|
|||
Rule General Information |
---|
Release Date: | 2021-12-20 | |
Rule Name: | Scanner ZAP Detection | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | ZAP is an open source web application security scanning tool that is used to find and exploit various security issues in applications. You can perform security penetration tests on Web sites, scan for common Web application security vulnerabilities, and generate reports. This rule is used to check the scanning behavior of the ZAP tool. | |
Impact: | Attackers use scanners to scan targets, may find vulnerabilities in the target system, resulting in system information leakage, and then attack the system to obtain system permissions. | |
Affected OS: | Windows, Linux, Others | |
Reference: | ||
Solutions |
---|
1. If scanning behavior from an unknown IP address is determined, block the IP address immediately. 2. ensure that the file system permissions of Web servers and applications are set properly, and restrict access to sensitive files and directories. 3. ensure that systems and applications are updated to the latest version and fix known vulnerabilities to reduce the impact on the system. |