Invalid Content-Length Headers
Item | Description |
---|---|
Full Fuzzer Name | InvalidContentLengthHeadersFuzzer |
Log Key | ICLH |
Description | This fuzzer will set an invalid Content-Length header. The Fuzzer will send happy path requests. The expectation is that APIs will reject the request with 400 . |
Enabled by default? | Yes |
Target header types | All |
Expected result when fuzzed header is required | N/A |
Expected result when fuzzed header is optional | N/A |
Fuzzing logic | Iteratively calls all paths and HTTP methods and set an invalid Content-Length header with value 1 , expecting a 400 response code. |
Conditions when this fuzzer will be skipped | None |
HTTP methods that will be skipped | None |
Reporting | Reports error if: 1. response code is 404 ; 2. response code is documented, but not equal to 400 ; 3. any unexpected exception. Reports warn if: 1. response code is expected and documented, but not matches response schema; 2. response code is expected, but not documented. Reports success if: 1. response code 400 . |