官术网_书友最值得收藏!

  • Bug Bounty Hunting Essentials
  • Carlos A. Lozano Shahmeer Amir
  • 162字
  • 2021-06-10 18:35:30

Nonqualifying vulnerabilities

This section lists all of the vulnerabilities that are explicitly out of scope. It lists the vulnerabilities that have been reported before or are not considered as critical enough to be reported. This is usually a long list of vulnerabilities that include commonly reported issues, such as:

  • Bugs in content/services that are not owned/operated by the program
  • Vulnerabilities affecting users of unsupported browsers
  • Subdomain takeovers for out-of-scope domains
  • Self-XSS or XSS bugs requiring an unlikely amount of user interaction
  • CSRF on forms that are available to anonymous users
  • Clickjacking that is, user interface hijacking on static pages
  • Error messages
  • HTTP 404 codes/pages or other HTTP non-200 code/pages
  • Fingerprinting banner disclosure-public information disclosure
  • Disclosure of known public files or directories+
  • Scripting or other automation and brute forcing of intended functionalities
  • Presence of application or web browser "autocomplete" or "save password" functionality
  • Lack of secure and HttpOnly cookie flags
  • HTTPS mixed content
  • Missing HTTP security headers, specifically-Strict-Transport-Security, X-Frame-Options, X-XSS-Protection, X-Content-Type-Options, and Content-Security-Policy
主站蜘蛛池模板: 通化县| 自贡市| 新郑市| 肥东县| 伊川县| 勐海县| 玉林市| 双辽市| 兴隆县| 靖西县| 五河县| 腾冲县| 德阳市| 南和县| 马公市| 嵩明县| 绥宁县| 汤原县| 大英县| 东城区| 天长市| 芜湖市| 绥中县| 保靖县| 双柏县| 汶上县| 龙陵县| 遂溪县| 德化县| 故城县| 民丰县| 永昌县| 阜南县| 延长县| 临武县| 闸北区| 塘沽区| 华安县| 阳西县| 将乐县| 团风县|