Skip to content

Detection fails behind WAF (false negatives?) #1

Description

@kazakhpunk

Hi! Quick question about the PoC: the script runs detect_vulnerability() without any of the WAF-bypass options, and only applies bypass settings for the exploit request.

If a target is behind a WAF, wouldn’t the detection request get blocked too, causing false negatives? Could we either (a) add an option to apply the same request-shaping to detection, or (b) document that detection may fail behind a WAF and recommend version-based checks instead?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions