New issue
Advanced search Search tips

Issue 718239 link

Starred by 1 user

Issue metadata

Status: Started
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Bug
Team-Security-UX



Sign in to add a comment

Check response headers when determining if a SafeBrowsing extended report upload was successful

Project Member Reported by mea...@chromium.org, May 4 2017

Issue description

We currently only check net error and response code while sending reports. It's possible that there are content filters, firewalls and captive portals that return a canned HTTP 200 response while blocking the actual request at the same time. We'd assume such a report upload to be successful even though it was blocked.

It might be a good idea to check the response headers in addition to the response code. As an example, SafeBrowsing extended reporting server sets X-Google-Service: safebrowsing_csd,safebrowsing-aggregate for cert report uploads, which we could test.
 
Description: Show this description
Labels: Hotlist-GoodFirstBug

Comment 3 by est...@chromium.org, Nov 10 2017

Labels: Hotlist-EnamelAndFriendsFixIt
Owner: carlosil@chromium.org
Status: Assigned (was: Available)
Status: Started (was: Assigned)

Comment 6 by est...@chromium.org, Feb 18 2018

Labels: -Hotlist-EnamelAndFriendsFixIt

Sign in to add a comment