Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-107

Web Security: INTERNAL IP ADDRESS REVEALED

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: High
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Must Have
    • Sprint:
      ST Sprint 1

      Description

      An internal IP address was returned within the response HTML. While not always visible in the rendered HTML, it was visible within the HTML source.

        Attachments

          Issue Links

            Activity

            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment - - edited

            In earlier scenarios Server IPs were visible in following files. This is resolved in this ticket.

            Please check following File Paths :
            1. AddXpress Company module - Upload logo and check for IP by inspecting logo.
            2. ConfigureLandingPage - Upload Image and check for IP by inspecting Image.
            3. IncompleteEnrollmentNotifications - Upload File and check for IP by inspecting file link.

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - - edited In earlier scenarios Server IPs were visible in following files. This is resolved in this ticket. Please check following File Paths : 1. AddXpress Company module - Upload logo and check for IP by inspecting logo. 2. ConfigureLandingPage - Upload Image and check for IP by inspecting Image. 3. IncompleteEnrollmentNotifications - Upload File and check for IP by inspecting file link.
            Hide
            amitg Amit Gude (Inactive) added a comment -

            Assigning to Zeeshan

            Show
            amitg Amit Gude (Inactive) added a comment - Assigning to Zeeshan
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Not Verified as Internal IP addresses was revealed in error response to Employee Feedback file upload and sent mail.
            But when tested in Praetorian Identified vulnerable response the issue is fixed for below page.
            /BenAdmin/UserDetails/UserDetails/IncompleteEnrollmentNotification

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Not Verified as Internal IP addresses was revealed in error response to Employee Feedback file upload and sent mail. But when tested in Praetorian Identified vulnerable response the issue is fixed for below page. /BenAdmin/UserDetails/UserDetails/IncompleteEnrollmentNotification
            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment -

            Hi Zeeshan Chishty

            We were not able to reproduce this issue. So, please approve implemented issue for stage

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - Hi Zeeshan Chishty We were not able to reproduce this issue. So, please approve implemented issue for stage
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Hi Rakesh Roy We can close this ticket as we are not able to reproduce this issue.
            When tested in Praetorian Identified vulnerable response page the issue is fixed and no internal IP is revealed.

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Hi Rakesh Roy We can close this ticket as we are not able to reproduce this issue. When tested in Praetorian Identified vulnerable response page the issue is fixed and no internal IP is revealed.
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            as per above comments closing this ticket

            Show
            deepalit Deepali Tidke (Inactive) added a comment - as per above comments closing this ticket
            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment -

            Hi Deepali Tidke

            Make it ready for stage for implemented change.
            For more discussion approach me.

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - Hi Deepali Tidke Make it ready for stage for implemented change. For more discussion approach me.
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            Kindly discuss with Niteen for more details

            Show
            deepalit Deepali Tidke (Inactive) added a comment - Kindly discuss with Niteen for more details
            Hide
            kunal.kedari Kunal Kedari (Inactive) added a comment -

            Hi Niteen Surwase,

            We have verified the mentioned change on local (wt-stage), we inspected the mentioned pages and check whether internal IP is displaying anywhere. After fix internal IP address is not displaying anywhere. Along with this we have also perform sanity testing for mentioned pages as well, no issue found during sanity. We can deploy the change to Stage.

            Show
            kunal.kedari Kunal Kedari (Inactive) added a comment - Hi Niteen Surwase , We have verified the mentioned change on local (wt-stage), we inspected the mentioned pages and check whether internal IP is displaying anywhere. After fix internal IP address is not displaying anywhere. Along with this we have also perform sanity testing for mentioned pages as well, no issue found during sanity. We can deploy the change to Stage.

              People

              Assignee:
              kunal.kedari Kunal Kedari (Inactive)
              Reporter:
              samir Samir
              Developer:
              Niteen Surwase (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: