Nmap Development mailing list archives

Re: http-methods & http-trace NSE Script Enhancement Ideas


From: David Fifield <david () bamsoftware com>
Date: Thu, 24 May 2012 13:45:30 -0700

On Wed, May 23, 2012 at 08:17:03AM -0400, King Thorin wrote:

I was just looking through some online docs and some nmap results. I've 
never seen a server that includes public or allow header(s) on a 
redirect response [maybe my experience is limited?]. It seems to me that the http-methods NSE should follow 
redirects (HTTP 301, 302, 303) in order to perform the necessary OPTIONS
 request on a page/resource that's providing a HTTP 200.

Ideally the redirect handling would work the same as the built-in
handling of the http.get and http.head methods. See this earlier
discussion:

http://seclists.org/nmap-dev/2012/q1/338

David Fifield
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: