← 문제 라이브러리
Security Advanced SECURITY-1249 · 20 min

An admin surface seems protected by an edge allowlist but an alternate hostname still bypasses it through another proxy chain

The main route is locked down, yet the same backend remains reachable through a secondary hostname that never traverses the allowlisted edge path.

WAF / AppSecPro
시나리오

A team secures the public admin entry and later discovers that an internal or …

구독하면 이어서 볼 수 있어요

이 문제의 전체 시나리오와 점검 체크리스트, 복구 순서, 모범 풀이는 Pro 구독에서 열립니다.

구독 안내 보기