()
| 11 | ) |
| 12 | |
| 13 | func TestWebCacheDeception() reportResult { |
| 14 | var repResult reportResult |
| 15 | repResult.Technique = "Cache Deception" |
| 16 | |
| 17 | // cacheable extensions: class, css, jar, js, jpg, jpeg, gif, ico, png, bmp, pict, csv, doc, docx, xls, xlsx, ps, pdf, pls, ppt, pptx, tif, tiff, ttf, otf, webp, woff, woff2, svg, svgz, eot, eps, ejs, swf, torrent, midi, mid |
| 18 | |
| 19 | appendings := []string{ |
| 20 | "/.css", // Path parameter |
| 21 | "/nonexistent1.css", // Path parameter |
| 22 | "/../nonexistent2.css", // Path traversal |
| 23 | "/%2e%2e/nonexistent3.css", // Encoded path traversal |
| 24 | "%0Anonexistent4.css", // Encoded Newline |
| 25 | "%00nonexistent5.css", // Encoded Null Byte |
| 26 | "%09nonexistent6.css", // Encoded Tab |
| 27 | "%3Bnonexistent7.css", // Encoded Semicolon |
| 28 | "%23nonexistent8.css", // Encoded Pound |
| 29 | "%3Fname=valnonexistent9.css", // Encoded Question Mark |
| 30 | "%26name=valnonexistent10.css", // Encoded Ampersand |
| 31 | ";nonexistent11.css", // Semicolon |
| 32 | "?nonexistent12.css", // Question Mark |
| 33 | "&nonexistent13.css", // Ampersand |
| 34 | "%0A%2f%2e%2e%2fresources%2fnonexistent1.css", // Encoded Path Traversal to static directory using Encoded Newline |
| 35 | "%00%2f%2e%2e%2fresources%2fnonexistent2.css", // Encoded Path Traversal to static directory using Encoded Null Byte |
| 36 | "%09%2f%2e%2e%2fresources%2fnonexistent3.css", // Encoded Path Traversal to static directory using Encoded Tab |
| 37 | "%3B%2f%2e%2e%2fresources%2fnonexistent4.css", // Encoded Path Traversal to static directoryEncoded using Semicolon |
| 38 | "%23%2f%2e%2e%2fresources%2fnonexistent5.css", // Encoded Path Traversal to static directory using Encoded Pound |
| 39 | "%3F%2f%2e%2e%2fresources%2fnonexistent6.css", // Encoded Path Traversal to static directory using Encoded Question Mark |
| 40 | "%26%2f%2e%2e%2fresources%2fnonexistent7.css", // Encoded Path Traversal to static directory using Encoded Ampersand |
| 41 | ";%2f%2e%2e%2fresources%2fnonexistent8.css", // Encoded Path Traversal to static directory using Semicolon |
| 42 | "?%2f%2e%2e%2fresources%2fnonexistent9.css", // Encoded Path Traversal to static directoy using Question Mark |
| 43 | "&%2f%2e%2e%2fresources%2fnonexistent10.css", // Encoded Path Traversal to static directory using Ampersand |
| 44 | "%0A%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2frobots.txt", // Encoded Path Traversal to robots.txt using Encoded Newline |
| 45 | "%00%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2frobots.txt", // Encoded Path Traversal to robots.txt directory using Encoded Null Byte |
| 46 | "%09%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2frobots.txt", // Encoded Path Traversal to robots.txt directory using Encoded Tab |
| 47 | "%3B%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2frobots.txt", // Encoded Path Traversal to robots.txt directoryEncoded using Semicolon |
| 48 | "%23%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2frobots.txt", // Encoded Path Traversal to robots.txt directory using Encoded Pound |
| 49 | "%3F%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2frobots.txt", // Encoded Path Traversal to robots.txt directory using Encoded Question Mark |
| 50 | "%26%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2frobots.txt", // Encoded Path Traversal to robots.txt directory using Encoded Ampersand |
| 51 | ";%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2frobots.txt", // Encoded Path Traversal to robots.txt directory using Semicolon |
| 52 | "?%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2frobots.txt", // Encoded Path Traversal to robots.txt directoy using Question Mark |
| 53 | "&%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2frobots.txt", // Encoded Path Traversal to robots.txt directory using Ampersand |
| 54 | } |
| 55 | // TODO add "Exploiting normalization by the origin server" cache deception which needs to prepend something before the url path |
| 56 | |
| 57 | if Config.Website.StatusCode != 200 || Config.Website.Body == "" { |
| 58 | msg := "Skipping Web Cache Deception test, as it requires a valid website configuration with a status code of 200 and a non-empty body.\n" |
| 59 | Print(msg, Yellow) |
| 60 | repResult.HasError = true |
| 61 | repResult.ErrorMessages = append(repResult.ErrorMessages, msg) |
| 62 | return repResult |
| 63 | } |
| 64 | PrintVerbose("Testing for Web Cache Deception\n", NoColor, 1) |
| 65 | |
| 66 | // test each appending one after another |
| 67 | for _, appendStr := range appendings { |
| 68 | err := webCacheDeceptionTemplate(&repResult, appendStr) |
| 69 | if err != nil { |
| 70 | repResult.HasError = true |
no test coverage detected