Re: consensus on :query ?

On Mon, Jul 21, 2014 at 12:14:18AM -0700, Roberto Peon wrote:
> Assuming that query params get put into the compressor, splitting the path
> off means that an attacker gets to test against all of those query-parts
> with a query and *any* path.

I'm not sure what you mean, we're speaking about having a single :query
for whatever follows the question mark, right ? If so, all the params
must be tried as a single block.

Willy

Received on Monday, 21 July 2014 07:56:51 UTC

Follow Lee on X/Twitter - Father, Husband, Serial builder creating AI, crypto, games & web tools. We are friends :) AI Will Come To Life!

Check out: eBank.nz (Art Generator) | Netwrck.com (AI Tools) | Text-Generator.io (AI API) | BitBank.nz (Crypto AI) | ReadingTime (Kids Reading) | RewordGame | BigMultiplayerChess | WebFiddle | How.nz | Helix AI Assistant