Releases
v0.4.0
Compare
Sorry, something went wrong.
No results found
Added: an often-forbidden tag for clients the server keeps refusing (403) (#123 )
Added: cache-busting version token on inspect-data URLs (#119 )
Added: detect www-Referer browser spoofing as spoofed_browser (#96 ) (#101 )
Changed: a browser that never caches at volume is spoofed, not automation (#130 )
Changed: all-cold-at-volume is a spoofed_browser tell (#103 ) (#129 )
Changed: a sustained 403 rate corroborates vuln_scanner (#128 )
Changed: a probing client is a vuln_scanner, even under a browser costume (#122 )
Changed: measure request cadence over navigations, not asset bursts (#121 )
Changed: asset co-load counts only referer-linked page cascades (#109 ) (#116 )
Fixed: "polls a few URLs repeatedly" counts targets, not query-stripped paths (#126 )
Fixed: lead the inspect rationale with the chosen classification (#125 )
Fixed: count query-string enumeration in the 404-storm signal (#124 )
Fixed: feed-polling spoofers no longer excused as feed readers; add polls-feeds tag (#120 )
Fixed: inspect trace nests an asset's own sub-resources (multi-level cascades) (#118 )
Fixed: require enough HTML pages before co-load scores a browser (#115 )
You can’t perform that action at this time.