Skip to content

[FALSE-NEGATIVE] Report Google Client ID from headers #11443

@davidfegyver

Description

@davidfegyver

Template IDs or paths

- http/exposures/tokens/google/google-client-id.yaml

Steps To Reproduce

Hi! Is there any reason not to check for Google Client ID-s in the HTTP headers? Some services, like Google IAP specifically has this string only in the response Location header, when it redirects for authentication. I would suggest the line part: body to be changed to part: all.

Thanks!
@davidfegyver

Relevant dumped responses

Image

Metadata

Metadata

Assignees

Labels

DoneReady to mergefalse-negativeNuclei template missing valid results

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions