lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <LfEHrbY--3-1@tutanota.com> Date: Sun, 19 May 2019 10:53:11 +0200 (CEST) From: <gionreale@...anota.com> To: Fulldisclosure <fulldisclosure@...lists.org> Subject: [FD] Epic Web Honeypot 2.0a - Fingerprinting Vulnerability The Epic Web Honeypot Project aims to lure attackers using various types of web vulnerability scanners by tricking them into believing that they have found a vulnerability on a host. Version 2.0a fails to avoid fingerprinting by including predictable data and size within index.html(the main file). Giving attackers the ability to detect and avoid this system. Discovered by Gionathan Armando Reale _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/