SolomonSklash / chomp-scan

A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.
https://www.solomonsklash.io/chomp-scan-update.html
GNU General Public License v3.0
393 stars 76 forks source link

reconsidering redirect #64

Open Sy3Omda opened 5 years ago

Sy3Omda commented 5 years ago

after reading a few writeup recently i start to reconsidering to not exclude redirect status code 30* from content discovery results from all tools because you could be missing gold there. for example this report GOOGLE BUG BOUNTY: LFI ON PRODUCTION SERVERS