Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

broken authentication alert disappear and other problem of new version #98

Open
Jennifer0099 opened this issue Jun 29, 2019 · 5 comments

Comments

@Jennifer0099
Copy link

No description provided.

@Jennifer0099
Copy link
Author

in the past, when I test the tiredful API, it can show broken authentication error, and I guess it is because, that endpoint doesn't need to be authenticated, but Astra test this vulnerability by removing the authentication header and send the request again.
is this feature is closed now?

@Jennifer0099
Copy link
Author

and another problem is that it seems the log file is not right because compare to the log file of the API application, the request seems got a status code 404
image
image

@Jennifer0099
Copy link
Author

and when i test using an invalid URL i still can got the report like this:
image
but in the past, it will always show in progress but not completed

@Jennifer0099
Copy link
Author

and is I choose method post, every time when I refresh the page it will change to DEL

@Jennifer0099
Copy link
Author

and this kind of SQL injection vulnerability can't be test out
image
and rate limit
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant