<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable Web Server HTTP Trace/Track Method Support Cross-Site Tracing Vulnerability in Splunk AppDynamics</title>
    <link>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726043#M5039</link>
    <description>&lt;P&gt;Well, there is, but the other webservers does not have this port 9091 open. Just this one process as I listed in my original post.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Apr 2017 08:49:44 GMT</pubDate>
    <dc:creator>CommunityUser</dc:creator>
    <dc:date>2017-04-12T08:49:44Z</dc:date>
    <item>
      <title>Disable Web Server HTTP Trace/Track Method Support Cross-Site Tracing Vulnerability</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726039#M5035</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;We are gearing up to be audited for PCI. How can I achieve the above result so that we can get a clean scan on our servers?&lt;/P&gt;

&lt;P&gt;Here is more info:&lt;/P&gt;
&lt;P&gt;TCP Port 9091&lt;/P&gt;

&lt;P&gt;[root@01 ~]# netstat -putan | egrep "9091"&lt;BR /&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 :::9091&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :::*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LISTEN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2318/java&lt;/P&gt;
&lt;P&gt;[root@01 ~]# ps aux | grep 2318&lt;BR /&gt;root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 555&amp;nbsp; 0.0&amp;nbsp; 0.0 103320&amp;nbsp;&amp;nbsp; 844 pts/0&amp;nbsp;&amp;nbsp;&amp;nbsp; R+&amp;nbsp;&amp;nbsp; 14:42&amp;nbsp;&amp;nbsp; 0:00 grep 2318&lt;BR /&gt;root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2318&amp;nbsp; 0.1&amp;nbsp; 4.1 7854504 336264 ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sl&amp;nbsp;&amp;nbsp; Feb10 151:56 /opt/appdynamics/machine-agent/jre/bin/java -Dlog4j.configuration=file:/opt/appdynamics/machine-agent/conf/logging/log4j.xml -jar /opt/appdynamics/machine-agent/machineagent.jar&lt;/P&gt;

&lt;P&gt;[root@01 ~]# /opt/appdynamics/machine-agent/jre/bin/java -version&lt;BR /&gt;java version "1.8.0_74"&lt;BR /&gt;Java(TM) SE Runtime Environment (build 1.8.0_74-b02)&lt;BR /&gt;Java HotSpot(TM) 64-Bit Server VM (build 25.74-b02, mixed mode)&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Kobus&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 13:58:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726039#M5035</guid>
      <dc:creator>CommunityUser</dc:creator>
      <dc:date>2017-04-11T13:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Web Server HTTP Trace/Track Method Support Cross-Site Tracing Vulnerability</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726040#M5036</link>
      <description>&lt;P&gt;Hi Kobus,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Is this vulenaribility discovered on an AppDynamics Contoller endpoint? If so could you please share the endpoint URL?&lt;/P&gt;
&lt;P&gt;Machine Agent is not a web server, so I do not see the connection.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Saradhi&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 17:32:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726040#M5036</guid>
      <dc:creator>Saradhi_Pothara</dc:creator>
      <dc:date>2017-04-11T17:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Web Server HTTP Trace/Track Method Support Cross-Site Tracing Vulnerability</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726041#M5037</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Thank you fo rthe reply.&lt;/P&gt;

&lt;P&gt;In answer:&lt;/P&gt;
&lt;P&gt;Well it is on one, and only one of our servers. It is not on an endpoint, just a normal server with the client installed.&lt;/P&gt;

&lt;P&gt;So yes, I dont understand that either. I might just reinstall the client and see what happens.&lt;/P&gt;

&lt;P&gt;Kobus&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 08:35:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726041#M5037</guid>
      <dc:creator>CommunityUser</dc:creator>
      <dc:date>2017-04-12T08:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Web Server HTTP Trace/Track Method Support Cross-Site Tracing Vulnerability</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726042#M5038</link>
      <description>Hi Kobus,&lt;BR /&gt;&lt;BR /&gt;Machine agent runs as a standalone java program. If there is any other&lt;BR /&gt;webserver installed on the same server as machine agent you might want to&lt;BR /&gt;check that web server.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Saradhi&lt;BR /&gt;</description>
      <pubDate>Wed, 12 Apr 2017 08:41:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726042#M5038</guid>
      <dc:creator>Saradhi_Pothara</dc:creator>
      <dc:date>2017-04-12T08:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Web Server HTTP Trace/Track Method Support Cross-Site Tracing Vulnerability</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726043#M5039</link>
      <description>&lt;P&gt;Well, there is, but the other webservers does not have this port 9091 open. Just this one process as I listed in my original post.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 08:49:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726043#M5039</guid>
      <dc:creator>CommunityUser</dc:creator>
      <dc:date>2017-04-12T08:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Web Server HTTP Trace/Track Method Support Cross-Site Tracing Vulnerability</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726044#M5040</link>
      <description>&lt;P&gt;It would give a better idea how the vulnearibility scanner detects this vulnerability on 9091. It should be calling some end point otherwise I do not see an issue of XSS.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 10:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Disable-Web-Server-HTTP-Trace-Track-Method-Support-Cross-Site/m-p/726044#M5040</guid>
      <dc:creator>Saradhi_Pothara</dc:creator>
      <dc:date>2017-04-12T10:58:11Z</dc:date>
    </item>
  </channel>
</rss>

