Skip to content

Test nuclei http headers #8027

Closed Answered by princechaddha
0xc4sper0 asked this question in Q&A
Discussion options

You must be logged in to vote

Hello @0xc4sper0, We advise against relying solely on the duration DSL, as it can vary due to network issues. Therefore, we recommend adding additional matchers for better detection while running on a large dataset of hosts. In the above example, it is mentioned that the TrackingId cookie is vulnerable to SQLi. To test this vulnerability, you need to inject the cookie value instead of modifying the cookie header directly. For example: TrackingId=x'||pg_sleep(10)--

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by 0xc4sper0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants