diff --git a/CHANGELOG.md b/CHANGELOG.md
index dca4c38..bfb72f1 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -3,6 +3,9 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/).
+## 2025-08-30
+- Imported OS Command Injection tests from [Reinforced Wavsep](https://github.com/luigiurbano/Reinforced-Wavsep) at commit [962d566](https://github.com/luigiurbano/Reinforced-Wavsep/commit/962d566ebe51a3f64f772b6c1856d99f1150ba4a).
+
## 2025-08-28
### Changed
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
new file mode 100644
index 0000000..72f6c7e
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..4b68682
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | ";
+ String linuxPrefix = "cat " + defaultFileName + " | ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
new file mode 100644
index 0000000..f99c538
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr ";
+ String linuxPrefix = "cat " + defaultFileName + " | grep ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..04d12f8
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr ";
+ String linuxPrefix = "cat " + defaultFileName + " | grep ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..5ec94bb
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr ";
+ String linuxPrefix = "cat " + defaultFileName + " | grep ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
new file mode 100644
index 0000000..96fa22a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
@@ -0,0 +1,321 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ String linuxPostfix = "| grep Java";
+ String windowsPostfix = "| findstr Java";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ postfix = windowsPostfix;
+ } else {
+ prefix = linuxPrefix;
+ postfix = linuxPostfix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..da38958
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,321 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ String linuxPostfix = "| grep Java";
+ String windowsPostfix = "| findstr Java";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ postfix = windowsPostfix;
+ } else {
+ prefix = linuxPrefix;
+ postfix = linuxPostfix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..70849cc
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
@@ -0,0 +1,321 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ String linuxPostfix = "| grep Java";
+ String windowsPostfix = "| findstr Java";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ postfix = windowsPostfix;
+ } else {
+ prefix = linuxPrefix;
+ postfix = linuxPostfix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
new file mode 100644
index 0000000..5a774c0
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
new file mode 100644
index 0000000..fe4d7dc
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
new file mode 100644
index 0000000..3a96365
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..89de206
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
new file mode 100644
index 0000000..52ca8d7
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
new file mode 100644
index 0000000..53eca1b
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
new file mode 100644
index 0000000..af5c857
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
new file mode 100644
index 0000000..5b7f33d
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
new file mode 100644
index 0000000..7f73872
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
new file mode 100644
index 0000000..38e2baa
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
new file mode 100644
index 0000000..96ace3a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
new file mode 100644
index 0000000..0ae9ff7
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
new file mode 100644
index 0000000..3873025
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..1e25a7c
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
new file mode 100644
index 0000000..75a1365
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
new file mode 100644
index 0000000..03e4ffc
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..999d694
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ System.out.println(prefix + input + postfix);
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..42d8494
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
new file mode 100644
index 0000000..5d0fa4a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | ";
+ String linuxPrefix = "cat " + defaultFileName + " | ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..b2bb923
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | ";
+ String linuxPrefix = "cat " + defaultFileName + " | ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/include.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/include.jsp
new file mode 100644
index 0000000..2ab7639
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/include.jsp
@@ -0,0 +1,145 @@
+<%@page import="java.io.*" %>
+<%@page import="java.net.*" %>
+<%@page import="com.sectooladdict.encoders.HtmlEncoder" %>
+<%@page import="com.sectooladdict.constants.SystemConstants" %>
+<%@page import="com.sectooladdict.constants.FileConstants" %>
+<%@page import="com.sectooladdict.constants.ContentConstants" %>
+<%@page import="com.sectooladdict.enums.VulnerabilityType" %>
+<%@page import="com.sectooladdict.enums.ResponseType" %>
+<%@page import="com.sectooladdict.enums.DefaultInputType" %>
+<%@page import="com.sectooladdict.enums.FileAccessRestriction" %>
+<%@page import="com.sectooladdict.enums.FileInjectionContext" %>
+<%@page import="com.sectooladdict.enums.PrefixRequirement" %>
+<%@page import="com.sectooladdict.enums.OsType" %>
+
+<%
+//set debug flag from main config
+boolean debugMode = SystemConstants.DEBUG_FLAG_DEFAULT_STATE;
+
+//begin setting group definitions
+//--------------------------------
+
+//** Set File Access Restriction ***
+//NONE, WHITE_LIST, LOCAL_FOLDER_ONLY, PERMISSIONS,
+//UNIX_TRAVESAL_INPUT_VALIDATION, UNIX_TRAVESAL_INPUT_REMOVAL,
+//WINDOWS_TRAVESAL_INPUT_VALIDATION, WINDOWS_TRAVESAL_INPUT_REMOVAL,
+//SLASH_INPUT_VALIDATION, SLASH_INPUT_REMOVAL,
+//BACKSLASH_INPUT_VALIDATION, BACKSLASH_INPUT_REMOVAL,
+FileAccessRestriction accessRestriction = FileAccessRestriction.NONE;
+
+//** Set Default Input Format ***
+//FULL_PATH_INPUT, RELATIVE_INPUT, INVALID_INPUT, EMPTY_INPUT
+DefaultInputType defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX;
+
+//set path requirement
+//ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+//FTP_DIRECTIVE, HTTP_DIRECTIVE,
+PrefixRequirement prefixRequired = PrefixRequirement.ANY;
+
+//*** set OS simulation (unix default) ***
+//WINDOWS, UNIX
+OsType osSimulated = OsType.ANY;
+
+//*** Set Default Response Type ***
+//ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ResponseType invalidResponseType = ResponseType.ERROR_200;
+
+//*** Set Default Content Type ***
+//CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+String validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+//*** Set Default Prefix String ***
+String prefix = ""; //"",[cmd.exe /c ] [command]
+//*** Set Default Prefix String ***
+String postfix = ""; //"",|[command] &[command] >>[command] >[command] <[command] <[command]
+
+//obtain deliminters and path information
+String fileDelimiter = System.getProperty("file.separator");
+String lineDelimiter = System.getProperty("line.separator");
+
+//Initial Path/URL:
+String DefaultInitialPath = ""; //Empty
+//Current User Directory File Object
+File directory = new File (".");
+//User Directory Path - Absolute
+String userPath = System.getProperty("user.dir");
+///Deployement Path Root - Absolute
+String documentRootPath =
+ getServletConfig().getServletContext().getRealPath("");
+//Relative path of current file - Absolute
+String currentFilePath = request.getRealPath(request.getServletPath());
+//Relative path of current directory - Absolute - No Final Line Delimiter
+String currentDirPath = request.getRealPath(
+ (request.getServletPath()).split("/Case")[0]);
+//Web Path of Root - Relative
+String contextPath = this.getServletContext().getContextPath();
+//Web Path of File - Relative and *NOT* including ROOT (!)
+String contextPathFile = request.getServletPath();
+//Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!)
+String contextRelativeDirPath = (request.getServletPath()).split("/Case")[0];
+
+if (debugMode == true) {
+ String BR = "
";
+ String FontStart = "";
+ String FontEnd = "";
+
+ System.out.println ("File delimiter: " + fileDelimiter);
+ out.println (FontStart + "File delimiter: " + FontEnd + fileDelimiter + BR);
+ System.out.println ("Line delimiter (encoded):" + HtmlEncoder.htmlEncode(lineDelimiter));
+ out.println (FontStart + "Line delimiter (encoded): " + FontEnd
+ + HtmlEncoder.htmlEncode(HtmlEncoder.htmlEncode(lineDelimiter)) + BR);
+
+ //User Directory Path - Absolute
+ System.out.println ("User Directory Path (Absolute): " + userPath);
+ out.println (FontStart + "User Directory Path (Absolute): " + FontEnd + userPath + BR);
+ ///Deployement Path Root - Absolute
+ System.out.println ("Deployment Path Root (Absolute): " + documentRootPath);
+ out.println (FontStart + "Deployment Path Root (Absolute): " + FontEnd + documentRootPath + BR);
+ //Relative path of current file - Absolute
+ System.out.println ("Deployment Path Current File (Absolute): " + currentFilePath);
+ out.println (FontStart + "Deployment Path Current File (Absolute): " + FontEnd + currentFilePath + BR);
+ //Relative path of current directory - Absolute
+ System.out.println ("Deployment Path Current Directory (Absolute): " + currentDirPath);
+ out.println (FontStart + "Deployment Path Current Directory (Absolute): " + FontEnd + currentDirPath + BR);
+ //Web Path of Root - Relative
+ System.out.println ("Web Path Root (Relative): " + contextPath);
+ out.println (FontStart + "Web Path Root (Relative): " + FontEnd + contextPath + BR);
+ //Web Path of File - Relative and *NOT* including ROOT (!)
+ System.out.println ("Web Path of File (Relative-no-root): " + contextPathFile);
+ out.println (FontStart + "Web Path of File (Relative-no-root): " + FontEnd + contextPathFile + BR);
+ //Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!)
+ System.out.println ("Web Path of Dir (Relative-no-root): " + contextRelativeDirPath);
+ out.println (FontStart + "Web Path of Dir (Relative-no-root): " + FontEnd + contextRelativeDirPath + BR);
+ //Full URL:
+ System.out.println("request URL: " + request.getRequestURL());
+ out.println(FontStart + "request URL: " + FontEnd + request.getRequestURL() + BR);
+
+ //System.out.println(request.getRealPath("/"));
+
+ try {
+ System.out.println ("Current directory's canonical path: "
+ + directory.getCanonicalPath());
+ out.println (FontStart + "Current directory's canonical path: "
+ + FontEnd + directory.getCanonicalPath() + BR);
+ System.out.println ("Current directory's absolute path: "
+ + directory.getAbsolutePath());
+ out.println (FontStart + "Current directory's absolute path: "
+ + FontEnd + directory.getAbsolutePath() + BR);
+ } catch(Exception e) {
+ System.out.println("Exceptione is =" + e.getMessage());
+ }
+
+ out.println(BR + BR);
+} // end of debug if
+
+//****ways to get the file ****
+//1)context.getRequestDispatcher("/").forward(request, response);
+//2)File file = new File (currentDirPath + targetFile);
+//3)is = getServletContext().getResourceAsStream(contextRelativeDirPath + targetFile);
+//4)is = new FileInputStream(currentDirPath + targetFile);
+//5)URL url = new URL(URLInitialPath + targetFile);
+// URLConnection urlconn = url.openConnection();
+//6)FORWARD (FP)
+//6)REDIRECT (FP)
+
+%>
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/index.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/index.jsp
new file mode 100644
index 0000000..6542362
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/index.jsp
@@ -0,0 +1,1315 @@
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+Evaluation of OS Command Injection Detection Accuracy - HTTP GET Method
+
+
+
+<%@ include file="include.jsp"%>
+
+<%
+ String defaultFullOsCommandInputWithoutPrefix = null;
+ String defaultFullOsCommandInputWithPrefix = null;
+ String defaultPostfixOsCommandInputWithInitialCommand = null;
+ String defaultPostfixOsCommandInputWithoutInitialCommand = null;
+ String defaultEmptyInput = null;
+ String defaultPartialInput = null;
+ String defaultPostfixValueInput = null;
+ String defaultPostfixCommandInput = null;
+ String defaultInvalidInput = null;
+
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultFullOsCommandInputWithoutPrefix = "dir";
+ defaultFullOsCommandInputWithPrefix = "cmd.exe /c dir";
+
+ defaultPostfixOsCommandInputWithInitialCommand = "findstr Java";
+ defaultPostfixOsCommandInputWithoutInitialCommand = "Java";
+ defaultEmptyInput = "";
+ defaultPartialInput = "eclipse.ini";
+ defaultPostfixValueInput = "Build";
+ defaultPostfixCommandInput = " | findstr Build";
+ defaultInvalidInput = "dfdflkjsh";
+ } else {
+ defaultFullOsCommandInputWithoutPrefix = "ls";
+ defaultFullOsCommandInputWithPrefix = "ls";
+ defaultEmptyInput = "";
+ defaultPartialInput = "eclipse.ini";
+ defaultPostfixValueInput = "Build";
+ defaultPostfixCommandInput = " | grep Build";
+ defaultInvalidInput = "dfdflkjsh";
+ }
+%>
+
+OS Command Injection Test Cases - HTTP 200 Valid Responses:
+
+
+Injection Contexts Covered:
+1) Initial Statement/Command Context: Default OS Command Input with and without prefix:
+ [windows only: cmd.exe /c ]*OS COMMAND INJECTION*
+2) Internal Statement/Command Context: Input integrated in the middle of a fixed OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*[ | postfix-fixed-commands]
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*
+3) Internal Statement/Command Context: Input integrated in postfix section of an OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ][ | postfix-fixed-commands ]*INPUT*
+
+
+
+
+
+ Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (with prefix), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Full OS Command With Prefix |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): cmd.exe /c dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default EMPTY input (invalid), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+ Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default INVALID input (invalid), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (no prefix), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Full OS Command No Prefix |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): | cat /etc/passwd
+ |
+
+
+
+
+
+ Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+ |
+
+
+
+
+
+ Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+ |
+
+
+
+
+ Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Full OS Postfix Command |
+ ANY | Postfix Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Postfix Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Postfix Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Partial OS Postfix Command |
+ ANY | Postfix Statement/Command (After initial postfix command) | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+ |
+
+
+
+
+
+
+ Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Postfix Statement/Command (After initial postfix command) | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+ |
+
+
+
+
+
+
+
+ Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Postfix Statement/Command (After initial postfix command) | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+ |
+
+
+
+
+
+
+ Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default PARTIAL input (filename), using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Partial Command (filename) |
+ ANY | Mid Statement/Command with Fixed Postfix | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent14.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent14.txt
+ |
+
+
+
+
+
+
+ Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default EMPTY input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Mid Statement/Command with Fixed Postfix | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent15.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent15.txt
+ |
+
+
+
+
+
+
+ Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default INVALID input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Mid Statement/Command with Fixed Postfix | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent16.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent16.txt
+ |
+
+
+
+
+
+
+ Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Validation | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent17.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent17.txt
+ |
+
+
+
+
+
+
+ Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Validation | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent18.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent18.txt
+ |
+
+
+
+
+
+
+ Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Validation | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent19.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent19.txt
+ |
+
+
+
+
+
+
+ Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Removal | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent20.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent20.txt
+ |
+
+
+
+
+
+
+ Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Removal | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent21.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent21.txt
+ |
+
+
+
+
+
+
+ Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Removal | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent22.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent22.txt
+ |
+
+
+
+
+
+ Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Validation | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent23.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent23.txt
+ |
+
+
+
+
+
+ Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Validation | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent24.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent24.txt
+ |
+
+
+
+
+
+ Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Validation | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent25.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent25.txt
+ |
+
+
+
+
+
+ Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Removal | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent26.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent26.txt
+ |
+
+
+
+
+
+ Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Removal | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent27.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent27.txt
+ |
+
+
+
+
+
+ Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Removal | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent28.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent28.txt
+ |
+
+
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
new file mode 100644
index 0000000..72f6c7e
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..4b68682
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | ";
+ String linuxPrefix = "cat " + defaultFileName + " | ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
new file mode 100644
index 0000000..f99c538
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr ";
+ String linuxPrefix = "cat " + defaultFileName + " | grep ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..04d12f8
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr ";
+ String linuxPrefix = "cat " + defaultFileName + " | grep ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..5ec94bb
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr ";
+ String linuxPrefix = "cat " + defaultFileName + " | grep ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
new file mode 100644
index 0000000..96fa22a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
@@ -0,0 +1,321 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ String linuxPostfix = "| grep Java";
+ String windowsPostfix = "| findstr Java";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ postfix = windowsPostfix;
+ } else {
+ prefix = linuxPrefix;
+ postfix = linuxPostfix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..da38958
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,321 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ String linuxPostfix = "| grep Java";
+ String windowsPostfix = "| findstr Java";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ postfix = windowsPostfix;
+ } else {
+ prefix = linuxPrefix;
+ postfix = linuxPostfix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..70849cc
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
@@ -0,0 +1,321 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ String linuxPostfix = "| grep Java";
+ String windowsPostfix = "| findstr Java";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ postfix = windowsPostfix;
+ } else {
+ prefix = linuxPrefix;
+ postfix = linuxPostfix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
new file mode 100644
index 0000000..5a774c0
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
new file mode 100644
index 0000000..fe4d7dc
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
new file mode 100644
index 0000000..3a96365
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..89de206
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
new file mode 100644
index 0000000..52ca8d7
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
new file mode 100644
index 0000000..53eca1b
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
new file mode 100644
index 0000000..af5c857
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
new file mode 100644
index 0000000..5b7f33d
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
new file mode 100644
index 0000000..7f73872
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
new file mode 100644
index 0000000..38e2baa
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
new file mode 100644
index 0000000..96ace3a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
new file mode 100644
index 0000000..0ae9ff7
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
new file mode 100644
index 0000000..3873025
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..1e25a7c
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
new file mode 100644
index 0000000..75a1365
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
new file mode 100644
index 0000000..03e4ffc
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..1e0d95a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..42d8494
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
new file mode 100644
index 0000000..5d0fa4a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | ";
+ String linuxPrefix = "cat " + defaultFileName + " | ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..b2bb923
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | ";
+ String linuxPrefix = "cat " + defaultFileName + " | ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/include.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/include.jsp
new file mode 100644
index 0000000..a357805
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/include.jsp
@@ -0,0 +1,145 @@
+<%@page import="java.io.*" %>
+<%@page import="java.net.*" %>
+<%@page import="com.sectooladdict.encoders.HtmlEncoder" %>
+<%@page import="com.sectooladdict.constants.SystemConstants" %>
+<%@page import="com.sectooladdict.constants.FileConstants" %>
+<%@page import="com.sectooladdict.constants.ContentConstants" %>
+<%@page import="com.sectooladdict.enums.VulnerabilityType" %>
+<%@page import="com.sectooladdict.enums.ResponseType" %>
+<%@page import="com.sectooladdict.enums.DefaultInputType" %>
+<%@page import="com.sectooladdict.enums.FileAccessRestriction" %>
+<%@page import="com.sectooladdict.enums.FileInjectionContext" %>
+<%@page import="com.sectooladdict.enums.PrefixRequirement" %>
+<%@page import="com.sectooladdict.enums.OsType" %>
+
+<%
+//set debug flag from main config
+boolean debugMode = SystemConstants.DEBUG_FLAG_DEFAULT_STATE;
+
+//begin setting group definitions
+//--------------------------------
+
+//** Set File Access Restriction ***
+//NONE, WHITE_LIST, LOCAL_FOLDER_ONLY, PERMISSIONS,
+//UNIX_TRAVESAL_INPUT_VALIDATION, UNIX_TRAVESAL_INPUT_REMOVAL,
+//WINDOWS_TRAVESAL_INPUT_VALIDATION, WINDOWS_TRAVESAL_INPUT_REMOVAL,
+//SLASH_INPUT_VALIDATION, SLASH_INPUT_REMOVAL,
+//BACKSLASH_INPUT_VALIDATION, BACKSLASH_INPUT_REMOVAL,
+FileAccessRestriction accessRestriction = FileAccessRestriction.NONE;
+
+//** Set Default Input Format ***
+//FULL_PATH_INPUT, RELATIVE_INPUT, INVALID_INPUT, EMPTY_INPUT
+DefaultInputType defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX;
+
+//set path requirement
+//ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+//FTP_DIRECTIVE, HTTP_DIRECTIVE,
+PrefixRequirement prefixRequired = PrefixRequirement.ANY;
+
+//*** set OS simulation (unix default) ***
+//WINDOWS, UNIX
+OsType osSimulated = OsType.ANY;
+
+//*** Set Default Response Type ***
+//ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ResponseType invalidResponseType = ResponseType.ERROR_500;
+
+//*** Set Default Content Type ***
+//CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+String validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+//*** Set Default Prefix String ***
+String prefix = ""; //"",[cmd.exe /c ] [command]
+//*** Set Default Prefix String ***
+String postfix = ""; //"",|[command] &[command] >>[command] >[command] <[command] <[command]
+
+//obtain deliminters and path information
+String fileDelimiter = System.getProperty("file.separator");
+String lineDelimiter = System.getProperty("line.separator");
+
+//Initial Path/URL:
+String DefaultInitialPath = ""; //Empty
+//Current User Directory File Object
+File directory = new File (".");
+//User Directory Path - Absolute
+String userPath = System.getProperty("user.dir");
+///Deployement Path Root - Absolute
+String documentRootPath =
+ getServletConfig().getServletContext().getRealPath("");
+//Relative path of current file - Absolute
+String currentFilePath = request.getRealPath(request.getServletPath());
+//Relative path of current directory - Absolute - No Final Line Delimiter
+String currentDirPath = request.getRealPath(
+ (request.getServletPath()).split("/Case")[0]);
+//Web Path of Root - Relative
+String contextPath = this.getServletContext().getContextPath();
+//Web Path of File - Relative and *NOT* including ROOT (!)
+String contextPathFile = request.getServletPath();
+//Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!)
+String contextRelativeDirPath = (request.getServletPath()).split("/Case")[0];
+
+if (debugMode == true) {
+ String BR = "
";
+ String FontStart = "";
+ String FontEnd = "";
+
+ System.out.println ("File delimiter: " + fileDelimiter);
+ out.println (FontStart + "File delimiter: " + FontEnd + fileDelimiter + BR);
+ System.out.println ("Line delimiter (encoded):" + HtmlEncoder.htmlEncode(lineDelimiter));
+ out.println (FontStart + "Line delimiter (encoded): " + FontEnd
+ + HtmlEncoder.htmlEncode(HtmlEncoder.htmlEncode(lineDelimiter)) + BR);
+
+ //User Directory Path - Absolute
+ System.out.println ("User Directory Path (Absolute): " + userPath);
+ out.println (FontStart + "User Directory Path (Absolute): " + FontEnd + userPath + BR);
+ ///Deployement Path Root - Absolute
+ System.out.println ("Deployment Path Root (Absolute): " + documentRootPath);
+ out.println (FontStart + "Deployment Path Root (Absolute): " + FontEnd + documentRootPath + BR);
+ //Relative path of current file - Absolute
+ System.out.println ("Deployment Path Current File (Absolute): " + currentFilePath);
+ out.println (FontStart + "Deployment Path Current File (Absolute): " + FontEnd + currentFilePath + BR);
+ //Relative path of current directory - Absolute
+ System.out.println ("Deployment Path Current Directory (Absolute): " + currentDirPath);
+ out.println (FontStart + "Deployment Path Current Directory (Absolute): " + FontEnd + currentDirPath + BR);
+ //Web Path of Root - Relative
+ System.out.println ("Web Path Root (Relative): " + contextPath);
+ out.println (FontStart + "Web Path Root (Relative): " + FontEnd + contextPath + BR);
+ //Web Path of File - Relative and *NOT* including ROOT (!)
+ System.out.println ("Web Path of File (Relative-no-root): " + contextPathFile);
+ out.println (FontStart + "Web Path of File (Relative-no-root): " + FontEnd + contextPathFile + BR);
+ //Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!)
+ System.out.println ("Web Path of Dir (Relative-no-root): " + contextRelativeDirPath);
+ out.println (FontStart + "Web Path of Dir (Relative-no-root): " + FontEnd + contextRelativeDirPath + BR);
+ //Full URL:
+ System.out.println("request URL: " + request.getRequestURL());
+ out.println(FontStart + "request URL: " + FontEnd + request.getRequestURL() + BR);
+
+ //System.out.println(request.getRealPath("/"));
+
+ try {
+ System.out.println ("Current directory's canonical path: "
+ + directory.getCanonicalPath());
+ out.println (FontStart + "Current directory's canonical path: "
+ + FontEnd + directory.getCanonicalPath() + BR);
+ System.out.println ("Current directory's absolute path: "
+ + directory.getAbsolutePath());
+ out.println (FontStart + "Current directory's absolute path: "
+ + FontEnd + directory.getAbsolutePath() + BR);
+ } catch(Exception e) {
+ System.out.println("Exceptione is =" + e.getMessage());
+ }
+
+ out.println(BR + BR);
+} // end of debug if
+
+//****ways to get the file ****
+//1)context.getRequestDispatcher("/").forward(request, response);
+//2)File file = new File (currentDirPath + targetFile);
+//3)is = getServletContext().getResourceAsStream(contextRelativeDirPath + targetFile);
+//4)is = new FileInputStream(currentDirPath + targetFile);
+//5)URL url = new URL(URLInitialPath + targetFile);
+// URLConnection urlconn = url.openConnection();
+//6)FORWARD (FP)
+//6)REDIRECT (FP)
+
+%>
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/index.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/index.jsp
new file mode 100644
index 0000000..a8ada8a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/index.jsp
@@ -0,0 +1,1315 @@
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+Evaluation of OS Command Injection Detection Accuracy - HTTP GET Method
+
+
+
+<%@ include file="include.jsp"%>
+
+<%
+ String defaultFullOsCommandInputWithoutPrefix = null;
+ String defaultFullOsCommandInputWithPrefix = null;
+ String defaultPostfixOsCommandInputWithInitialCommand = null;
+ String defaultPostfixOsCommandInputWithoutInitialCommand = null;
+ String defaultEmptyInput = null;
+ String defaultPartialInput = null;
+ String defaultPostfixValueInput = null;
+ String defaultPostfixCommandInput = null;
+ String defaultInvalidInput = null;
+
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultFullOsCommandInputWithoutPrefix = "dir";
+ defaultFullOsCommandInputWithPrefix = "cmd.exe /c dir";
+
+ defaultPostfixOsCommandInputWithInitialCommand = "findstr Java";
+ defaultPostfixOsCommandInputWithoutInitialCommand = "Java";
+ defaultEmptyInput = "";
+ defaultPartialInput = "eclipse.ini";
+ defaultPostfixValueInput = "Build";
+ defaultPostfixCommandInput = " | findstr Build";
+ defaultInvalidInput = "dfdflkjsh";
+ } else {
+ defaultFullOsCommandInputWithoutPrefix = "ls";
+ defaultFullOsCommandInputWithPrefix = "ls";
+ defaultEmptyInput = "";
+ defaultPartialInput = "eclipse.ini";
+ defaultPostfixValueInput = "Build";
+ defaultPostfixCommandInput = " | grep Build";
+ defaultInvalidInput = "dfdflkjsh";
+ }
+%>
+
+OS Command Injection Test Cases - HTTP 200 Valid Responses:
+
+
+Injection Contexts Covered:
+1) Initial Statement/Command Context: Default OS Command Input with and without prefix:
+ [windows only: cmd.exe /c ]*OS COMMAND INJECTION*
+2) Internal Statement/Command Context: Input integrated in the middle of a fixed OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*[ | postfix-fixed-commands]
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*
+3) Internal Statement/Command Context: Input integrated in postfix section of an OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ][ | postfix-fixed-commands ]*INPUT*
+
+
+
+
+
+ Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (with prefix), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Full OS Command With Prefix |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): cmd.exe /c dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default EMPTY input (invalid), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+ Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default INVALID input (invalid), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (no prefix), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Full OS Command No Prefix |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): | cat /etc/passwd
+ |
+
+
+
+
+
+ Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+ |
+
+
+
+
+
+ Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+ |
+
+
+
+
+ Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Full OS Postfix Command |
+ ANY | Postfix Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Postfix Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Postfix Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Partial OS Postfix Command |
+ ANY | Postfix Statement/Command (After initial postfix command) | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+ |
+
+
+
+
+
+
+ Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Postfix Statement/Command (After initial postfix command) | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+ |
+
+
+
+
+
+
+
+ Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Postfix Statement/Command (After initial postfix command) | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+ |
+
+
+
+
+
+
+ Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default PARTIAL input (filename), using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Partial Command (filename) |
+ ANY | Mid Statement/Command with Fixed Postfix | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent14.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent14.txt
+ |
+
+
+
+
+
+
+ Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default EMPTY input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Mid Statement/Command with Fixed Postfix | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent15.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent15.txt
+ |
+
+
+
+
+
+
+ Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default INVALID input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Mid Statement/Command with Fixed Postfix | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent16.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent16.txt
+ |
+
+
+
+
+
+
+ Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Validation | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent17.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent17.txt
+ |
+
+
+
+
+
+
+ Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Validation | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent18.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent18.txt
+ |
+
+
+
+
+
+
+ Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Validation | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent19.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent19.txt
+ |
+
+
+
+
+
+
+ Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Removal | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent20.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent20.txt
+ |
+
+
+
+
+
+
+ Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Removal | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent21.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent21.txt
+ |
+
+
+
+
+
+
+ Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Removal | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent22.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent22.txt
+ |
+
+
+
+
+
+ Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Validation | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent23.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent23.txt
+ |
+
+
+
+
+
+ Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Validation | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent24.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent24.txt
+ |
+
+
+
+
+
+ Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Validation | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent25.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent25.txt
+ |
+
+
+
+
+
+ Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Removal | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent26.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent26.txt
+ |
+
+
+
+
+
+ Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Removal | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent27.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent27.txt
+ |
+
+
+
+
+
+ Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Removal | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent28.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent28.txt
+ |
+
+
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
new file mode 100644
index 0000000..72f6c7e
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..4b68682
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | ";
+ String linuxPrefix = "cat " + defaultFileName + " | ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
new file mode 100644
index 0000000..f99c538
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr ";
+ String linuxPrefix = "cat " + defaultFileName + " | grep ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..04d12f8
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr ";
+ String linuxPrefix = "cat " + defaultFileName + " | grep ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..5ec94bb
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr ";
+ String linuxPrefix = "cat " + defaultFileName + " | grep ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
new file mode 100644
index 0000000..96fa22a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
@@ -0,0 +1,321 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ String linuxPostfix = "| grep Java";
+ String windowsPostfix = "| findstr Java";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ postfix = windowsPostfix;
+ } else {
+ prefix = linuxPrefix;
+ postfix = linuxPostfix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..da38958
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,321 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ String linuxPostfix = "| grep Java";
+ String windowsPostfix = "| findstr Java";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ postfix = windowsPostfix;
+ } else {
+ prefix = linuxPrefix;
+ postfix = linuxPostfix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..70849cc
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
@@ -0,0 +1,321 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ String linuxPostfix = "| grep Java";
+ String windowsPostfix = "| findstr Java";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ postfix = windowsPostfix;
+ } else {
+ prefix = linuxPrefix;
+ postfix = linuxPostfix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
new file mode 100644
index 0000000..5a774c0
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
new file mode 100644
index 0000000..fe4d7dc
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
new file mode 100644
index 0000000..3a96365
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..89de206
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
new file mode 100644
index 0000000..52ca8d7
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
new file mode 100644
index 0000000..53eca1b
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
new file mode 100644
index 0000000..af5c857
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
new file mode 100644
index 0000000..5b7f33d
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
new file mode 100644
index 0000000..7f73872
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
new file mode 100644
index 0000000..38e2baa
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
new file mode 100644
index 0000000..96ace3a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
new file mode 100644
index 0000000..0ae9ff7
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
new file mode 100644
index 0000000..3873025
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..1e25a7c
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
new file mode 100644
index 0000000..75a1365
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
new file mode 100644
index 0000000..03e4ffc
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..1e0d95a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..42d8494
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
new file mode 100644
index 0000000..5d0fa4a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | ";
+ String linuxPrefix = "cat " + defaultFileName + " | ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..b2bb923
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | ";
+ String linuxPrefix = "cat " + defaultFileName + " | ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/include.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/include.jsp
new file mode 100644
index 0000000..2ab7639
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/include.jsp
@@ -0,0 +1,145 @@
+<%@page import="java.io.*" %>
+<%@page import="java.net.*" %>
+<%@page import="com.sectooladdict.encoders.HtmlEncoder" %>
+<%@page import="com.sectooladdict.constants.SystemConstants" %>
+<%@page import="com.sectooladdict.constants.FileConstants" %>
+<%@page import="com.sectooladdict.constants.ContentConstants" %>
+<%@page import="com.sectooladdict.enums.VulnerabilityType" %>
+<%@page import="com.sectooladdict.enums.ResponseType" %>
+<%@page import="com.sectooladdict.enums.DefaultInputType" %>
+<%@page import="com.sectooladdict.enums.FileAccessRestriction" %>
+<%@page import="com.sectooladdict.enums.FileInjectionContext" %>
+<%@page import="com.sectooladdict.enums.PrefixRequirement" %>
+<%@page import="com.sectooladdict.enums.OsType" %>
+
+<%
+//set debug flag from main config
+boolean debugMode = SystemConstants.DEBUG_FLAG_DEFAULT_STATE;
+
+//begin setting group definitions
+//--------------------------------
+
+//** Set File Access Restriction ***
+//NONE, WHITE_LIST, LOCAL_FOLDER_ONLY, PERMISSIONS,
+//UNIX_TRAVESAL_INPUT_VALIDATION, UNIX_TRAVESAL_INPUT_REMOVAL,
+//WINDOWS_TRAVESAL_INPUT_VALIDATION, WINDOWS_TRAVESAL_INPUT_REMOVAL,
+//SLASH_INPUT_VALIDATION, SLASH_INPUT_REMOVAL,
+//BACKSLASH_INPUT_VALIDATION, BACKSLASH_INPUT_REMOVAL,
+FileAccessRestriction accessRestriction = FileAccessRestriction.NONE;
+
+//** Set Default Input Format ***
+//FULL_PATH_INPUT, RELATIVE_INPUT, INVALID_INPUT, EMPTY_INPUT
+DefaultInputType defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX;
+
+//set path requirement
+//ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+//FTP_DIRECTIVE, HTTP_DIRECTIVE,
+PrefixRequirement prefixRequired = PrefixRequirement.ANY;
+
+//*** set OS simulation (unix default) ***
+//WINDOWS, UNIX
+OsType osSimulated = OsType.ANY;
+
+//*** Set Default Response Type ***
+//ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ResponseType invalidResponseType = ResponseType.ERROR_200;
+
+//*** Set Default Content Type ***
+//CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+String validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+//*** Set Default Prefix String ***
+String prefix = ""; //"",[cmd.exe /c ] [command]
+//*** Set Default Prefix String ***
+String postfix = ""; //"",|[command] &[command] >>[command] >[command] <[command] <[command]
+
+//obtain deliminters and path information
+String fileDelimiter = System.getProperty("file.separator");
+String lineDelimiter = System.getProperty("line.separator");
+
+//Initial Path/URL:
+String DefaultInitialPath = ""; //Empty
+//Current User Directory File Object
+File directory = new File (".");
+//User Directory Path - Absolute
+String userPath = System.getProperty("user.dir");
+///Deployement Path Root - Absolute
+String documentRootPath =
+ getServletConfig().getServletContext().getRealPath("");
+//Relative path of current file - Absolute
+String currentFilePath = request.getRealPath(request.getServletPath());
+//Relative path of current directory - Absolute - No Final Line Delimiter
+String currentDirPath = request.getRealPath(
+ (request.getServletPath()).split("/Case")[0]);
+//Web Path of Root - Relative
+String contextPath = this.getServletContext().getContextPath();
+//Web Path of File - Relative and *NOT* including ROOT (!)
+String contextPathFile = request.getServletPath();
+//Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!)
+String contextRelativeDirPath = (request.getServletPath()).split("/Case")[0];
+
+if (debugMode == true) {
+ String BR = "
";
+ String FontStart = "";
+ String FontEnd = "";
+
+ System.out.println ("File delimiter: " + fileDelimiter);
+ out.println (FontStart + "File delimiter: " + FontEnd + fileDelimiter + BR);
+ System.out.println ("Line delimiter (encoded):" + HtmlEncoder.htmlEncode(lineDelimiter));
+ out.println (FontStart + "Line delimiter (encoded): " + FontEnd
+ + HtmlEncoder.htmlEncode(HtmlEncoder.htmlEncode(lineDelimiter)) + BR);
+
+ //User Directory Path - Absolute
+ System.out.println ("User Directory Path (Absolute): " + userPath);
+ out.println (FontStart + "User Directory Path (Absolute): " + FontEnd + userPath + BR);
+ ///Deployement Path Root - Absolute
+ System.out.println ("Deployment Path Root (Absolute): " + documentRootPath);
+ out.println (FontStart + "Deployment Path Root (Absolute): " + FontEnd + documentRootPath + BR);
+ //Relative path of current file - Absolute
+ System.out.println ("Deployment Path Current File (Absolute): " + currentFilePath);
+ out.println (FontStart + "Deployment Path Current File (Absolute): " + FontEnd + currentFilePath + BR);
+ //Relative path of current directory - Absolute
+ System.out.println ("Deployment Path Current Directory (Absolute): " + currentDirPath);
+ out.println (FontStart + "Deployment Path Current Directory (Absolute): " + FontEnd + currentDirPath + BR);
+ //Web Path of Root - Relative
+ System.out.println ("Web Path Root (Relative): " + contextPath);
+ out.println (FontStart + "Web Path Root (Relative): " + FontEnd + contextPath + BR);
+ //Web Path of File - Relative and *NOT* including ROOT (!)
+ System.out.println ("Web Path of File (Relative-no-root): " + contextPathFile);
+ out.println (FontStart + "Web Path of File (Relative-no-root): " + FontEnd + contextPathFile + BR);
+ //Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!)
+ System.out.println ("Web Path of Dir (Relative-no-root): " + contextRelativeDirPath);
+ out.println (FontStart + "Web Path of Dir (Relative-no-root): " + FontEnd + contextRelativeDirPath + BR);
+ //Full URL:
+ System.out.println("request URL: " + request.getRequestURL());
+ out.println(FontStart + "request URL: " + FontEnd + request.getRequestURL() + BR);
+
+ //System.out.println(request.getRealPath("/"));
+
+ try {
+ System.out.println ("Current directory's canonical path: "
+ + directory.getCanonicalPath());
+ out.println (FontStart + "Current directory's canonical path: "
+ + FontEnd + directory.getCanonicalPath() + BR);
+ System.out.println ("Current directory's absolute path: "
+ + directory.getAbsolutePath());
+ out.println (FontStart + "Current directory's absolute path: "
+ + FontEnd + directory.getAbsolutePath() + BR);
+ } catch(Exception e) {
+ System.out.println("Exceptione is =" + e.getMessage());
+ }
+
+ out.println(BR + BR);
+} // end of debug if
+
+//****ways to get the file ****
+//1)context.getRequestDispatcher("/").forward(request, response);
+//2)File file = new File (currentDirPath + targetFile);
+//3)is = getServletContext().getResourceAsStream(contextRelativeDirPath + targetFile);
+//4)is = new FileInputStream(currentDirPath + targetFile);
+//5)URL url = new URL(URLInitialPath + targetFile);
+// URLConnection urlconn = url.openConnection();
+//6)FORWARD (FP)
+//6)REDIRECT (FP)
+
+%>
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/index.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/index.jsp
new file mode 100644
index 0000000..3c4ea94
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/index.jsp
@@ -0,0 +1,1315 @@
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+Evaluation of OS Command Injection Detection Accuracy - HTTP GET Method
+
+
+
+<%@ include file="include.jsp"%>
+
+<%
+ String defaultFullOsCommandInputWithoutPrefix = null;
+ String defaultFullOsCommandInputWithPrefix = null;
+ String defaultPostfixOsCommandInputWithInitialCommand = null;
+ String defaultPostfixOsCommandInputWithoutInitialCommand = null;
+ String defaultEmptyInput = null;
+ String defaultPartialInput = null;
+ String defaultPostfixValueInput = null;
+ String defaultPostfixCommandInput = null;
+ String defaultInvalidInput = null;
+
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultFullOsCommandInputWithoutPrefix = "dir";
+ defaultFullOsCommandInputWithPrefix = "cmd.exe /c dir";
+
+ defaultPostfixOsCommandInputWithInitialCommand = "findstr Java";
+ defaultPostfixOsCommandInputWithoutInitialCommand = "Java";
+ defaultEmptyInput = "";
+ defaultPartialInput = "eclipse.ini";
+ defaultPostfixValueInput = "Build";
+ defaultPostfixCommandInput = " | findstr Build";
+ defaultInvalidInput = "dfdflkjsh";
+ } else {
+ defaultFullOsCommandInputWithoutPrefix = "ls";
+ defaultFullOsCommandInputWithPrefix = "ls";
+ defaultEmptyInput = "";
+ defaultPartialInput = "eclipse.ini";
+ defaultPostfixValueInput = "Build";
+ defaultPostfixCommandInput = " | grep Build";
+ defaultInvalidInput = "dfdflkjsh";
+ }
+%>
+
+OS Command Injection Test Cases - HTTP 200 Valid Responses:
+
+
+Injection Contexts Covered:
+1) Initial Statement/Command Context: Default OS Command Input with and without prefix:
+ [windows only: cmd.exe /c ]*OS COMMAND INJECTION*
+2) Internal Statement/Command Context: Input integrated in the middle of a fixed OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*[ | postfix-fixed-commands]
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*
+3) Internal Statement/Command Context: Input integrated in postfix section of an OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ][ | postfix-fixed-commands ]*INPUT*
+
+
+
+
+
+ Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (with prefix), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Full OS Command With Prefix |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): cmd.exe /c dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default EMPTY input (invalid), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+ Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default INVALID input (invalid), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (no prefix), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Full OS Command No Prefix |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): | cat /etc/passwd
+ |
+
+
+
+
+
+ Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+ |
+
+
+
+
+
+ Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+ |
+
+
+
+
+ Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Full OS Postfix Command |
+ ANY | Postfix Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Postfix Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Postfix Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Partial OS Postfix Command |
+ ANY | Postfix Statement/Command (After initial postfix command) | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+ |
+
+
+
+
+
+
+ Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Postfix Statement/Command (After initial postfix command) | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+ |
+
+
+
+
+
+
+
+ Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Postfix Statement/Command (After initial postfix command) | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+ |
+
+
+
+
+
+
+ Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default PARTIAL input (filename), using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Partial Command (filename) |
+ ANY | Mid Statement/Command with Fixed Postfix | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent14.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent14.txt
+ |
+
+
+
+
+
+
+ Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default EMPTY input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Mid Statement/Command with Fixed Postfix | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent15.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent15.txt
+ |
+
+
+
+
+
+
+ Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default INVALID input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Mid Statement/Command with Fixed Postfix | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent16.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent16.txt
+ |
+
+
+
+
+
+
+ Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Validation | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent17.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent17.txt
+ |
+
+
+
+
+
+
+ Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Validation | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent18.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent18.txt
+ |
+
+
+
+
+
+
+ Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Validation | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent19.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent19.txt
+ |
+
+
+
+
+
+
+ Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Removal | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent20.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent20.txt
+ |
+
+
+
+
+
+
+ Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Removal | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent21.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent21.txt
+ |
+
+
+
+
+
+
+ Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Removal | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent22.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent22.txt
+ |
+
+
+
+
+
+ Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Validation | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent23.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent23.txt
+ |
+
+
+
+
+
+ Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Validation | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent24.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent24.txt
+ |
+
+
+
+
+
+ Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Validation | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent25.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent25.txt
+ |
+
+
+
+
+
+ Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Removal | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent26.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent26.txt
+ |
+
+
+
+
+
+ Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Removal | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent27.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent27.txt
+ |
+
+
+
+
+
+ Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Removal | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent28.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent28.txt
+ |
+
+
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
new file mode 100644
index 0000000..72f6c7e
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..4b68682
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | ";
+ String linuxPrefix = "cat " + defaultFileName + " | ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
new file mode 100644
index 0000000..f99c538
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr ";
+ String linuxPrefix = "cat " + defaultFileName + " | grep ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..04d12f8
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr ";
+ String linuxPrefix = "cat " + defaultFileName + " | grep ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..5ec94bb
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr ";
+ String linuxPrefix = "cat " + defaultFileName + " | grep ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
new file mode 100644
index 0000000..96fa22a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
@@ -0,0 +1,321 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ String linuxPostfix = "| grep Java";
+ String windowsPostfix = "| findstr Java";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ postfix = windowsPostfix;
+ } else {
+ prefix = linuxPrefix;
+ postfix = linuxPostfix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..da38958
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,321 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ String linuxPostfix = "| grep Java";
+ String windowsPostfix = "| findstr Java";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ postfix = windowsPostfix;
+ } else {
+ prefix = linuxPrefix;
+ postfix = linuxPostfix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..70849cc
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
@@ -0,0 +1,321 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ String linuxPostfix = "| grep Java";
+ String windowsPostfix = "| findstr Java";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ postfix = windowsPostfix;
+ } else {
+ prefix = linuxPrefix;
+ postfix = linuxPostfix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
new file mode 100644
index 0000000..5a774c0
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
new file mode 100644
index 0000000..fe4d7dc
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
new file mode 100644
index 0000000..3a96365
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..89de206
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
new file mode 100644
index 0000000..52ca8d7
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
new file mode 100644
index 0000000..53eca1b
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
new file mode 100644
index 0000000..af5c857
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
new file mode 100644
index 0000000..5b7f33d
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
new file mode 100644
index 0000000..7f73872
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
new file mode 100644
index 0000000..38e2baa
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
new file mode 100644
index 0000000..96ace3a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
new file mode 100644
index 0000000..0ae9ff7
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
new file mode 100644
index 0000000..3873025
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
@@ -0,0 +1,331 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL
+ accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL;
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) {
+ if (InputValidator.validatePipe(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) {
+ input = InputValidator.removePipe(input);
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) {
+ if (InputValidator.validateAmpersand(input)) {
+ inputValidationFailure = true;
+ }
+ } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) {
+ input = InputValidator.removeAmpersand(input);
+ } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..1e25a7c
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
new file mode 100644
index 0000000..75a1365
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c ";
+ String linuxPrefix = "";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "cmd.exe /c dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "dir";
+ } else {
+ defaultInput = "ls";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
new file mode 100644
index 0000000..03e4ffc
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.PARTIAL_COMMAND;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..1e0d95a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
new file mode 100644
index 0000000..42d8494
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
@@ -0,0 +1,317 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.INVALID_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type ";
+ String linuxPrefix = "cat ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "eclipse.ini";
+ } else {
+ defaultInput = "eclipse.ini";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "eclipse.ini";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
new file mode 100644
index 0000000..5d0fa4a
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | ";
+ String linuxPrefix = "cat " + defaultFileName + " | ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
new file mode 100644
index 0000000..b2bb923
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
@@ -0,0 +1,318 @@
+<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
+<%@page import="com.sectooladdict.constants.FileConstants"%>
+<%@page import="com.sectooladdict.validators.InputValidator"%>
+
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+OS Command Injection Test Case
+
+
+
+ <%@ include file="include.jsp"%>
+
+ <%
+ //*** Re-define Default Exposure Variables - Per Page ***
+
+ //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT
+ //COMMAND_POSTFIX,PARTIAL_COMMAND
+ defaultInputType = DefaultInputType.EMPTY_INPUT;
+
+ //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+ //FTP_DIRECTIVE, HTTP_DIRECTIVE,
+ prefixRequired = PrefixRequirement.NONE;
+
+ //WINDOWS, UNIX
+ osSimulated = OsType.ANY;
+
+ //Use the default defined in include.jsp
+ //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ //invalidResponseType = ResponseType.ERROR_200;
+
+ //Use the default defined in include.jsp
+ //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+ //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+ //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL
+ //pathType = PathType.OS_PATH;
+
+ %>
+ <%
+ String defaultFileName = "eclipse.ini";
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+ String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | ";
+ String linuxPrefix = "cat " + defaultFileName + " | ";
+ String osCommand = "";
+ String defaultInput = "";
+ prefix = "";
+ postfix = "";
+ boolean isCommandError = false;
+ %>
+ <%
+ //First set the prefix according to the path type
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ prefix = windowsPrefix;
+ } else {
+ prefix = linuxPrefix;
+ }
+
+ if(debugMode == true) {
+ System.out.println("*****Initial Prefix*****: " + prefix);
+ }
+
+ if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) {
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultInput = "findstr Java";
+ } else {
+ defaultInput = "grep Java";
+ }
+ } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) {
+ if (isWindows) {
+ defaultInput = "Java";
+ } else {
+ defaultInput = "Java";
+ }
+ } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) {
+ //Statement structure: command [input] | postfix command
+ defaultInput = "Java";
+ } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) {
+ //Statement structure: command fixed-value | postfix command [input]
+ defaultInput = "Build"; //keyword in content.ini file for findstr/grep
+ } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) {
+ defaultInput = ""; //intentionally flawd/empty input
+ } else if (defaultInputType == DefaultInputType.INVALID_INPUT) {
+ defaultInput = "fsdfsas"; //intentionally flawd/empty input
+ }
+
+
+ if(debugMode == true) {
+ System.out.println("*****default input*****: " + defaultInput);
+ }
+ %>
+
+ <%
+ if (request.getParameter("target") == null) {
+ %>
+ <%
+ if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) {
+ %>
+
+ Show Log:
+
+
+
+
+ <%
+ } else if (validResposeStream
+ .equals(ContentConstants.CONTENT_TYPE_STREAM)) {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ } else {
+ %>
+
+ Get Content:
+
+
+
+
+ <%
+ }
+ %>
+ <%
+ } else {
+
+ String input = request.getParameter("target");
+
+ boolean inputValidationFailure = false;
+
+ //***************************
+ //* Flawed Input Validation *
+ //***************************
+ //Potential Input Validation / Removal
+ if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateUnixTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator.removeUnixTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) {
+ if (InputValidator.validateWindowsTraversal(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) {
+ input = InputValidator
+ .removeWindowsTraversal(input);
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeSlash(input);
+ System.out.println("alskjalsdkjalsdkjalsdkj file: " + input);
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) {
+ if (InputValidator.validateBackSlash(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) {
+ input = InputValidator.removeBackSlash(input);
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) {
+ if (InputValidator.validateHttp(input)) {
+ inputValidationFailure = true;
+ }
+ } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) {
+ input = InputValidator.removeHttp(input);
+ } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) {
+ if (!(input.equals("content.ini") || input.equals("content")
+ || input.equals("content2.ini") || input.equals("content2")
+ )) {
+ inputValidationFailure = true;
+ }
+ }
+
+ //***********************
+ //* Vulnerability Logic *
+ //***********************
+ BufferedInputStream bis = null;
+
+ try {
+
+ if (inputValidationFailure == true) {
+ throw new Exception("Input Validation Failure");
+ }
+
+
+ if (debugMode == true) {
+ System.out.println("File:" + input);
+ System.out.println("prefix:" + prefix);
+ System.out.println("postfix:" + postfix);
+ System.out.println("Command to run:" + prefix
+ + input + postfix);
+ File f = new File(".");
+ System.out
+ .println("Current Absolute File Path: "
+ + f.getAbsolutePath());
+ System.out
+ .println("Current Canonical Dir Path: "
+ + f.getCanonicalPath());
+ }
+
+ java.lang.Process tempProcess = null;
+ //run the command
+ try {
+ tempProcess = Runtime.getRuntime().exec(prefix + input + postfix);
+ tempProcess.waitFor();
+ } catch (Exception e) {
+ isCommandError = true;
+ }
+
+ if (!isCommandError) {
+
+ //$$$set valid response content type$$$
+ response.setContentType(validResposeStream);
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getInputStream());
+ ServletOutputStream ouputStream = response
+ .getOutputStream();
+ byte byteBuffer[] = new byte[8192];
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ //out.println("
Error Stream:
");
+ bis = new BufferedInputStream(tempProcess.getErrorStream());
+ while (true) {
+ int bytesRead = bis.read(byteBuffer);
+ if (bytesRead < 0)
+ break;
+ ouputStream.write(byteBuffer, 0, bytesRead);
+ }
+
+ ouputStream.flush();
+ ouputStream.close();
+
+ byteBuffer = null;
+
+ } else {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Invalid Input");
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "Content Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Invalid Input");
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ }
+
+ } catch (Exception e) {
+ //set errorneous response content type
+ //response.setContentType(validResposeStream);
+
+ if (invalidResponseType == ResponseType.ERROR_500) {
+ response.sendError(500, "Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.ERROR_404) {
+ response.sendError(404, "File Not Found");
+ } else if (invalidResponseType == ResponseType.REDIRECT_302) {
+ response.sendRedirect("MissingResource.html");
+ } else if (invalidResponseType == ResponseType.ERROR_200) {
+ out.println("Exception details: " + e);
+ } else if (invalidResponseType == ResponseType.VALID_200) {
+ out.println("The information is unavailable at this time.
"
+ + "Please try again later.");
+ } else if (invalidResponseType == ResponseType.IDENTICAL_200) {
+ //return a default empty value (found in the default file)
+ //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) {
+ out.println("'input' is not recognized as an internal or external command, operable program or batch file.");
+ }
+ out.flush();
+ } finally {
+ try {
+ bis.close();
+ } catch(Exception e) {
+ //do nothing
+ }
+ }
+
+ } //end of if/else block
+ %>
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/include.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/include.jsp
new file mode 100644
index 0000000..a357805
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/include.jsp
@@ -0,0 +1,145 @@
+<%@page import="java.io.*" %>
+<%@page import="java.net.*" %>
+<%@page import="com.sectooladdict.encoders.HtmlEncoder" %>
+<%@page import="com.sectooladdict.constants.SystemConstants" %>
+<%@page import="com.sectooladdict.constants.FileConstants" %>
+<%@page import="com.sectooladdict.constants.ContentConstants" %>
+<%@page import="com.sectooladdict.enums.VulnerabilityType" %>
+<%@page import="com.sectooladdict.enums.ResponseType" %>
+<%@page import="com.sectooladdict.enums.DefaultInputType" %>
+<%@page import="com.sectooladdict.enums.FileAccessRestriction" %>
+<%@page import="com.sectooladdict.enums.FileInjectionContext" %>
+<%@page import="com.sectooladdict.enums.PrefixRequirement" %>
+<%@page import="com.sectooladdict.enums.OsType" %>
+
+<%
+//set debug flag from main config
+boolean debugMode = SystemConstants.DEBUG_FLAG_DEFAULT_STATE;
+
+//begin setting group definitions
+//--------------------------------
+
+//** Set File Access Restriction ***
+//NONE, WHITE_LIST, LOCAL_FOLDER_ONLY, PERMISSIONS,
+//UNIX_TRAVESAL_INPUT_VALIDATION, UNIX_TRAVESAL_INPUT_REMOVAL,
+//WINDOWS_TRAVESAL_INPUT_VALIDATION, WINDOWS_TRAVESAL_INPUT_REMOVAL,
+//SLASH_INPUT_VALIDATION, SLASH_INPUT_REMOVAL,
+//BACKSLASH_INPUT_VALIDATION, BACKSLASH_INPUT_REMOVAL,
+FileAccessRestriction accessRestriction = FileAccessRestriction.NONE;
+
+//** Set Default Input Format ***
+//FULL_PATH_INPUT, RELATIVE_INPUT, INVALID_INPUT, EMPTY_INPUT
+DefaultInputType defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX;
+
+//set path requirement
+//ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX,
+//FTP_DIRECTIVE, HTTP_DIRECTIVE,
+PrefixRequirement prefixRequired = PrefixRequirement.ANY;
+
+//*** set OS simulation (unix default) ***
+//WINDOWS, UNIX
+OsType osSimulated = OsType.ANY;
+
+//*** Set Default Response Type ***
+//ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200
+ResponseType invalidResponseType = ResponseType.ERROR_500;
+
+//*** Set Default Content Type ***
+//CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream")
+String validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML;
+
+//*** Set Default Prefix String ***
+String prefix = ""; //"",[cmd.exe /c ] [command]
+//*** Set Default Prefix String ***
+String postfix = ""; //"",|[command] &[command] >>[command] >[command] <[command] <[command]
+
+//obtain deliminters and path information
+String fileDelimiter = System.getProperty("file.separator");
+String lineDelimiter = System.getProperty("line.separator");
+
+//Initial Path/URL:
+String DefaultInitialPath = ""; //Empty
+//Current User Directory File Object
+File directory = new File (".");
+//User Directory Path - Absolute
+String userPath = System.getProperty("user.dir");
+///Deployement Path Root - Absolute
+String documentRootPath =
+ getServletConfig().getServletContext().getRealPath("");
+//Relative path of current file - Absolute
+String currentFilePath = request.getRealPath(request.getServletPath());
+//Relative path of current directory - Absolute - No Final Line Delimiter
+String currentDirPath = request.getRealPath(
+ (request.getServletPath()).split("/Case")[0]);
+//Web Path of Root - Relative
+String contextPath = this.getServletContext().getContextPath();
+//Web Path of File - Relative and *NOT* including ROOT (!)
+String contextPathFile = request.getServletPath();
+//Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!)
+String contextRelativeDirPath = (request.getServletPath()).split("/Case")[0];
+
+if (debugMode == true) {
+ String BR = "
";
+ String FontStart = "";
+ String FontEnd = "";
+
+ System.out.println ("File delimiter: " + fileDelimiter);
+ out.println (FontStart + "File delimiter: " + FontEnd + fileDelimiter + BR);
+ System.out.println ("Line delimiter (encoded):" + HtmlEncoder.htmlEncode(lineDelimiter));
+ out.println (FontStart + "Line delimiter (encoded): " + FontEnd
+ + HtmlEncoder.htmlEncode(HtmlEncoder.htmlEncode(lineDelimiter)) + BR);
+
+ //User Directory Path - Absolute
+ System.out.println ("User Directory Path (Absolute): " + userPath);
+ out.println (FontStart + "User Directory Path (Absolute): " + FontEnd + userPath + BR);
+ ///Deployement Path Root - Absolute
+ System.out.println ("Deployment Path Root (Absolute): " + documentRootPath);
+ out.println (FontStart + "Deployment Path Root (Absolute): " + FontEnd + documentRootPath + BR);
+ //Relative path of current file - Absolute
+ System.out.println ("Deployment Path Current File (Absolute): " + currentFilePath);
+ out.println (FontStart + "Deployment Path Current File (Absolute): " + FontEnd + currentFilePath + BR);
+ //Relative path of current directory - Absolute
+ System.out.println ("Deployment Path Current Directory (Absolute): " + currentDirPath);
+ out.println (FontStart + "Deployment Path Current Directory (Absolute): " + FontEnd + currentDirPath + BR);
+ //Web Path of Root - Relative
+ System.out.println ("Web Path Root (Relative): " + contextPath);
+ out.println (FontStart + "Web Path Root (Relative): " + FontEnd + contextPath + BR);
+ //Web Path of File - Relative and *NOT* including ROOT (!)
+ System.out.println ("Web Path of File (Relative-no-root): " + contextPathFile);
+ out.println (FontStart + "Web Path of File (Relative-no-root): " + FontEnd + contextPathFile + BR);
+ //Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!)
+ System.out.println ("Web Path of Dir (Relative-no-root): " + contextRelativeDirPath);
+ out.println (FontStart + "Web Path of Dir (Relative-no-root): " + FontEnd + contextRelativeDirPath + BR);
+ //Full URL:
+ System.out.println("request URL: " + request.getRequestURL());
+ out.println(FontStart + "request URL: " + FontEnd + request.getRequestURL() + BR);
+
+ //System.out.println(request.getRealPath("/"));
+
+ try {
+ System.out.println ("Current directory's canonical path: "
+ + directory.getCanonicalPath());
+ out.println (FontStart + "Current directory's canonical path: "
+ + FontEnd + directory.getCanonicalPath() + BR);
+ System.out.println ("Current directory's absolute path: "
+ + directory.getAbsolutePath());
+ out.println (FontStart + "Current directory's absolute path: "
+ + FontEnd + directory.getAbsolutePath() + BR);
+ } catch(Exception e) {
+ System.out.println("Exceptione is =" + e.getMessage());
+ }
+
+ out.println(BR + BR);
+} // end of debug if
+
+//****ways to get the file ****
+//1)context.getRequestDispatcher("/").forward(request, response);
+//2)File file = new File (currentDirPath + targetFile);
+//3)is = getServletContext().getResourceAsStream(contextRelativeDirPath + targetFile);
+//4)is = new FileInputStream(currentDirPath + targetFile);
+//5)URL url = new URL(URLInitialPath + targetFile);
+// URLConnection urlconn = url.openConnection();
+//6)FORWARD (FP)
+//6)REDIRECT (FP)
+
+%>
\ No newline at end of file
diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/index.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/index.jsp
new file mode 100644
index 0000000..7f93792
--- /dev/null
+++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/index.jsp
@@ -0,0 +1,1314 @@
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+Evaluation of OS Command Injection Detection Accuracy - HTTP GET Method
+
+
+
+<%@ include file="include.jsp"%>
+
+<%
+ String defaultFullOsCommandInputWithoutPrefix = null;
+ String defaultFullOsCommandInputWithPrefix = null;
+ String defaultPostfixOsCommandInputWithInitialCommand = null;
+ String defaultPostfixOsCommandInputWithoutInitialCommand = null;
+ String defaultEmptyInput = null;
+ String defaultPartialInput = null;
+ String defaultPostfixValueInput = null;
+ String defaultPostfixCommandInput = null;
+ String defaultInvalidInput = null;
+
+
+ boolean isWindows = System.getProperty("os.name").contains("Win");
+
+ if (isWindows) { //If OS Type = Windows Add the cmd prefix
+ defaultFullOsCommandInputWithoutPrefix = "dir";
+ defaultFullOsCommandInputWithPrefix = "cmd.exe /c dir";
+
+ defaultPostfixOsCommandInputWithInitialCommand = "findstr Java";
+ defaultPostfixOsCommandInputWithoutInitialCommand = "Java";
+ defaultEmptyInput = "";
+ defaultPartialInput = "eclipse.ini";
+ defaultPostfixValueInput = "Build";
+ defaultPostfixCommandInput = " | findstr Build";
+ defaultInvalidInput = "dfdflkjsh";
+ } else {
+ defaultFullOsCommandInputWithoutPrefix = "ls";
+ defaultFullOsCommandInputWithPrefix = "ls";
+ defaultEmptyInput = "";
+ defaultPartialInput = "eclipse.ini";
+ defaultPostfixValueInput = "Build";
+ defaultPostfixCommandInput = " | grep Build";
+ defaultInvalidInput = "dfdflkjsh";
+ }
+%>
+
+OS Command Injection Test Cases - HTTP 200 Valid Responses:
+
+
+Injection Contexts Covered:
+1) Initial Statement/Command Context: Default OS Command Input with and without prefix:
+ [windows only: cmd.exe /c ]*OS COMMAND INJECTION*
+2) Internal Statement/Command Context: Input integrated in the middle of a fixed OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*[ | postfix-fixed-commands]
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*
+3) Internal Statement/Command Context: Input integrated in postfix section of an OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ][ | postfix-fixed-commands ]*INPUT*
+
+
+
+
+
+ Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (with prefix), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Full OS Command With Prefix |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): cmd.exe /c dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default EMPTY input (invalid), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+ Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default INVALID input (invalid), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (no prefix), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Full OS Command No Prefix |
+ ANY | Initial Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): | cat /etc/passwd
+ |
+
+
+
+
+
+ Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+ |
+
+
+
+
+
+ Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+ |
+
+
+
+
+ Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Full OS Postfix Command |
+ ANY | Postfix Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Postfix Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Postfix Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+ |
+
+
+
+
+
+ Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Partial OS Postfix Command |
+ ANY | Postfix Statement/Command (After initial postfix command) | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+ |
+
+
+
+
+
+
+ Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Postfix Statement/Command (After initial postfix command) | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+ |
+
+
+
+
+
+
+
+ Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Postfix Statement/Command (After initial postfix command) | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+ |
+
+
+
+
+
+
+ Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default PARTIAL input (filename), using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Partial Command (filename) |
+ ANY | Mid Statement/Command with Fixed Postfix | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent14.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent14.txt
+ |
+
+
+
+
+
+
+ Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default EMPTY input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Empty Input |
+ ANY | Mid Statement/Command with Fixed Postfix | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent15.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent15.txt
+ |
+
+
+
+
+
+
+ Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default INVALID input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | None | Invalid Input |
+ ANY | Mid Statement/Command with Fixed Postfix | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent16.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent16.txt
+ |
+
+
+
+
+
+
+ Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Validation | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent17.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent17.txt
+ |
+
+
+
+
+
+
+ Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Validation | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent18.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent18.txt
+ |
+
+
+
+
+
+
+ Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Validation | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent19.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent19.txt
+ |
+
+
+
+
+
+
+ Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Removal | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent20.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent20.txt
+ |
+
+
+
+
+
+
+ Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Removal | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent21.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent21.txt
+ |
+
+
+
+
+
+
+ Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Pipe Input Removal | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent22.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent22.txt
+ |
+
+
+
+
+
+ Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Validation | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent23.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent23.txt
+ |
+
+
+
+
+
+ Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Validation | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent24.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent24.txt
+ |
+
+
+
+
+
+ Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input validation.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Validation | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent25.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent25.txt
+ |
+
+
+
+
+
+ Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Removal | Partial Command (filename) |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent26.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent26.txt
+ |
+
+
+
+
+
+ Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Removal | Empty Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent27.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent27.txt
+ |
+
+
+
+
+
+ Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input removal.
+
+
+
+ | OS Access Method: | Barriers:
|
+ Default Input: | OS Type: |
+ Injection Context: | Prefix Requirement: |
+ Valid Response Stream: |
+
+
+ | Runtime.getRuntime().exec("[injection]").waitFor() | Ampersand Input Removal | Invalid Input |
+ ANY | Mid-End Statement/Command | None |
+ Text/Html |
+
+
+
+ |
+ Sample Detection Structures:
+ |
+
+ [os-command](success) or
+ [time-delay os-command] (success) vs.
+ [invalid OS command] (failure)
+ |
+ |
+ Sample Exploit Structures:
+ |
+
+ Windows/Linux: [command][attacker host OR sensitive content]
+ |
+ |
+ Examples of Exploits:
+ |
+
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent28.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent28.txt
+ |
+
+
+
+
\ No newline at end of file
diff --git a/WebContent/active/index-main.jsp b/WebContent/active/index-main.jsp
index aeeefc6..745d69d 100644
--- a/WebContent/active/index-main.jsp
+++ b/WebContent/active/index-main.jsp
@@ -16,6 +16,7 @@ Pages in this section should only contain vulnerabilities detectable by passive
Remote File Inclusion
Unvalidated Redirect
False Positive Test Cases
+OS Command Injection Test Cases
+
+OS Command Injection - Test Cases:
+
+
GET Input Vector, Text/HTML Valid Response Stream
+Evaluation of OS Command Injection Detection Accuracy - GET - Erroneous HTTP 200 Responses
+Evaluation of OS Command Injection Detection Accuracy - GET - Erroneous HTTP 500 Responses
+
+
POST Input Vector, Text/HTML Valid Response Stream
+Evaluation of OS Command Injection Detection Accuracy - POST - HTTP 200 Errors
+Evaluation of OS Command Injection Detection Accuracy - POST - Erroneous HTTP 500 Responses
+
+
diff --git a/WebContent/active/index-os-command.jsp b/WebContent/active/index-os-command.jsp
new file mode 100644
index 0000000..5d32560
--- /dev/null
+++ b/WebContent/active/index-os-command.jsp
@@ -0,0 +1,22 @@
+<%@ page language="java" contentType="text/html; charset=ISO-8859-1"
+ pageEncoding="ISO-8859-1"%>
+
+
+
+
+
Evaluation of Web Application Scanners Detection Accuracy
+
+
+