fullhunt / log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
MIT License
3.4k stars 741 forks source link

Fix #83 : Provide a 'headers-minimal.txt' file #92

Closed axel3rd closed 2 years ago

axel3rd commented 2 years ago

Fix #83

(opinionated with no many network experience) minimal headers list, avoiding requests be cancelled by security appliance, which seems ~50.

Any debate is welcome.

Removed headers from default file:

TE
X-ATT-DeviceId
X-CSRFToken
X-Foo
X-Foo-Bar
X-Forwarded-For-Original
X-Forwarded-Protocol
X-Forwarder-For
X-Forward-For
X-Forward-Proto
X-Frame-Options
X-HTTP-Method-Override
X-Http-Path-Override
X-Https
X-Htx-Agent
X-Imbo-Test-Config
X-Insight
X-Ip
X-Ip-Trail
X-Wap-Profile
mazen160 commented 2 years ago

@axel3rd Thank you very much!! It looks great :)