zap - zaproxy scan report solution in PHP -


i using zaproxy automatic testing of site. there p1 alert in scan report. dont know how rectify err. can please me out:-

https://example.com/index.php?id=1535&source=home&storyid=468&r=video%2fview%22%26timeout+%2ft+5%26%22&mode=current      parameter  r      attack  video/view"&timeout /t 5&" 

ok, timing attack. these prone false positives if server under load.

you should try manually validate potential vulnerability reported scanning tool, including zap.

in case open urls referenced in browser - did take around 5 seconds load? change '5' on url larger, eg '30' - did take 30 seconds?

if took around same length of time false positive.


Comments

Popular posts from this blog

javascript - jQuery: Add class depending on URL in the best way -

caching - How to check if a url path exists in the service worker cache -

Redirect to a HTTPS version using .htaccess -