Hi,
A commissioned company has detected a cyber security lack and we were forced to unable the HTTP methods PUT and DELETE on our web server. This was their report:
Test HTTP dangerous methods
Description
Misconfigured web servers allows remote clients to perform dangerous HTTP methods such as PUT and DELETE. This script checks if they are enabled and can be misused to upload or delete files.
Output
Although we could not exploit this it seems that the PUT method is enabled (auth protected) at this web server for the following directories: ....
Although we could not exploit this it seems that the DELETE method is enabled (auth protected) at this web server for the following directories: ....
Solution
Use access restrictions to these dangerous HTTP methods or disable them completely.
After disabling the both methods, we are no more able to create new pages in Conflunece. What is the best solution in such a case?
Thanks in advance.
Best regards,
Aysenur