4 ms·
Maybe the scanner should also look at the "resource-that-should-not-exist-whose-status-code-should-not-be-200 well-known URI" https://w3c.github.io/webappsec-c
by jonas-w 3y ago
Maybe the scanner should also look at the "resource-that-should-not-exist-whose-status-code-should-not-be-200 well-known URI"
https://w3c.github.io/webappsec-change-password-url/response-code-reliability.html#the-resource-that-should-not-exist-whose-status-code-should-not-be-200-well-known-uri https://w3c.github.io/webappsec-change-password-url/response...
- tremon 3y agoWow. If I were a webserver, I'd return 204 for that URL, just for shits and giggles.
- wakamoleguy 3y agoDespite the URL using "200" and not "2xx", any status between 200-299 inclusive would flag the server as having unreliable status codes. https://w3c.github.io/webappsec-change-password-url/response-code-reliability.html#semantics https://w3c.github.io/webappsec-change-password-url/response...
- deleted 3y ago[deleted]
- superkuh 3y agoI have my webserver return the /index.html status 200 for any non-existent path in /. Since I didn't want bots to be able to detect I was doing this by this method I set nginx to return a 404 instead just for that path. location /.well-known/resource-that-should-not-exist-whose-status-code-should-not-be-200 { return 404; }