trustedsec / cve-2019-19781

This is a tool published for the Citrix ADC (NetScaler) vulnerability. We are only disclosing this due to others publishing the exploit code first.
Other
570 stars 127 forks source link

Consider ASCII encoding evasion #14

Closed itsreallynick closed 4 years ago

itsreallynick commented 4 years ago

UNC1194, Consider ASCII encoding evasion (or argument to enable it) in case people's IPSs are dropping the vuln check URL without actually being patched. I would not recommend adding this same thing to your exploitation .py Thanks for all you do! Background: https://www.fireeye.com/blog/threat-research/2019/12/breaking-the-rules-tough-outlook-for-home-page-attacks.html

trustedsec commented 4 years ago

This looks good! I appreciate the submission. Awww, don't add to the exploit? No fun :) I concur though haha.