Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Have attacker rerun all requests, update xfail test #44

Merged
merged 8 commits into from
Apr 10, 2020
20 changes: 10 additions & 10 deletions fuzz_lightyear/plugins/idor.py
Original file line number Diff line number Diff line change
Expand Up @@ -34,13 +34,13 @@ def is_vulnerable(
request_sequence: List[FuzzingRequest],
response_sequence: List[Any],
) -> bool:
last_request = request_sequence[-1]
try:
last_request.send(
auth=get_abstraction().get_attacker_session(), # type: ignore
should_log=False,
)

return True
except (HTTPError, SwaggerMappingError, ValidationError):
return False
for request in request_sequence:
try:
request.send(
auth=get_abstraction().get_attacker_session(), # type: ignore
should_log=False,
)

except (HTTPError, SwaggerMappingError, ValidationError):
return False
return True
tanx16 marked this conversation as resolved.
Show resolved Hide resolved
17 changes: 11 additions & 6 deletions testing/vulnerable_app/views/sequence.py
Original file line number Diff line number Diff line change
Expand Up @@ -61,25 +61,30 @@ def get(self):
return number_query_parser.parse_args()['id']


@ns.route('/side-effect/create')
@ns.route('/side-effect/create/<int:id>')
class CreateWithSideEffect(Resource):
@api.doc(security='apikey')
@api.response(200, 'Success', model=widget_model)
@requires_user
def post(self, user):
user.has_created_resource = True
user.save()
def post(self, id, user):

with database.connection() as session:
entry = session.query(Widget).filter(
Widget.id == id,
).first()
if entry:
abort(500)
tanx16 marked this conversation as resolved.
Show resolved Hide resolved
entry = Widget()
entry.id = id

session.add(entry)
session.commit()

widget_id = entry.id
user.has_created_resource = True
user.save()

return {
'id': widget_id,
'id': id,
}


Expand Down