Hacker News new | ask | show | jobs
by pbz 4789 days ago
Well, after removing all the default headers, there's the CSRF token, certain paths that will bypass a regular 404 detection, and so on... There are ways.