Full Disclosure mailing list archives

Epic Web Honeypot 2.0a - Fingerprinting Vulnerability


From: <gionreale () tutanota com>
Date: Sun, 19 May 2019 10:53:11 +0200 (CEST)


The Epic Web Honeypot Project aims to lure attackers using various types of web vulnerability scanners by tricking them 
into believing that they have found a vulnerability on a host.

Version 2.0a fails to avoid fingerprinting by including predictable data and size within index.html(the main file). 
Giving attackers the ability to detect and avoid this system.


Discovered by Gionathan Armando Reale

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/


Current thread: