zap - zaproxy scan report solution in PHP -
i using zaproxy automatic testing of site. there p1 alert in scan report. dont know how rectify err. can please me out:-
https://example.com/index.php?id=1535&source=home&storyid=468&r=video%2fview%22%26timeout+%2ft+5%26%22&mode=current parameter r attack video/view"&timeout /t 5&"
ok, timing attack. these prone false positives if server under load.
you should try manually validate potential vulnerability reported scanning tool, including zap.
in case open urls referenced in browser - did take around 5 seconds load? change '5' on url larger, eg '30' - did take 30 seconds?
if took around same length of time false positive.
Comments
Post a Comment