Skip to content

Pentest site on local deployment instance #122

@samjjacko

Description

@samjjacko

It would be worth before handing the site over to the game dev club to deploy the site locally and see if there are any glaring vulnerabilities, e.g.:

  • Zap
  • Cross-site scripting vulnerabilities from inline scripts, forms, etc, e.g. href=javascript:alert('XSS')
  • Test malicious requests

Additionally, we should investigate configuring nginx, specifically CORS, to make cross-site scripting etc more difficult.

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions