sytzevk

Absent Member.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2016-01-11
12:47
4993 views
WorkflowMacros adds hosts to allowed hosts list
Using the REST API, the hosts in WorkflowMacros parameter are added to the allowed hosts list for a scan (this is not in the documentation, this is only mentioned for the LoginMacro parameter). This is rather dangerous, because users might use a browser with many tabs open to create the WorkFlowMacro that automatically call all sorts of domains, besided the test domain that you wanted to target. What is the best way to solve this ?
0 Replies