Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trust_null with wrong result #15

Closed
hayicle opened this issue Aug 12, 2020 · 1 comment
Closed

Trust_null with wrong result #15

hayicle opened this issue Aug 12, 2020 · 1 comment

Comments

@hayicle
Copy link
Contributor

hayicle commented Aug 12, 2020

Hi,

As i tested in portswigger lab - The result is wrong with trust_null.

2020-08-12 17:24:32 INFO Start checking trust_null for https://acbd1f041e7e90af80c6221d008d000c.web-security-academy.net/accountDetails

response_header={'access-control-allow-origin': 'null', 'access-control-allow-credentials': 'true', 'content-type': 'application/json; charset=utf-8', 'x-xss-protection': '0', 'content-encoding': 'gzip', 'connection': 'close', 'content-length': '98'}
=> vulnerable
2020-08-12 17:24:34 INFO nothing found for {url: https://acbd1f041e7e90af80c6221d008d000c.web-security-academy.net/accountDetails, origin: null, type: trust_null}
=> however nothing found

May you please have a look ?
Have a nice day ^^!

@chenjj
Copy link
Owner

chenjj commented Aug 12, 2020

Oh...too bad... Thank you for pointing it out, @hayicle.

@chenjj chenjj closed this as completed Aug 12, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants