Multiple guest chats in VA

Harsha Pappala
Kilo Sage

Hi Everyone, 

 

we observed multiple guest chats being initiated at almost same time (varying in seconds), all by guest user in servicenow. They have all been closed (left the conversation) without selecting anything. 

 

Can you advise me on how VA can be triggered by guest user ?, who/how can access VA by API ?

Want to understand if this is an attack from outside

1 ACCEPTED SOLUTION

Hi @Harsha Pappala,

 

That is possible if you have Virtual Agent API plugin installed. Check the plugins if you have it installed and:

  1. Navigate to All > System Web Services > Scripted Web Services > Scripted REST APIs.
  2. Select the VA Bot Integration record to open it.
  3. In the Resources tab, open the BOT Integration record.
  4. In the Security tab on the same page, select the Requires authentication check box

If you found this helpful, please hit the thumbs-up button and mark as correct. That helps others find their solutions.

View solution in original post

5 REPLIES 5

Medi C
Giga Sage

Hi @Harsha Pappala,

 

Do you have MS Teams integration configured?

Can you:

  1. Navigate to All > ServiceNow for Microsoft Teams> Teams Guest User Chat Configuration.
  2. Open the record(s) you have.
  3. Disable “Enable Guest access”.

If you found this helpful, please hit the thumbs-up button and mark as correct. That helps others find their solutions.

We don't have it enabled, no records found like that. Is there a way if someone did trigger it by using the API ?

Hi @Harsha Pappala,

 

That is possible if you have Virtual Agent API plugin installed. Check the plugins if you have it installed and:

  1. Navigate to All > System Web Services > Scripted Web Services > Scripted REST APIs.
  2. Select the VA Bot Integration record to open it.
  3. In the Resources tab, open the BOT Integration record.
  4. In the Security tab on the same page, select the Requires authentication check box

If you found this helpful, please hit the thumbs-up button and mark as correct. That helps others find their solutions.

Harsha Pappala
Kilo Sage

Hi @Medi C 

 

Oddly there is a record for API definition in the scripted REST API list, Someone might have left it after previous installation. thank you 

HarshaPappala_0-1742265797739.png