to hide some web pages from the users. Risk description: There is no particular security risk in having a robots.txt file. However, it's important to note that adding endpoints in it should not be considered a security measure, as this file can be directly accessed and read by anyone. Recommendation: i recommend you to manually review the entries from robots.txt and remove the ones which lead to sensitive locations in the website (ex. administration panels, configuration files, etc).References

Target: https://www.aigne.io/en

1 条回复

wangshijun23个月前

Thanks for the advice, will improve in next version.

回复