Server software and technology found by penetration test
i do a penetration test and scanning which is has server software and techonology found which is easier by the attackers to find out what do the website use to develop this website the scanning is on https://www.arcblock.io/en i found this info:
Server software and technology found
| Sort bySoftware / Versionin ascending order | Sort byCategoryin ascending order |
|---|---|
| Amazon Cloudfront | CDN |
| Emotion | JavaScript frameworks, Development |
| Google Font API | Font scripts |
| Amazon Web Services | PaaS |
| AWS Certificate Manager | SSL/TLS certificate authorities |
| core-js 3.38.0 | JavaScript libraries |
| HTTP/3 | Miscellaneous |
| MUI | UI frameworks |
| Open Graph | Miscellaneous |
| React 18.3.1 | JavaScript frameworks |
| HSTS | Security |
vulnerability: i noticed that the info of all programs that used to run the website is exposed, this make attackers easier to gaining information of what the website use to run or develop the website
Risk: the risk is the attacker can run a specific program to exploit a specific version of the programs that being used
Solution: i recommend you to eliminate the information which permits the identification of software platform, technology, server and operating system: HTTP server headers, HTML meta information, etc.
1 reply
This is information that can be shared publicly.