Skip to content

Detection fails behind WAF (false negatives?) #1

@kazakhpunk

Description

@kazakhpunk

Hi! Quick question about the PoC: the script runs detect_vulnerability() without any of the WAF-bypass options, and only applies bypass settings for the exploit request.

If a target is behind a WAF, wouldn’t the detection request get blocked too, causing false negatives? Could we either (a) add an option to apply the same request-shaping to detection, or (b) document that detection may fail behind a WAF and recommend version-based checks instead?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions