Open TheTechromancer opened 3 weeks ago
Since I can't reproduce with that domain, I can only assume this was a once in a million fluke.
There's really no way to completely stop this. I have safeguards to limit it once it starts to run away, which I am sure kicked in eventually to stop that.
The options are:
1) Increase the number of confirmations required for an initial detection. 2) Shorten the "safeguard" limit, so that it kicks in sooner.
Drawbacks of # 1:
This adds overhead for ALL detections. Basically the more rare I make it, the most overhead attached to every legitimate detection.
Drawbacks of # 2:
A legitimate true positive with a lot of real shortnames is also affected by this limit. It would start to cut off real results if there was a large amount of them.
I suppose there's option 3, which is make those verbose messages debug. Most of the time if this happens (which again, should be VERY rare at this point), nobody would notice the scan taking a bit longer waiting for the safeguard to kick in.
Based on my testing I'd say it's around 1 in 1000. Dell.com has 10K subdomains and there's a high chance at least one of them will get stuck.
I'm personally in favor of #2, i.e. a very eager abort, but maybe with a FINDING
generated, so we can circle back around and investigate it manually. Maybe the abort threshold can be configurable so for a more targeted scan you can really crank it up.
@liquidsec
Full scan log