Insecure service configuration - Host verification
Description
The system does not properly restrict incoming connections from unknown external hosts.
Impact
Establish connections with untrusted machines.
Recommendation
Validate that incoming connections come from trusted hosts already defined in the known_hosts file.
Threat
Authenticated attacker from the Internet.
Expected Remediation Time
⏱️ 15 minutes.
Requirements
266 - Disable insecure functionalitiesRules
Android Apk Ssl Hostname Not VerifiedJava Insecure Hostname VerifierJavascript Postmessage Wildcard OriginJson Allowed Hosts WildcardPhp Ssl Verification Disabled SetoptXml Allows All DomainsJava Unsafe Hostname VerifierGo Disabled Ignore Host KeysJava Hostname Verification DisabledGo Insecure Tls Skip VerificationPhp Ssl Verification DisabledTypescript Postmessage Wildcard OriginC Sharp Http Listener WildcardJson Ng Serve Host Check DisabledPython Hostname Verification Disabled