Skip to main content
ArcBlock Community

robot.txt found open to everyone on aigne

Harumi
Developers
blocklet-serverqualifiedrewardedsecurity

image.png

Vulnerability description: i found the robots.txt on the target server. This file instructs web crawlers what URLs and endpoints of the web application they can visit and crawl. Website administrators often misuse this file while attempting to hide some web pages from the users. Risk description: There is no particular security risk in having a robots.txt file. However, it's important to note that adding endpoints in it should not be considered a security measure, as this file can be directly accessed and read by anyone. Recommendation: i recommend you to manually review the entries from robots.txt and remove the ones which lead to sensitive locations in the website (ex. administration panels, configuration files, etc).References

Target: https://www.aigne.io/en

1 reply

wangshijun23 months ago

Thanks for the advice, will improve in next version.

Reply