RE: [Plugins-writers] Script false alarms

From: Martin O'Neal (martin.oneal@private)
Date: Wed Feb 23 2005 - 01:25:40 PST


Versions as per:

fcgi_echo.nasl script_id(10838)       v1.11
phproxy_xss.nasl script_id(16069)     v1.2
ubbthreads_xss.nasl script_id(15951)  v1.3

Additionally the following script only checks for a numeric "1" in a
response, no HTTP status checking etc, so false alarms on just about
anything; standard apache/iis errors etc.

an_httpd_count_cgi.nasl script_id(11555)  v1.4 

Martin...

 

-----Original Message-----
From: plugins-writers-bounces@private
[mailto:plugins-writers-bounces@private] On Behalf Of Renaud
Deraison
Sent: 21 February 2005 22:04
To: plugins-writers@private
Subject: Re: [Plugins-writers] Script false alarms

On Mon, Feb 21, 2005 at 09:12:08PM -0000, Martin O'Neal wrote:
> 
> The following scripts all produce false alarms on sites that repeat
the
> url back as part of a location header in a 302 redirect.
> 
> fcgi_echo.nasl script_id(10838)
> phproxy_xss.nasl script_id(16069)
> ubbthreads_xss.nasl script_id(15951)

I fixed them last week - which revisions are you talking about exactly ?


				-- Renaud
_______________________________________________
Plugins-writers mailing list
Plugins-writers@private
http://mail.nessus.org/mailman/listinfo/plugins-writers
_______________________________________________
Plugins-writers mailing list
Plugins-writers@private
http://mail.nessus.org/mailman/listinfo/plugins-writers



This archive was generated by hypermail 2.1.3 : Wed Feb 23 2005 - 01:26:40 PST