Safe3 / uuWAF

A industry-leading free, high-performance, AI and semantic technology web application and API security protection product - uuWAF. 一款工业级免费、高性能、高扩展,支持AI和语义引擎的Web应用和API安全防护产品-南墙。Web应用防火墙、WAF、WAAP
https://waf.uusec.com
Other
640 stars 59 forks source link

试验pikachu靶场,对响应策略存在疑问 #65

Closed k4n5ha0 closed 2 months ago

k4n5ha0 commented 2 months ago

image 如上图,响应包存在以下文本 You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ']-(SELECT/**_**/0/**_**/WHERE/**_**/1028=1028/**_**/AND/**_**/6204=(SELECT/**_**' at line 1 同时,我已经将“SQL报错检测”的默认策略改为响应包长度大于2如下图 image

You have an error in your SQL syntax(?: near|;)该正则未正确判断响应包中敏感信息

再次建议将本策略改为兼容pikachu等等靶场的策略,以增加甲方采购前试用的竞争性

Safe3 commented 2 months ago

确认是返回chunk编码页面没有处理,现已支持