sherlock-project/sherlock

False positive for: LushStories

aytvill opened this issue · 0 comments

Additional info

I have run today check for my own nickname for first time with --nsfw flag. Among other false positives, Lush Stories reported by Sherlock as if I have profile, which I do not.

Browser merely redirects me to /login page.

When I execute curl with profile curl -I https://www.lushstories.com/profile/aytvill, it also gives redirect 302.

curl -I https://www.lushstories.com/profile/aytvill
HTTP/2 302
date: Thu, 21 Nov 2024 10:56:31 GMT
location: /login
x-varnish: 568760724
age: 0
via: 1.1 varnish (Varnish/6.1)
x-varnish-ttl:
x-varnish-cache:
strict-transport-security: max-age=31536000
x-content-type-options: nosniff
cf-cache-status: DYNAMIC
report-to: {"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=e3FnD3pCn7xilwslTf8Z9UcTP1kFqydQ1JU9oIVQrPSH3T4GnRakPhoGvGqKDUOt5m55nmTRV4nNfmBfEKCZDnq5cPczBV9Sxj8EkQ2B90sZMP%2F2IjW5aTCXbPlbPrERNLhucQqt"}],"group":"cf-nel","max_age":604800}
nel: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
server: cloudflare
cf-ray: 8e6027518be80e50-AMS
alt-svc: h3=":443"; ma=86400
server-timing: cfL4;desc="?proto=TCP&rtt=45503&sent=7&recv=10&lost=0&retrans=0&sent_bytes=3419&recv_bytes=841&delivery_rate=69178&cwnd=47&unsent_bytes=0&cid=00ac86517898d8b6&ts=285&x=0"

Which implies one has to have profile in order to be able to check existence of profile with nickname. As I'm not willing to create there any profiles, I only state:

in case of LS site your method to detect has clear 100% false positive for my nickname.

Code of Conduct

  • I agree to follow this project's Code of Conduct