> In this case, the engine is sending to the tested web server application
> a request that tricks that web server into connecting to an outside
> web site.  The severity is mitigated by the fact that the
> example.com|org|net domains are reserved by IANA, and are unlikely to
> host malicious code.  But given there is an alternative, I don't
> think this approach should be used.

Ah!  I understand.

-geoff

---------------------------------
Geoff Galitz
Blankenheim NRW, Germany
http://www.galitz.org/
http://german-way.com/blog/



_______________________________________________
Openvas-devel mailing list
Openvas-devel@wald.intevation.org
http://lists.wald.intevation.org/mailman/listinfo/openvas-devel

Reply via email to