HTTP Verb Tampering
Insecure Coding
$pattern = "/^[A-Za-z\s]+$/";
if(preg_match($pattern, $_GET["code"])) {
$query = "Select * from ports where port_code like '%" . $_REQUEST["code"] . "%'";
...SNIP...
}Insecure Configurations
<Limit GET POST>
Require valid-user
</Limit>Attack
[METHOD] /[index.htm] HTTP/1.1
host: [www.example.com]OPTIONS /index.html HTTP/1.1
host: www.example.comAutomated HTTP Verb Tampering Testing
Reference
Last updated