diff --git a/exposed-panels/magento-admin-panel.yaml b/exposed-panels/magento-admin-panel.yaml index 6c43218865..4dbb067919 100644 --- a/exposed-panels/magento-admin-panel.yaml +++ b/exposed-panels/magento-admin-panel.yaml @@ -4,7 +4,8 @@ info: name: Exposed Magento Admin Panel author: TechbrunchFR,ritikchaddha severity: info - description: As a security best practice, Magento recommends that you use a unique, custom Admin URL instead of the default admin or a common term such as backend. Although it will not directly protect your site + description: | + As a security best practice, Magento recommends that you use a unique, custom Admin URL instead of the default admin or a common term such as backend. Although it will not directly protect your site from a determined bad actor, it can reduce exposure to scripts that try to gain unauthorized access. reference: - https://docs.magento.com/user-guide/stores/store-urls-custom-admin.html @@ -18,13 +19,14 @@ requests: path: - '{{BaseURL}}/admin' + redirects: true + max-redirects: 2 matchers-condition: and matchers: - - type: status - status: - - 200 - type: word part: body words: - - "Magento Admin Page" + - "Magento" + - "Admin Panel" + condition: and