Re: consensus on :query ?

Hi Roberto,

On Sun, Jul 20, 2014 at 06:33:01PM -0700, Roberto Peon wrote:
> One doesn't have to guess path + query, one only guess the query.
> In some scenarios, this enhances the attacker's ability to probe.
> The question is, does it do so enough for us to care.

I don't see why it would be a trouble since the path is generally
well known and could be considered constant. It will be retrieved
from a link on a page, a location header, or will just be "/" or
something like this.

Willy

Received on Monday, 21 July 2014 05:50:03 UTC

Follow Lee on X/Twitter - Father, Husband, Serial builder creating AI, crypto, games & web tools. We are friends :) AI Will Come To Life!

Check out: eBank.nz (Art Generator) | Netwrck.com (AI Tools) | Text-Generator.io (AI API) | BitBank.nz (Crypto AI) | ReadingTime (Kids Reading) | RewordGame | BigMultiplayerChess | WebFiddle | How.nz | Helix AI Assistant