π Day 121 β Routing, Pages, and Public Attack Surface
π Topic
Mapping website routes as user journeys and public exposure points.
π― Goal
Connect React Router pages to user behavior, business purpose, and security review.
π What I Did
I broke the Farina website into public routes and treated each route as both a user journey and an exposed surface. The site includes pages for the homepage, products, gallery, contacts, about section, firewood information, firewood ordering, privacy policy, cookie policy, and fallback handling. This helped me see routing as more than navigation. Every public route needs a purpose, clear content, and predictable behavior.
Main areas covered:
- homepage
- products
- gallery
- contact
- about
- firewood
- firewood ordering
- privacy policy
- cookie policy
- 404 fallback
π Key Cybersecurity Connections
Public routes matter because every route is something users, search engines, scanners, and attackers can request. Even static sites need sensible route handling and clean fallback behavior.
π Investigation Questions
- Which routes exist?
- Which routes collect input?
- Which routes expose business details?
- Which routes should search engines index?
- Does the 404 page leak anything or create confusion?
π¨ Detection Opportunities
Potential monitoring ideas:
- unusual requests to hidden paths
- high volume of 404s
- scanning for admin routes
- attempted form abuse on public pages
- unexpected route changes in deployment
Example:
project=farina-farm-website
change_type=public_website_update
risk_area=repository_deployment_or_public_input
triage=review_change_intent_and_validate_build
π§ MITRE ATT&CK Techniques
Possible mappings depending on confirmed behavior:
- T1190 β Exploit Public-Facing Application
- T1595 β Active Scanning
- T1592 β Gather Victim Host Information
πΊ Visual Investigation Diagram
URL request
β Router
β Page component
β Content/function
β Logs/analytics
β Security review
β Challenges
The challenge was thinking like both a user and a defender. A user asks, βCan I find what I need?β A defender asks, βWhat can be touched from the internet?β
π What I Learned
I learned that route mapping is a simple but useful security habit. You cannot protect or test what you have not listed.
β‘ Next Steps
- Create a route inventory
- Check route purpose and content
- Review form-related routes more carefully
π§ Reflection
This was useful because it turned a real project into security-aware learning without pretending that every task was a pure cybersecurity lab.
π§© Lessons Learned
What worked
Mapping every route explicitly.
What broke
Treating pages as only design units.
Why it broke
Pages are also public entry points.
Fix / takeaway
Maintain a simple route inventory for every web project.
π Skill Progression Context
This supports SOC progression because investigations often begin with URLs, paths, HTTP status codes, and user activity.
π TL;DR
Routes are user journeys and exposure points.
