Does the TCM identifier on a public website show a security issue?

Does the TCM identifier in a SiteEdit statement on a public website show a security issue? I think this should not be a problem, since Tridion is behind the firewall. I want to know the opinion of experts.

+6
source share
3 answers

I would say that this is really not a problem. If there are holes in the firewall that could be compromised, an attacker might find a way to get through independently. The fact that there is a Tridion CMS installation behind a firewall is somewhat irrelevant.

If you have a URI in the source code or not, your implementation should be provided well enough so that the knowledge gained through knowing that you have a Tridion CMS does not matter to the hacker.

+3
source

I think you are asking the wrong question. It does not matter if these SiteEdit instructions are a security risk, they should only be present in the targeted publications in which you use SiteEdit. For any other purpose, they simply unnecessarily increase the size and reveal implementation details that are not relevant to visitors to this goal.

Therefore, if you did not enable SiteEdit on your public website ( very unlikely ), SiteEdit instructions should not be in HTML.

+7
source

It depends on the level of security you require. Basically, your security should be so good that you do not rely on "security of obscurity." You had to simulate each threat, understand it and develop an impregnable defense.

In real life, this is a little harder to achieve, and the focus is on what is commonly called "security in depth." In other words, you are doing your best to have an impregnable defense, but if some simple disciplines make your attacker more difficult, you will also be sure to go with that effort. There is much evidence that the first step in any attack is to attempt to count the technology you are using. Then, if there are any known exploits for this technology, the attacker will try to use them. In addition, if an exploit becomes known, attackers will look for potential victims by searching for the signature of a compromised technology.

Identifying the TCM URIs in your public circulation is as useful as telling the attacker that you are using Tridion. So, in this respect, the SiteEdit code is exposed. If you use Tridion, it is not necessary to do any of this. You can simply display a website that does not provide any information about its implementation. (The ability to avoid providing these tips will be a tough requirement for many large organizations choosing WCMS, and the strength of Tridion in this regard may be one of the reasons why the organization you work for chose to use it.)

Thus, while there is nothing in the TCM URI that in itself causes a security problem, it unnecessarily provides information to potential attackers, so yes, it is a security problem. Financial institutions, government organizations, and large corporations generally expect you to make a clean implementation that does not help the bad guys.

+5
source

Source: https://habr.com/ru/post/922401/


All Articles