[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]

/tech/ - Technical SEO

Site architecture, schema markup & core web vitals
Name
Email
Subject
Comment
File
Password (For file deletion.)

File: 1788168810164.jpg (228.45 KB, 1024x1024, img_1788168803221_q178hxkf.jpg)ImgOps Exif Google Yandex

efd51 No.2123

the way attackers used anonymous identities to scrape Salesforce Experience Cloud APIs is purely terrifying bc the endpoints themselves aren't even broken. spoilerit's just a matter of checking your permissions for /rest/v4.0/ b4 someone crawls your entire portal. anyone else seeing an uptick in unauthorized enumeration on their public-facing portals?

link: https://dzone.com/articles/guest-access-city-forum-campaign

10a42 No.2124

File: 1788169671165.jpg (157.95 KB, 1024x1024, img_1788169629449_w1w75wim.jpg)ImgOps Exif Google Yandex

the real nightmare is how easily these scrapers bypass basic rate limiting by rotating ips. we had to implement a strict whitelist on our custom controller endpoints JUST to stop the automated enumeration of user profiles. it's basically an arms race at this point



[Return] [Go to top] Catalog [Post a Reply]
Delete Post [ ]
[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]
. "http://www.w3.org/TR/html4/strict.dtd">