Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FALSE-NEGATIVE] Polyfill issue has been fixed by Namecheap #11651

Open
tess-ss opened this issue Feb 22, 2025 · 2 comments
Open

[FALSE-NEGATIVE] Polyfill issue has been fixed by Namecheap #11651

tess-ss opened this issue Feb 22, 2025 · 2 comments
Assignees
Labels
false-negative Nuclei template missing valid results

Comments

@tess-ss
Copy link
Contributor

tess-ss commented Feb 22, 2025

Template IDs or paths

https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/backdoor/polyfill-backdoor.yaml

Environment

- OS: 
- Nuclei: 
- Go:

Steps To Reproduce

Hi team,

The following template here which is https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/backdoor/polyfill-backdoor.yaml is I believe fixed by https://news.ycombinator.com/item?id=40805827 where namecheap has removed the domain, Please let me know if you still think the issue is valid.

Best Regards,
tess

Relevant dumped responses

Anything else?

No response

@tess-ss tess-ss added the false-negative Nuclei template missing valid results label Feb 22, 2025
@ehsandeep
Copy link
Member

@tess-ss, thanks for creating the issue. The exploit no longer appears to be effective, but the reference to the backdoored domain should still be removed. We can adjust the severity accordingly. Let me know if I missed anything. cc @ritikchaddha

@tess-ss
Copy link
Contributor Author

tess-ss commented Feb 22, 2025

Hi @ehsandeep ,

Appreciate the prompt response, Yes I agree the severity should be reduced, you do highlight a valid point that the following domains should be removed.

Thanks,
@tess-ss

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
false-negative Nuclei template missing valid results
Projects
None yet
Development

No branches or pull requests

3 participants