Synopsis
E-mail Address Disclosure
Description
Email addresses are typically found on "Contact us" pages, however, they can also be found within scripts or code comments of the application. They are used to provide a legitimate means of contacting an organisation.
As one of the initial steps in information gathering, cyber-criminals will spider a website and using automated methods collect as many email addresses as possible, that they may then use in a social engineering attack.
Using the same automated methods, scanner was able to detect one or more email addresses that were stored within the affected page.
Solution
E-mail addresses should be presented in such a way that it is hard to process them automatically.
Plugin Details
Scan Template: api, basic, full, overview, pci, scan