hyuk
Member
Hi,
We are currently operating Flashphoner WCS behind an Nginx reverse proxy. During a recent web security assessment, the following items were identified as information exposure:
Thank you.
We are currently operating Flashphoner WCS behind an Nginx reverse proxy. During a recent web security assessment, the following items were identified as information exposure:
- exposed wss endpoint/path
- exposed Flashphoner product name and version
- exposed internal event/path information such as OnDataEvent
- Is there any official way in Flashphoner to reduce or hide exposure of product name, version, or internal event/path information?
- Are there any recommended settings that can be applied together with Nginx for this purpose?
- In a browser-based architecture, is exposure of the wss://... endpoint/path unavoidable by design?
- If some of this information cannot be hidden structurally, is there any official document or technical explanation stating that this does not represent a critical security issue by itself?
Thank you.