4 ms·
Is obfuscation a type of authorisation? If you knowingly exploited a vulnerability to access a non-standard URL then it's pretty obvious you shouldn't have been
by MaximumYComb 7y ago
Is obfuscation a type of authorisation? If you knowingly exploited a vulnerability to access a non-standard URL then it's pretty obvious you shouldn't have been there. This isn't you navigating to a websites home page, the information I've found reads the following for CVE-2008-6541:
>Access Complexity Medium (The access conditions are somewhat specialized. Some preconditions must be satistified to exploit)
- CiPHPerCoder 7y ago> Is obfuscation a type of authorisation? No. And even if you tried to argue that, the exploit was public on exploit-db for years, and therefore the expected security from the broken obfuscation is zero bits; so in this case, it would not count. More pertinent: > Authentication Not required (Authentication is not required to exploit the vulnerability.)