store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sun May 19, 2013 8:23 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 2 posts ] 
Author Message
 Post subject: False negatives
Unread postPosted: Tue Nov 30, 2010 10:40 pm 
Offline
New Forum User
New Forum User

Joined: Tue Nov 30, 2010 10:21 pm
Posts: 1
We switched to the gotroot.com rules to address issues with our static rules. After the switch, we are having false negatives during or scans from Qualys. The specific errors are related to "Reflected Cross-Site Scripting (XSS) Vulnerabilities."

Here is one of the results output:
Quote:
http://domain.com/knowledgebase.php?action=search -- comment: DOM verification failed for this test. This result may need to be manually verified.

n.com/knowledgebase.php">Knowledgebase</a> » <a href="knowledgebase.php?action=search&search=' onEvent=X3010763568Y1Z ">Search</a></p>
</div>
</div>
</div>
,http://domain.com/knowledgebase.php?action=search -- comment: DOM verification failed for this test. This result may need to be manually verified.

in.com/knowledgebase.php">Knowledgebase</a> » <a href="knowledgebase.php?action=search&search=' onEvent=X138453672Y1Z ">Search</a></p>
</div>
</div>
</div>


Are these issues covered by our support?


Top
 Profile  
 
 Post subject: Re: False negatives
Unread postPosted: Wed Dec 01, 2010 5:38 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3243
Location: Chantilly, VA
Yes thats fully supported. The result you posted is a little short on details, any chance their scanner tells you what argument(s) in your application are vulnerable to XSS attacks?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 2 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group