irsdl / IIS-ShortName-Scanner

latest version of scanners for IIS short filename (8.3) disclosure vulnerability
1.41k stars 250 forks source link

Cookie mistake > I don't use "&" character in cookie #22

Closed Comancheroo closed 1 year ago

Comancheroo commented 6 years ago

Hello,

I don't use "&" character in cookie(config.xml;entry key=cookies).

Note 1: Edit config.xml file to change the scanner settings, for instance to add additional headers. Note 2: Sometimes it does not work for the first time and you need to try again.

irsdl commented 1 year ago

if you have XML special characters, you need to use HTML encoding or CDATA