Skip to content

false positive code injection points #43

@r23j5a

Description

@r23j5a

Messages from the scan in the form of

Issue detail  
The application appears to evaluate user input as code.  
It was instructed to sleep for 0ms, and a response time of 1516ms was observed.
It was then instructed to sleep for 15062ms, which resulted in a response time of 15062ms. 
This was re-confirmed six times to reduce false-positives  

 Please report any false-positives to https://github.com/albinowax/ActiveScanPlusPlus

appear often in my scans. I don't think it's even possible to sleep and measure something of a network with a ms precision (sleep for 15062ms, which resulted in a response time of 15062ms.), so the message itself could be used to filter out false positives.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions