Available in Classic and VPC
You might run into the following problems when using Web Security Checker. Find out causes and possible solutions.
URL Collection
URL collection is not working.
It is unclear whether the URL has been collected.
Cause
The following are examples of why the URL collection might not function properly:
- Missing authentication information (HTTP header).
- The HTTP status code is not 200 when accessing the diagnostic URL.
- Hyperlinks on the webpage point to external domains different from the target domain.
Solution
- Make sure that authentication information (HTTP header) is entered correctly.
- Verify that the URL to be diagnosed is accessible on the Internet.
A specific domain is classified under "Not Scanned Domain List"
A specific domain has been classified as "Not Scanned Domain List."
Cause
Web Security Checker only diagnoses domains that match the diagnostic URL you've entered.
<example>
- Diagnostic URL: https://www.example.com?a=1&b=2
- Diagnostic domain: https://www.example.com
- doNotScanned: https://api.example.com, https://img.example.com, https://other.com
Solution
Only domains identical to the diagnostic URL you've entered are scanned. Other domains or subdomains are not targets for diagnosis and are normally classified under Not Scanned Domain List.
False positives detected
False positives have been detected. I want to exclude false positives from the report.
Cause
False positives may occur in automatized systems.
Solution
Vulnerabilities confirmed as false positives can be removed from the report. To remove false positives from the report, take the following steps:
- In NAVER Cloud Platform console, click
> Services > Security > Web Security Checker in order. - Click [Report] for the diagnostic URL.
- In the report window, click [Edit].
- Uncheck the box for items you want to exclude.
- Click [Apply].
Diagnosis Time
The diagnostic is taking too long. I’d like to know how long it takes to complete the diagnosis.
Cause / solution
The time required for diagnostic varies depending on the website structure and the number of parameters involved. Therefore, it is impossible to predict the exact diagnostic time.
If you're still having trouble finding what you need, click on the feedback icon and send us your thoughts and requests. We'll use your feedback to improve this guide.