Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-107

Web Security: INTERNAL IP ADDRESS REVEALED

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: High
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Must Have
    • Sprint:
      ST Sprint 1

      Description

      An internal IP address was returned within the response HTML. While not always visible in the rendered HTML, it was visible within the HTML source.

        Attachments

          Issue Links

            Activity

            samir Samir created issue -
            samir Samir made changes -
            Field Original Value New Value
            Status New Request [ 10029 ] Pending for Approval [ 10002 ]
            samir Samir made changes -
            Status Pending for Approval [ 10002 ] Approved for Development [ 10003 ]
            samir Samir made changes -
            Assignee Niteen Surwase [ niteen.surwase ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Status Approved for Development [ 10003 ] In Development [ 10007 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Status In Development [ 10007 ] Local Testing [ 10200 ]
            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment - - edited

            In earlier scenarios Server IPs were visible in following files. This is resolved in this ticket.

            Please check following File Paths :
            1. AddXpress Company module - Upload logo and check for IP by inspecting logo.
            2. ConfigureLandingPage - Upload Image and check for IP by inspecting Image.
            3. IncompleteEnrollmentNotifications - Upload File and check for IP by inspecting file link.

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - - edited In earlier scenarios Server IPs were visible in following files. This is resolved in this ticket. Please check following File Paths : 1. AddXpress Company module - Upload logo and check for IP by inspecting logo. 2. ConfigureLandingPage - Upload Image and check for IP by inspecting Image. 3. IncompleteEnrollmentNotifications - Upload File and check for IP by inspecting file link.
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Assignee Niteen Surwase [ niteen.surwase ] Amit Gude [ amitg ]
            samir Samir made changes -
            Sprint ST Sprint 1 [ 1 ]
            samir Samir made changes -
            Rank Ranked higher
            Hide
            amitg Amit Gude (Inactive) added a comment -

            Assigning to Zeeshan

            Show
            amitg Amit Gude (Inactive) added a comment - Assigning to Zeeshan
            amitg Amit Gude (Inactive) made changes -
            Assignee Amit Gude [ amitg ] Zeeshan Chishty [ zeeshan.chishty ]
            Zeeshan.Chishty Zeeshan Chishty (Inactive) made changes -
            Attachment Internal IP revealed.jpg [ 16153 ]
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Not Verified as Internal IP addresses was revealed in error response to Employee Feedback file upload and sent mail.
            But when tested in Praetorian Identified vulnerable response the issue is fixed for below page.
            /BenAdmin/UserDetails/UserDetails/IncompleteEnrollmentNotification

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Not Verified as Internal IP addresses was revealed in error response to Employee Feedback file upload and sent mail. But when tested in Praetorian Identified vulnerable response the issue is fixed for below page. /BenAdmin/UserDetails/UserDetails/IncompleteEnrollmentNotification
            Zeeshan.Chishty Zeeshan Chishty (Inactive) made changes -
            Status Local Testing [ 10200 ] Reopen in Local [ 10018 ]
            samir Samir made changes -
            Issue Importance Must Have [ 11800 ]
            Zeeshan.Chishty Zeeshan Chishty (Inactive) made changes -
            Assignee Zeeshan Chishty [ zeeshan.chishty ] Niteen Surwase [ niteen.surwase ]
            Zeeshan.Chishty Zeeshan Chishty (Inactive) made changes -
            Labels Security
            Zeeshan.Chishty Zeeshan Chishty (Inactive) made changes -
            Link This issue is blocked by ST-169 [ ST-169 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Module Parent values: BenAdmin(10100) Parent values: BenAdmin(10100)Level 1 values: Security(10112)
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Assignee Niteen Surwase [ niteen.surwase ] Zeeshan Chishty [ zeeshan.chishty ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Status Reopen in Local [ 10018 ] In Development [ 10007 ]
            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment -

            Hi Zeeshan Chishty

            We were not able to reproduce this issue. So, please approve implemented issue for stage

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - Hi Zeeshan Chishty We were not able to reproduce this issue. So, please approve implemented issue for stage
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Item State Parent values: LB QA(10201)Level 1 values: LB Deployed(11600)
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Status In Development [ 10007 ] Local Testing [ 10200 ]
            Zeeshan.Chishty Zeeshan Chishty (Inactive) made changes -
            Item State Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213)
            Zeeshan.Chishty Zeeshan Chishty (Inactive) made changes -
            Status Local Testing [ 10200 ] Pending for Stage Approval [ 10300 ]
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Hi Rakesh Roy We can close this ticket as we are not able to reproduce this issue.
            When tested in Praetorian Identified vulnerable response page the issue is fixed and no internal IP is revealed.

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Hi Rakesh Roy We can close this ticket as we are not able to reproduce this issue. When tested in Praetorian Identified vulnerable response page the issue is fixed and no internal IP is revealed.
            Zeeshan.Chishty Zeeshan Chishty (Inactive) made changes -
            Assignee Zeeshan Chishty [ zeeshan.chishty ] Rakesh Roy [ rakeshr ]
            rakeshr Rakesh Roy (Inactive) made changes -
            Assignee Rakesh Roy [ rakeshr ] Deepali Tidke [ deepalit ]
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            as per above comments closing this ticket

            Show
            deepalit Deepali Tidke (Inactive) added a comment - as per above comments closing this ticket
            deepalit Deepali Tidke (Inactive) made changes -
            Item State Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) Parent values: Production Complete(10222)Level 1 values: Closed(10223)
            deepalit Deepali Tidke (Inactive) made changes -
            Status Pending for Stage Approval [ 10300 ] Approved for Stage [ 10030 ]
            deepalit Deepali Tidke (Inactive) made changes -
            Status Approved for Stage [ 10030 ] Stage Testing [ 10201 ]
            deepalit Deepali Tidke (Inactive) made changes -
            Status Stage Testing [ 10201 ] Pending for Production Approval [ 10301 ]
            deepalit Deepali Tidke (Inactive) made changes -
            Status Pending for Production Approval [ 10301 ] Approved for production [ 10034 ]
            deepalit Deepali Tidke (Inactive) made changes -
            Status Approved for production [ 10034 ] Production Testing [ 10202 ]
            deepalit Deepali Tidke (Inactive) made changes -
            Resolution Fixed [ 1 ]
            Status Production Testing [ 10202 ] Production Complete [ 10028 ]
            deepalit Deepali Tidke (Inactive) made changes -
            Status Production Complete [ 10028 ] Closed [ 6 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Item State Parent values: Production Complete(10222)Level 1 values: Closed(10223) Parent values: LB QA(10201)
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Item State Parent values: LB QA(10201) Parent values: LB QA(10201)Level 1 values: LB Deployed(11600)
            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment -

            Hi Deepali Tidke

            Make it ready for stage for implemented change.
            For more discussion approach me.

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - Hi Deepali Tidke Make it ready for stage for implemented change. For more discussion approach me.
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Developer Niteen Surwase [ niteen.surwase ]
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            Kindly discuss with Niteen for more details

            Show
            deepalit Deepali Tidke (Inactive) added a comment - Kindly discuss with Niteen for more details
            deepalit Deepali Tidke (Inactive) made changes -
            Assignee Deepali Tidke [ deepalit ] Kunal Kedari [ kunal.kedari ]
            kunal.kedari Kunal Kedari (Inactive) made changes -
            Item State Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) Parent values: LB QA(10201)Level 1 values: In Testing(10210)
            Hide
            kunal.kedari Kunal Kedari (Inactive) added a comment -

            Hi Niteen Surwase,

            We have verified the mentioned change on local (wt-stage), we inspected the mentioned pages and check whether internal IP is displaying anywhere. After fix internal IP address is not displaying anywhere. Along with this we have also perform sanity testing for mentioned pages as well, no issue found during sanity. We can deploy the change to Stage.

            Show
            kunal.kedari Kunal Kedari (Inactive) added a comment - Hi Niteen Surwase , We have verified the mentioned change on local (wt-stage), we inspected the mentioned pages and check whether internal IP is displaying anywhere. After fix internal IP address is not displaying anywhere. Along with this we have also perform sanity testing for mentioned pages as well, no issue found during sanity. We can deploy the change to Stage.
            kunal.kedari Kunal Kedari (Inactive) made changes -
            Item State Parent values: LB QA(10201)Level 1 values: In Testing(10210) Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213)
            rakeshr Rakesh Roy (Inactive) made changes -
            Item State Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) Parent values: Production Complete(10222)Level 1 values: Closed(10223)
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Link This issue relates to DEV-13718 [ DEV-13718 ]
            Transition Time In Source Status Execution Times
            Samir made transition -
            New Request Pending for Approval
            1m 3s 1
            Samir made transition -
            Pending for Approval Approved for Development
            3s 1
            Niteen Surwase (Inactive) made transition -
            Approved for Development In Development
            11d 23h 41m 1
            Zeeshan Chishty (Inactive) made transition -
            In LB Testing Reopen in Local
            21d 1h 33m 1
            Niteen Surwase (Inactive) made transition -
            Reopen in Local In Development
            56d 1h 24m 1
            Niteen Surwase (Inactive) made transition -
            In Development In LB Testing
            10d 20h 57m 2
            Zeeshan Chishty (Inactive) made transition -
            In LB Testing Pending for Stage Approval
            2d 18h 30m 1
            Deepali Tidke (Inactive) made transition -
            Pending for Stage Approval Approved for Stage
            3d 4h 25m 1
            Deepali Tidke (Inactive) made transition -
            Approved for Stage Stage Testing
            2s 1
            Deepali Tidke (Inactive) made transition -
            Stage Testing Pending for Production Approval
            5s 1
            Deepali Tidke (Inactive) made transition -
            Pending for Production Approval Approved for production
            2s 1
            Deepali Tidke (Inactive) made transition -
            Approved for production In Production Testing
            2s 1
            Deepali Tidke (Inactive) made transition -
            In Production Testing Production Complete
            12s 1
            Deepali Tidke (Inactive) made transition -
            Production Complete Closed
            2s 1

              People

              Assignee:
              kunal.kedari Kunal Kedari (Inactive)
              Reporter:
              samir Samir
              Developer:
              Niteen Surwase (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: