Added the URI encoded injection code feature#28
Open
DeweshSingh wants to merge 2 commits into13o-bbr-bbq:masterfrom
Open
Added the URI encoded injection code feature#28DeweshSingh wants to merge 2 commits into13o-bbr-bbq:masterfrom
DeweshSingh wants to merge 2 commits into13o-bbr-bbq:masterfrom
Conversation
Owner
|
Great thanks!! |
Author
|
Looks like the problem was with the indentation. I generally use tabs instead of spaces. I have fixed it now. Kindly have a look at it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I have modified the ga_main.py and the gan_main.py files.
Now these files not only test the normal injection code during evaluation but also the encoded version of these injection codes for detecting if the script is running. The csv files generated after running the ga_main.py and gan_main.py now contain the injection code along with their encoded version as well.
The most common XSS attack prevention technique is the regex string matching. This encoded injection code has a better chance of causing an XSS attack by not getting detected by normal string matching techniques. Thus this feature has an advantage over the normal injection codes.