-
Notifications
You must be signed in to change notification settings - Fork 7
Security Best Practice
Itzbenz edited this page Dec 1, 2022
·
3 revisions
- Never use this in production without isolated network
- or this happened

- Imagine attacker request
http://supersecretserver.local/nuclear.phpthis server is not exposed to internet, but thanks to your effort the attacker able to tunnel with this API - Innocent example
https://example.com/api/v3/classification/http://192.168.1.39/img/module_table_top.png
- Specify
ALLOWED_HOSTmanually - Blacklist server using
BLOCKED_HOST - Or if you want to use
ALLOW_ALL_HOSTjust firewall and isolate your app
Sponsored by: PCAS, KGB, Joe Bidden, Elongated Musk, The Mossad, Malaysian Government, AWS, Three Letter Agencies