5 ms·
- Private IP address disclosure (1) - Allowed HTTP methods (1) - Non HTTP-Only Cookies (2) - Insecure Cookies (4) Note: This is a 2-page website. Loo
by cloudwalking 14y ago
- Private IP address disclosure (1)
- Allowed HTTP methods (1)
- Non HTTP-Only Cookies (2)
- Insecure Cookies (4)
Note: This is a 2-page website. Looks like the cookie problems are a result of the default Heroku 404 page.
- tptacek 14y agoIt's good to have a fast check for these things, but you realize how simple that stuff is to spot, right? Insecure cookies and HTTPOnly (which: HTTPOnly is a bit of a band-aid; it's not a vulnerability not to have it) are trivial regexes on set-cookie headers; methods is something you can do with curl and a shell script. If you're spotting these kinds of things only after using a 3rd-party tool, consider whether this is the kind of stuff you want to build into your integration testing.
- borski 14y agoIn that vein, we search for a lot more than just these. We're actually working on some tools to help integrate Tinfoil into your integrating testing scheme - more to come on that in the future. :)
- tptacek 14y agoSorry! I know you do (for the benefit of the thread: I've been talking to 'borski for awhile about Tinfoil). I'm not commenting about Tinfoil so much as developers who are surprised to not be using secure cookies. :)