Update basic-xss-prober.yaml

Hoping to cut down on false positives by ignoring reflections from JSON API endpoints
patch-1
Geeknik Labs 2020-11-02 15:04:05 +00:00 committed by GitHub
parent b239b4ff56
commit 5e911f5cd9
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 7 additions and 1 deletions

View File

@ -2,7 +2,7 @@ id: basic-xss-prober
info:
name: Basic XSS Prober
author: nadino
author: nadino & geeknik
severity: low
# Basic XSS prober
@ -12,7 +12,13 @@ requests:
- method: GET
path:
- "{{BaseURL}}/%61%27%22%3e%3c%69%6e%6a%65%63%74%61%62%6c%65%3e"
matchers-condition: and
matchers:
- type: word
words:
- "\"><injectable>"
part: body
- type: word
words:
- "text/html"
part: header