4 ms·
It would have stopped the request being made to the attackers server in the first place. Smokescreen sits between your app server and the destination URL that
by plasma 5y ago
It would have stopped the request being made to the attackers server in the first place.
Smokescreen sits between your app server and the destination URL that was requested, as a proxy server, that has ACLs/rules about what URLs and domains it allows to talk to on behalf of the app server.
You define allowed or blocked domains/routes in Smokescreen, and it’s the one that decides to access the remote URL or not.
So in the above example, the app server would still have been tricked to request the attackers URL with its auth token included, but smokescreen would have realised that server/domain isn’t in its allow list, and blocked the app server attempt to access the attackers sever with the auth token by refusing to even attempt to connect to the attackers server in the first place (and returns a HTTP error back to the app server).