We are updating the screens and captures of each article as needed, but while the update is being completed,
We appreciate your understanding that there will be differences in your screen while the update is completed.
The following is an example of the adjustments that need to be made before starting the scan.
■Remove IP address restrictions
■Impact on intrusion detection and prevention systems (IPS/IDS) and web application firewalls (WAF)
If there is a device that blocks communication from the sender, the scan results may not be obtained correctly.
In this case, please set the access source IP address of AeyeScan to be out of scope.
■Lifting restrictions on banning consecutive submissions
If spam submission measures are in place, such as prohibiting the continuous submission of forms, please check the manual of the service you are using and remove any restrictions.
For example, you can find out how to lift the 'ban on consecutive submissions' on PIPED BITS' SPIRAL® at the following URL.
https://support.smp.ne.jp/manuals/web/form/
■Disable throttling function
If there is a throttling mechanism that limits the number of processes when a lot of accesses are executed, please check the manual of the service you are using and disable the restrictions.
Instructions on how to change the EC CUBE® settings can also be found on our technical blog below.
https://qiita.com/AeyeScan/private/42d85984d4a035d26371
■Impact on the server
It is also strongly recommended that AeyeScan diagnostics be performed in a development or staging environment.
■Informing all relevant parties of the mass transmission of e-mails
■Feature that does not perform a scan
- Features to purchase products from EC sites -> There is a possibility of purchasing a large amount of products.
- Features to delete user accounts and other data -> There is a possibility to delete registered accounts.
- Features for inquiries with email transmission -> There is a possibility that a large amount of email will be sent.
- Feature to register for seminars -> There is a possibility of a large number of registrations.
- Feature to write and register data on social media, internet forum, etc. -> There is a possibility of registering a large number of invalid characters.
- Feature to upload files -> There is a possibility that a large number of files will be created.
I want to remove the admin panel from the crawl/scan target.
■CAPTCHA authentication, multi-factor authentication, and reCAPTCHA are set up.