Vulnerability scanner hitting on some URL virtual directories
search cancel

Vulnerability scanner hitting on some URL virtual directories

book

Article ID: 258492

calendar_today

Updated On:

Products

Security Analytics

Issue/Introduction

Tenable vulnerability scanner is reporting a false-positive on the URLs https://server/users/login~ and https://server/users/.login.swp.  The plugin looks for any text and it shows the login page if you aren't logged in and if you are logged in it shows that it's a bad link. 

Page Not Found
The requested URL /users/login~ is not found on this server.

Environment

Release : 8.2.4-55248

Cause

This is a false positive in the vulnerability scanner.

Resolution

 The URLs are javascript redirects to the login page. These are false positives.