#21 · Scan Internal APIs using Escape's Proxy
In our pursuit to enhance security and provide more accessibility, we've rolled out a feature allowing users to scan their internal APIs, which is especially beneficial for those who can't whitelist IPs. By leveraging a custom proxy, this process becomes a breeze.
⚙️ What's New:¶
-
Custom Proxy Deployment: If you're unable to whitelist IPs but can deploy a service and expose its IP, you now have the flexibility of a custom proxy. While you can choose any proxy, the Escape proxy is readily available for use. Ensure to allow incoming traffic to this proxy via your firewall settings.
-
Essential Setup Information: To get started, you'll need a few details:
User: The user permitted to connect to the proxy. If you're using the Escape proxy, this would be your organization ID.Password: The password for the aforementioned user. For the Escape proxy users, this translates to your API key.IP&Port: The IP address and port to connect to your proxy.
-
Configuration Guide: For a step-by-step guide on setting up the proxy and integrating it into your scan configuration, please refer to our detailed documentation.
With this update, we continue to simplify and fortify the security scanning process for our users. The ability to scan internal APIs using a proxy not only fills a pivotal gap in security testing but also caters to a broader range of user requirements. Your insights shape our journey, and we're eager for your feedback on this new addition.