What it checks
Exposed doors
Admin, setup and debugging pages that anyone on the internet can open.
How it is checked
Sentinel asks for a fixed list of addresses where these pages usually live and looks at what comes back. It never fills in or submits a form.
- Admin, setup and debug pages. A fixed list of addresses where installers, database tools, status pages and login pages usually live.
What it can find
A setup page is open to anyone
Fix soonA real weakness that an attacker would look for.
- What it is
- An installer or setup page for the site's software can be opened by anyone and appears ready to run.
- Why it matters
- Whoever runs it can set the site up again as their own, with themselves as administrator.
- How to fix it
- Finish the installation, or delete the installer file from the server.
A diagnostics page shows your server's full configuration
Fix soonA real weakness that an attacker would look for.
- What it is
- A page that prints every detail of the server's setup is public: software versions, file paths, and sometimes passwords held in settings.
- Why it matters
- It is a map of the server for anyone planning an attack.
- How to fix it
- Delete the file from the server.
Your database's control panel is open to the internet
Should fixMakes an attack easier or more damaging.
- What it is
- The sign-in page of a database administration tool can be reached by anyone.
- Why it matters
- It invites password guessing against the place all your data lives, and these tools have a history of security holes of their own.
- How to fix it
- Remove the tool if it is not needed. Otherwise limit who can reach it, by network address or an extra password in front.
A live status page for your server is public
Should fixMakes an attack easier or more damaging.
- What it is
- A page showing what the server is doing right now, including the addresses visitors are requesting, can be opened by anyone.
- Why it matters
- It reveals visitors' activity and addresses on your site that were meant to be private.
- How to fix it
- Limit the status page to the server itself in the web server settings, or turn it off.
A developer's debugging tool is switched on for everyone
Fix soonA real weakness that an attacker would look for.
- What it is
- A debugging screen meant for development is reachable on the live site.
- Why it matters
- These tools show the inner workings of the site: database queries, settings, and often passwords and customers' data from recent requests.
- How to fix it
- Switch the site out of debug mode and remove development tools from the live server.
Your admin sign-in page is open to the internet
Worth tidyingGood practice that is missing.
- What it is
- The page where administrators sign in can be reached by anyone. This is how most sites are set up, and it is not a hole by itself.
- Why it matters
- It is the first place automated password guessing is aimed.
- How to fix it
- Use long unique passwords, turn on two-step sign-in for every administrator, and limit sign-in attempts.WordPress: a security plugin can limit sign-in attempts and add two-step sign-in.