Merge pull request #1458 from geeknik/patch-91

Update top-xss-params.yaml
patch-1
Sandeep Singh 2021-05-11 00:29:39 +05:30 committed by GitHub
commit c2aad94548
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 23 additions and 15 deletions

View File

@ -19,21 +19,21 @@ requests:
matchers:
- type: word
words:
- "\"<svg/onload=confirm('q')>"
- "\"<svg/onload=confirm('s')>"
- "\"<svg/onload=confirm('search')>"
- "\"<svg/onload=confirm('id')>"
- "\"<svg/onload=confirm('action')>"
- "\"<svg/onload=confirm('keyword')>"
- "\"<svg/onload=confirm('query')>"
- "\"<svg/onload=confirm('page')>"
- "\"<svg/onload=confirm('keywords')>"
- "\"<svg/onload=confirm('url')>"
- "\"<svg/onload=confirm('view')>"
- "\"<svg/onload=confirm('cat')>"
- "\"<svg/onload=confirm('name')>"
- "\"<svg/onload=confirm('key')>"
- "\"<svg/onload=confirm('p')>"
- "'>\"<svg/onload=confirm('q')>"
- "'>\"<svg/onload=confirm('s')>"
- "'>\"<svg/onload=confirm('search')>"
- "'>\"<svg/onload=confirm('id')>"
- "'>\"<svg/onload=confirm('action')>"
- "'>\"<svg/onload=confirm('keyword')>"
- "'>\"<svg/onload=confirm('query')>"
- "'>\"<svg/onload=confirm('page')>"
- "'>\"<svg/onload=confirm('keywords')>"
- "'>\"<svg/onload=confirm('url')>"
- "'>\"<svg/onload=confirm('view')>"
- "'>\"<svg/onload=confirm('cat')>"
- "'>\"<svg/onload=confirm('name')>"
- "'>\"<svg/onload=confirm('key')>"
- "'>\"<svg/onload=confirm('p')>"
part: body
condition: or
@ -42,6 +42,14 @@ requests:
- "text/html"
part: header
- type: word
words:
- "<title>Access Denied</title>"
- "You don't have permission to access"
part: body
condition: and
negative: true
- type: status
status:
- 200