πŸ”„ Topic

Mapping website routes as user journeys and public exposure points.


🎯 Goal

Connect React Router pages to user behavior, business purpose, and security review.


πŸ›  What I Did

I broke the Farina website into public routes and treated each route as both a user journey and an exposed surface. The site includes pages for the homepage, products, gallery, contacts, about section, firewood information, firewood ordering, privacy policy, cookie policy, and fallback handling. This helped me see routing as more than navigation. Every public route needs a purpose, clear content, and predictable behavior.

Main areas covered:

  • homepage
  • products
  • gallery
  • contact
  • about
  • firewood
  • firewood ordering
  • privacy policy
  • cookie policy
  • 404 fallback

πŸ”— Key Cybersecurity Connections

Public routes matter because every route is something users, search engines, scanners, and attackers can request. Even static sites need sensible route handling and clean fallback behavior.


πŸ” Investigation Questions

  • Which routes exist?
  • Which routes collect input?
  • Which routes expose business details?
  • Which routes should search engines index?
  • Does the 404 page leak anything or create confusion?

🚨 Detection Opportunities

Potential monitoring ideas:

  • unusual requests to hidden paths
  • high volume of 404s
  • scanning for admin routes
  • attempted form abuse on public pages
  • unexpected route changes in deployment

Example:

project=farina-farm-website
change_type=public_website_update
risk_area=repository_deployment_or_public_input
triage=review_change_intent_and_validate_build

🧭 MITRE ATT&CK Techniques

Possible mappings depending on confirmed behavior:

  • T1190 β€” Exploit Public-Facing Application
  • T1595 β€” Active Scanning
  • T1592 β€” Gather Victim Host Information

πŸ—Ί Visual Investigation Diagram

URL request
    ↓ Router
    ↓ Page component
    ↓ Content/function
    ↓ Logs/analytics
    ↓ Security review

⚠ Challenges

The challenge was thinking like both a user and a defender. A user asks, β€˜Can I find what I need?’ A defender asks, β€˜What can be touched from the internet?’


πŸ“š What I Learned

I learned that route mapping is a simple but useful security habit. You cannot protect or test what you have not listed.


➑ Next Steps

  • Create a route inventory
  • Check route purpose and content
  • Review form-related routes more carefully

🧠 Reflection

This was useful because it turned a real project into security-aware learning without pretending that every task was a pure cybersecurity lab.


🧩 Lessons Learned

What worked

Mapping every route explicitly.

What broke

Treating pages as only design units.

Why it broke

Pages are also public entry points.

Fix / takeaway

Maintain a simple route inventory for every web project.


πŸ“ˆ Skill Progression Context

This supports SOC progression because investigations often begin with URLs, paths, HTTP status codes, and user activity.


πŸ˜„ TL;DR

Routes are user journeys and exposure points.