false positive from passive scan for Timestamp Disclosure - Unix for uuids
See original GitHub issueDescribe the bug
We have resources that are in the form of a uuid
To Reproduce
- Create a web service that serves the raw content of https://hg.mozilla.org/mozilla-central/raw-file/tip/xpcom/base/nsISupports.idl
- Create a passive scan of that single file
- See a timestamp disclosure complaint for
00000000
Expected behavior UUIDs or things that are close enough to uuids should not be treated as timestamps.
Additional context
Here’s the relevant content from the file:
[scriptable, uuid(00000000-0000-0000-c000-000000000046)]
Would you like to help fix this issue? Yes
Issue Analytics
- State:
- Created 2 years ago
- Comments:7 (6 by maintainers)
Top Results From Across the Web
False Positives for Timestamp Disclosure · Issue #7057 - GitHub
Run an active scan on a website containing the semantic offline stylesheet (sorry don't have an example site); See false positives. Expected ...
Read more >Timestamp Disclosure - OWASP ZAP
Solution. Manually confirm that the timestamp data is not sensitive, and that the data cannot be aggregated to disclose exploitable patterns.
Read more >Disable the DAST Unix Timestamp Vulnerability Check - GitLab
The Unix Timestamp Disclosure vulnerability should be disabled by default because it often causes False Positive results.
Read more >Timestamp Disclosure - Unix - ScanRepeat
A timestamp disclosed by the application server or web server can be used to retrieve other sensitive information e.g. when used as a...
Read more >ICMP Timestamp Response and Request Vulnerability Fix
The Vulnerabilities in ICMP Timestamp Request is prone to false positive reports by most vulnerability assessment solutions. AVDS is alone in using behavior ......
Read more >
Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free
Top Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
True, that’s a value that could always be ignored.
Or we could check for all zeros as a special case - thats unlikely to be a real timestamp 😃