Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

implementation error? #1

Open
joostgrunwald opened this issue Mar 30, 2023 · 0 comments
Open

implementation error? #1

joostgrunwald opened this issue Mar 30, 2023 · 0 comments

Comments

@joostgrunwald
Copy link

Hey so I'm using this tool and trying to verify some vulnerabilities.

I noticed the following:

    if canary_in_response(responseCandidate):
        if canary_in_response(confirmationResponse):
            return True
        else:
            return False
    else:
        return True

why do you return True if the canary is not inside the responsecandidate @Th0h0

If this prints vulnerability confirmed, is it then 100% confirmed? Cause I sometimes fail to replicate these results with other tools

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant