cure53 / H5SC

HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors

Home Page:https://html5sec.org/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

/rss/ is partially broken

fuzzyroddis opened this issue · comments

https://html5sec.org/rss/ works but...

Not Found

The requested URL /rss/+ was not found on this server.
Not Found

The requested URL /rss/+1234/ was not found on this server.
Not Found

The requested URL /rss/1234/ was not found on this server.

/rss/.htaccess hasn't changed and I would have thought it was an AllowOverride problem but https://html5sec.org/r/ works. hmmm.

We have been having problems with this feature for quite some time as the behaviors differ on Apache 2.4 compared to Apache 2.2 and other web-servers.

I am actually tempted to simply remove the feature but am not sure if it is commonly used. Our logs say no but I do not know about external H5Sc instances.

I am also happy to accept a pull request for a fix. Any thoughts?

I'll have a look at this, I actually wanted to use this feature the other week; I forget what for, I think I was testing some web based rss clients.

If I had to guess I'd say the + is being interpreted as a space.

Yeah, that might make sense. I have no time to look into this right now, if you have a fix I'd happily accept the PR :)

Cheers, I plan to have a look at this and if possible make a PR this week.

Thanks, appreciated :)

Closed for lack of activity