Minor bug fix - some applications do really set cookies like param="value" with double-quotes

This commit is contained in:
Bernardo Damele 2011-08-16 09:21:01 +00:00
parent e1dbb4443b
commit 9361e633f4

View File

@ -366,7 +366,7 @@ REFLECTIVE_MISS_THRESHOLD = 20
HTML_TITLE_REGEX = "<title>(?P<result>[^<]+)</title>"
# Chars used to quickly distinguish if the user provided tainted parameter values
DUMMY_SQL_INJECTION_CHARS = ";()\"'"
DUMMY_SQL_INJECTION_CHARS = ";()'"
# Extensions skipped by crawler
CRAWL_EXCLUDE_EXTENSIONS = ("gif","jpg","jar","tif","bmp","war","ear","mpg","wmv","mpeg","scm","iso","dmp","dll","cab","so","avi","bin","exe","iso","tar","png","pdf","ps","mp3","zip","rar","gz")