Skip to content

GitLab

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • T ticket
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 1,809
    • Issues 1,809
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 0
    • Merge requests 0
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Packages & Registries
    • Packages & Registries
    • Package Registry
    • Infrastructure Registry
  • Analytics
    • Analytics
    • CI/CD
    • Repository
    • Value stream
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • Administrator
  • ticket
  • Issues
  • #201

Closed
Open
Created Feb 10, 2022 by Administrator@rootMaintainer

attNXDOMAIN

Created by: armorcodegithubapp[bot]

Threat Class :URL Redirector Abuse Reason :AppScan found a link to an external site, and was not able to resolve it Technical Description :The web site contains a link to a non-existent domain. An attacker can exploit this scenario to launch a phishing attack by registering the non-existent domain. A naive user may browse to that link, thinking that he is within the original site, while in fact he is browsing the attacker site. This situation may lead to sensitive information leakage, because the user trusts the malicious site. Risk :It is possible to persuade a naive user to supply sensitive information such as username, password, credit card number, social security number etc.

Mitigation: It is advised to remove all links to non-existent domains. In addition, periodically check the validity of links to external sites.

https://app.armorcode.com/#/findings/64244245

Assignee
Assign to
Time tracking