False positives in wordpress detection
Nuclei Version:
v3.2.9
Template file:
http/technologies/wordpress-detect.yaml
Description:
These two matchers are very generic and generating false positives, it is recommended to restrict the matchers:
- '\/wp-content/themes\/'
- '\/wp-includes\/'
Hello, the response time for this issue was longer than usual because the team was traveling for DEFCON. The team will respond to this issue shortly. Thank you for your contribution
Hi @tarunkant
Is it possible to share the false positive target, it will help us in fixing the template
Thanks
@DhiyaneshGeek, here you go: https://survey.hotstar.com/
Hi @tarunkant
i have updated the template, by removing the weak matcher #10649
Let me know if this works
Thanks
@DhiyaneshGeek, yes it is fixed, thanks!
@DhiyaneshGeek @ritikchaddha,
Now this change is not detecting WordPress at this: https://ads.hotstar.com/.
Can you please take a look at this?
Thanks,
Hey @tarunkant, Thanks for updating, we are looking into it.
Any update here?
Hi @tarunkant
i have fixed the missing detection https://github.com/projectdiscovery/nuclei-templates/pull/10915
Let me know if the changes works
Thanks
It is fixed, thanks!