From b15374ea0eabc1556dafc2a55f35643760cd9ac3 Mon Sep 17 00:00:00 2001 From: Maximilian Hildebrand Date: Thu, 13 Jan 2022 12:45:58 +0100 Subject: [PATCH] disabled DOS via illegal header name, because of net/http limitations --- pkg/techniques.go | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkg/techniques.go b/pkg/techniques.go index dfa7338..e1990b3 100644 --- a/pkg/techniques.go +++ b/pkg/techniques.go @@ -808,8 +808,10 @@ func DOS() reportResult { headerDOSTemplate(&repResult, values, "User-Agent", "blacklisted security scanners ", true) // DOS via illegal header name + /* Currently disabled because of net/http throws error because of illegal character TODO: workaround values = []string{"foobar"} headerDOSTemplate(&repResult, values, "Ill\\egal", "illegal header name ", true) + */ // DOS via Max-Forwards (Webserver/Cache returns request) values = []string{"0", "1", "2"}