CVE Hunting Tips #004

Joe Helle
The Mayor
Published in
4 min readFeb 25, 2023

--

Observable Response and Timing Discrepancies

Photo by Lukas Blazek on Unsplash

What the heck are we talking about here?

When a user makes a request to a web server, the server is programmed to provide an expected response. These responses are based on data sent to the server, such as headers and session tokens, and are the basic premises of how users are provided the correct data based on their…

--

--

Father | Husband | Army Veteran | Former Mayor | Chief Operating Officer | Red Team Lead | CISM | PNPT | OSCP | Retired Moonshiner | Twitter @joehelle