Skip to content

Commit f40bd1a

Browse files
authored
Merge pull request #161 from blacklanternsecurity/dev
Dev-> Main
2 parents 191485f + 61894d5 commit f40bd1a

File tree

5 files changed

+720
-679
lines changed

5 files changed

+720
-679
lines changed

badsecrets/modules/express_signedcookies_es.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ class ExpressSignedCookies_ES(BadsecretsBase):
2424
}
2525

2626
def carve_regex(self):
27-
return re.compile(r"(s%3[Aa][^\.]+\.(?!.*%20|.*%22)[a-zA-Z0-9%]{20,90})")
27+
return re.compile(r"(?<!http)(s%3[Aa][^.]+\.(?![^ ]*%20|[^ ]*%22)[a-zA-Z0-9%]{20,90})")
2828

2929
def expressHMAC(self, payload, secret, hash_algorithm):
3030
return no_padding_urlsafe_base64_encode_es(

0 commit comments

Comments
 (0)