Okay, I keep ‘forgetting’ how to test if dotDefender is in place and able to block requests. Long story short, a URL can be fashioned as such:
http://example.com/?id=variable’or1=1
in order to be able to trip the expected response:
Okay, I keep ‘forgetting’ how to test if dotDefender is in place and able to block requests. Long story short, a URL can be fashioned as such:
http://example.com/?id=variable’or1=1
in order to be able to trip the expected response:
You may also try and traverse a directory like such:
http://some.site/?../../../../