mirror of
https://github.com/usestrix/strix.git
synced 2026-10-09 03:18:31 +00:00
Update strix/skills/custom/validation_methods.md
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
This commit is contained in:
parent
e204a846a2
commit
ddb2e0fb48
1 changed files with 1 additions and 1 deletions
|
|
@ -48,7 +48,7 @@ Proof: Headless browser confirms onerror fired (e.g., network request to canary
|
|||
```
|
||||
Follow-up: create a new object and check if `obj.strix_canary_a1b2c3 === "polluted"`.
|
||||
|
||||
**Strength:** Deterministic. If the canary appears, the finding is confirmed.
|
||||
**Strength:** Deterministic for confirming data flow. Exploitability is confirmed only when the canary demonstrates execution or another concrete security impact.
|
||||
**Weakness:** Only works for injection/reflection classes where you control input and observe output.
|
||||
|
||||
### 2. Heuristic / Differential Validation
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue