diff --git a/CHANGELOG.md b/CHANGELOG.md index dca4c38..bfb72f1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,9 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/). +## 2025-08-30 +- Imported OS Command Injection tests from [Reinforced Wavsep](https://github.com/luigiurbano/Reinforced-Wavsep) at commit [962d566](https://github.com/luigiurbano/Reinforced-Wavsep/commit/962d566ebe51a3f64f772b6c1856d99f1150ba4a). + ## 2025-08-28 ### Changed diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp new file mode 100644 index 0000000..72f6c7e --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp new file mode 100644 index 0000000..4b68682 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | "; + String linuxPrefix = "cat " + defaultFileName + " | "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp new file mode 100644 index 0000000..f99c538 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr "; + String linuxPrefix = "cat " + defaultFileName + " | grep "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..04d12f8 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr "; + String linuxPrefix = "cat " + defaultFileName + " | grep "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..5ec94bb --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr "; + String linuxPrefix = "cat " + defaultFileName + " | grep "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp new file mode 100644 index 0000000..96fa22a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp @@ -0,0 +1,321 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + String linuxPostfix = "| grep Java"; + String windowsPostfix = "| findstr Java"; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + postfix = windowsPostfix; + } else { + prefix = linuxPrefix; + postfix = linuxPostfix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..da38958 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,321 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + String linuxPostfix = "| grep Java"; + String windowsPostfix = "| findstr Java"; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + postfix = windowsPostfix; + } else { + prefix = linuxPrefix; + postfix = linuxPostfix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..70849cc --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp @@ -0,0 +1,321 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + String linuxPostfix = "| grep Java"; + String windowsPostfix = "| findstr Java"; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + postfix = windowsPostfix; + } else { + prefix = linuxPrefix; + postfix = linuxPostfix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp new file mode 100644 index 0000000..5a774c0 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp new file mode 100644 index 0000000..fe4d7dc --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp new file mode 100644 index 0000000..3a96365 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..89de206 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp new file mode 100644 index 0000000..52ca8d7 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp new file mode 100644 index 0000000..53eca1b --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp new file mode 100644 index 0000000..af5c857 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp new file mode 100644 index 0000000..5b7f33d --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp new file mode 100644 index 0000000..7f73872 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp new file mode 100644 index 0000000..38e2baa --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp new file mode 100644 index 0000000..96ace3a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp new file mode 100644 index 0000000..0ae9ff7 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp new file mode 100644 index 0000000..3873025 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..1e25a7c --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp new file mode 100644 index 0000000..75a1365 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp new file mode 100644 index 0000000..03e4ffc --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..999d694 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + System.out.println(prefix + input + postfix); + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..42d8494 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp new file mode 100644 index 0000000..5d0fa4a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | "; + String linuxPrefix = "cat " + defaultFileName + " | "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp new file mode 100644 index 0000000..b2bb923 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | "; + String linuxPrefix = "cat " + defaultFileName + " | "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/include.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/include.jsp new file mode 100644 index 0000000..2ab7639 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/include.jsp @@ -0,0 +1,145 @@ +<%@page import="java.io.*" %> +<%@page import="java.net.*" %> +<%@page import="com.sectooladdict.encoders.HtmlEncoder" %> +<%@page import="com.sectooladdict.constants.SystemConstants" %> +<%@page import="com.sectooladdict.constants.FileConstants" %> +<%@page import="com.sectooladdict.constants.ContentConstants" %> +<%@page import="com.sectooladdict.enums.VulnerabilityType" %> +<%@page import="com.sectooladdict.enums.ResponseType" %> +<%@page import="com.sectooladdict.enums.DefaultInputType" %> +<%@page import="com.sectooladdict.enums.FileAccessRestriction" %> +<%@page import="com.sectooladdict.enums.FileInjectionContext" %> +<%@page import="com.sectooladdict.enums.PrefixRequirement" %> +<%@page import="com.sectooladdict.enums.OsType" %> + +<% +//set debug flag from main config +boolean debugMode = SystemConstants.DEBUG_FLAG_DEFAULT_STATE; + +//begin setting group definitions +//-------------------------------- + +//** Set File Access Restriction *** +//NONE, WHITE_LIST, LOCAL_FOLDER_ONLY, PERMISSIONS, +//UNIX_TRAVESAL_INPUT_VALIDATION, UNIX_TRAVESAL_INPUT_REMOVAL, +//WINDOWS_TRAVESAL_INPUT_VALIDATION, WINDOWS_TRAVESAL_INPUT_REMOVAL, +//SLASH_INPUT_VALIDATION, SLASH_INPUT_REMOVAL, +//BACKSLASH_INPUT_VALIDATION, BACKSLASH_INPUT_REMOVAL, +FileAccessRestriction accessRestriction = FileAccessRestriction.NONE; + +//** Set Default Input Format *** +//FULL_PATH_INPUT, RELATIVE_INPUT, INVALID_INPUT, EMPTY_INPUT +DefaultInputType defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX; + +//set path requirement +//ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, +//FTP_DIRECTIVE, HTTP_DIRECTIVE, +PrefixRequirement prefixRequired = PrefixRequirement.ANY; + +//*** set OS simulation (unix default) *** +//WINDOWS, UNIX +OsType osSimulated = OsType.ANY; + +//*** Set Default Response Type *** +//ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 +ResponseType invalidResponseType = ResponseType.ERROR_200; + +//*** Set Default Content Type *** +//CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") +String validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + +//*** Set Default Prefix String *** +String prefix = ""; //"",[cmd.exe /c ] [command] +//*** Set Default Prefix String *** +String postfix = ""; //"",|[command] &[command] >>[command] >[command] <[command] <[command] + +//obtain deliminters and path information +String fileDelimiter = System.getProperty("file.separator"); +String lineDelimiter = System.getProperty("line.separator"); + +//Initial Path/URL: +String DefaultInitialPath = ""; //Empty +//Current User Directory File Object +File directory = new File ("."); +//User Directory Path - Absolute +String userPath = System.getProperty("user.dir"); +///Deployement Path Root - Absolute +String documentRootPath = + getServletConfig().getServletContext().getRealPath(""); +//Relative path of current file - Absolute +String currentFilePath = request.getRealPath(request.getServletPath()); +//Relative path of current directory - Absolute - No Final Line Delimiter +String currentDirPath = request.getRealPath( + (request.getServletPath()).split("/Case")[0]); +//Web Path of Root - Relative +String contextPath = this.getServletContext().getContextPath(); +//Web Path of File - Relative and *NOT* including ROOT (!) +String contextPathFile = request.getServletPath(); +//Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!) +String contextRelativeDirPath = (request.getServletPath()).split("/Case")[0]; + +if (debugMode == true) { + String BR = "
"; + String FontStart = ""; + String FontEnd = ""; + + System.out.println ("File delimiter: " + fileDelimiter); + out.println (FontStart + "File delimiter: " + FontEnd + fileDelimiter + BR); + System.out.println ("Line delimiter (encoded):" + HtmlEncoder.htmlEncode(lineDelimiter)); + out.println (FontStart + "Line delimiter (encoded): " + FontEnd + + HtmlEncoder.htmlEncode(HtmlEncoder.htmlEncode(lineDelimiter)) + BR); + + //User Directory Path - Absolute + System.out.println ("User Directory Path (Absolute): " + userPath); + out.println (FontStart + "User Directory Path (Absolute): " + FontEnd + userPath + BR); + ///Deployement Path Root - Absolute + System.out.println ("Deployment Path Root (Absolute): " + documentRootPath); + out.println (FontStart + "Deployment Path Root (Absolute): " + FontEnd + documentRootPath + BR); + //Relative path of current file - Absolute + System.out.println ("Deployment Path Current File (Absolute): " + currentFilePath); + out.println (FontStart + "Deployment Path Current File (Absolute): " + FontEnd + currentFilePath + BR); + //Relative path of current directory - Absolute + System.out.println ("Deployment Path Current Directory (Absolute): " + currentDirPath); + out.println (FontStart + "Deployment Path Current Directory (Absolute): " + FontEnd + currentDirPath + BR); + //Web Path of Root - Relative + System.out.println ("Web Path Root (Relative): " + contextPath); + out.println (FontStart + "Web Path Root (Relative): " + FontEnd + contextPath + BR); + //Web Path of File - Relative and *NOT* including ROOT (!) + System.out.println ("Web Path of File (Relative-no-root): " + contextPathFile); + out.println (FontStart + "Web Path of File (Relative-no-root): " + FontEnd + contextPathFile + BR); + //Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!) + System.out.println ("Web Path of Dir (Relative-no-root): " + contextRelativeDirPath); + out.println (FontStart + "Web Path of Dir (Relative-no-root): " + FontEnd + contextRelativeDirPath + BR); + //Full URL: + System.out.println("request URL: " + request.getRequestURL()); + out.println(FontStart + "request URL: " + FontEnd + request.getRequestURL() + BR); + + //System.out.println(request.getRealPath("/")); + + try { + System.out.println ("Current directory's canonical path: " + + directory.getCanonicalPath()); + out.println (FontStart + "Current directory's canonical path: " + + FontEnd + directory.getCanonicalPath() + BR); + System.out.println ("Current directory's absolute path: " + + directory.getAbsolutePath()); + out.println (FontStart + "Current directory's absolute path: " + + FontEnd + directory.getAbsolutePath() + BR); + } catch(Exception e) { + System.out.println("Exceptione is =" + e.getMessage()); + } + + out.println(BR + BR); +} // end of debug if + +//****ways to get the file **** +//1)context.getRequestDispatcher("/").forward(request, response); +//2)File file = new File (currentDirPath + targetFile); +//3)is = getServletContext().getResourceAsStream(contextRelativeDirPath + targetFile); +//4)is = new FileInputStream(currentDirPath + targetFile); +//5)URL url = new URL(URLInitialPath + targetFile); +// URLConnection urlconn = url.openConnection(); +//6)FORWARD (FP) +//6)REDIRECT (FP) + +%> \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/index.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/index.jsp new file mode 100644 index 0000000..6542362 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-200Error/index.jsp @@ -0,0 +1,1315 @@ +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +Evaluation of OS Command Injection Detection Accuracy - HTTP GET Method + + + +<%@ include file="include.jsp"%> + +<% + String defaultFullOsCommandInputWithoutPrefix = null; + String defaultFullOsCommandInputWithPrefix = null; + String defaultPostfixOsCommandInputWithInitialCommand = null; + String defaultPostfixOsCommandInputWithoutInitialCommand = null; + String defaultEmptyInput = null; + String defaultPartialInput = null; + String defaultPostfixValueInput = null; + String defaultPostfixCommandInput = null; + String defaultInvalidInput = null; + + + boolean isWindows = System.getProperty("os.name").contains("Win"); + + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultFullOsCommandInputWithoutPrefix = "dir"; + defaultFullOsCommandInputWithPrefix = "cmd.exe /c dir"; + + defaultPostfixOsCommandInputWithInitialCommand = "findstr Java"; + defaultPostfixOsCommandInputWithoutInitialCommand = "Java"; + defaultEmptyInput = ""; + defaultPartialInput = "eclipse.ini"; + defaultPostfixValueInput = "Build"; + defaultPostfixCommandInput = " | findstr Build"; + defaultInvalidInput = "dfdflkjsh"; + } else { + defaultFullOsCommandInputWithoutPrefix = "ls"; + defaultFullOsCommandInputWithPrefix = "ls"; + defaultEmptyInput = ""; + defaultPartialInput = "eclipse.ini"; + defaultPostfixValueInput = "Build"; + defaultPostfixCommandInput = " | grep Build"; + defaultInvalidInput = "dfdflkjsh"; + } +%> + +
OS Command Injection Test Cases - HTTP 200 Valid Responses:


+ +
+Injection Contexts Covered:
+1) Initial Statement/Command Context: Default OS Command Input with and without prefix:
+ [windows only: cmd.exe /c ]*OS COMMAND INJECTION*
+2) Internal Statement/Command Context: Input integrated in the middle of a fixed OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*[ | postfix-fixed-commands]
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*
+3) Internal Statement/Command Context: Input integrated in postfix section of an OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ][ | postfix-fixed-commands ]*INPUT*
+
+
+
+ + + Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (with prefix), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneFull OS Command With PrefixANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): cmd.exe /c dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default EMPTY input (invalid), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default INVALID input (invalid), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (no prefix), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneFull OS Command No PrefixANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NonePartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): | cat /etc/passwd
+
+
+ + + + Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+
+
+ + + + Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+
+
+ + + Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneFull OS Postfix CommandANYPostfix Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYPostfix Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYPostfix Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NonePartial OS Postfix CommandANYPostfix Statement/Command (After initial postfix command)NoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+
+
+ + + + + Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYPostfix Statement/Command (After initial postfix command)NoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+
+
+ + + + + + Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYPostfix Statement/Command (After initial postfix command)NoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+
+
+ + + + + Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default PARTIAL input (filename), using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NonePartial Command (filename)ANYMid Statement/Command with Fixed PostfixNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent14.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent14.txt
+
+
+ + + + + Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default EMPTY input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYMid Statement/Command with Fixed PostfixNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent15.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent15.txt
+
+
+ + + + + Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default INVALID input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYMid Statement/Command with Fixed PostfixNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent16.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent16.txt
+
+
+ + + + + Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input ValidationPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent17.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent17.txt
+
+
+ + + + + Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input ValidationEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent18.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent18.txt
+
+
+ + + + + Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input ValidationInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent19.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent19.txt
+
+
+ + + + + Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input RemovalPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent20.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent20.txt
+
+
+ + + + + Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input RemovalEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent21.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent21.txt
+
+
+ + + + + Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input RemovalInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent22.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent22.txt
+
+
+ + + + Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input ValidationPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent23.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent23.txt
+
+
+ + + + Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input ValidationEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent24.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent24.txt
+
+
+ + + + Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input ValidationInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent25.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent25.txt
+
+
+ + + + Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input RemovalPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent26.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent26.txt
+
+
+ + + + Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input RemovalEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent27.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent27.txt
+
+
+ + + + Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input RemovalInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent28.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent28.txt
+
+
+ + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp new file mode 100644 index 0000000..72f6c7e --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp new file mode 100644 index 0000000..4b68682 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | "; + String linuxPrefix = "cat " + defaultFileName + " | "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp new file mode 100644 index 0000000..f99c538 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr "; + String linuxPrefix = "cat " + defaultFileName + " | grep "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..04d12f8 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr "; + String linuxPrefix = "cat " + defaultFileName + " | grep "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..5ec94bb --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr "; + String linuxPrefix = "cat " + defaultFileName + " | grep "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp new file mode 100644 index 0000000..96fa22a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp @@ -0,0 +1,321 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + String linuxPostfix = "| grep Java"; + String windowsPostfix = "| findstr Java"; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + postfix = windowsPostfix; + } else { + prefix = linuxPrefix; + postfix = linuxPostfix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..da38958 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,321 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + String linuxPostfix = "| grep Java"; + String windowsPostfix = "| findstr Java"; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + postfix = windowsPostfix; + } else { + prefix = linuxPrefix; + postfix = linuxPostfix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..70849cc --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp @@ -0,0 +1,321 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + String linuxPostfix = "| grep Java"; + String windowsPostfix = "| findstr Java"; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + postfix = windowsPostfix; + } else { + prefix = linuxPrefix; + postfix = linuxPostfix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp new file mode 100644 index 0000000..5a774c0 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp new file mode 100644 index 0000000..fe4d7dc --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp new file mode 100644 index 0000000..3a96365 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..89de206 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp new file mode 100644 index 0000000..52ca8d7 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp new file mode 100644 index 0000000..53eca1b --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp new file mode 100644 index 0000000..af5c857 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp new file mode 100644 index 0000000..5b7f33d --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp new file mode 100644 index 0000000..7f73872 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp new file mode 100644 index 0000000..38e2baa --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp new file mode 100644 index 0000000..96ace3a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp new file mode 100644 index 0000000..0ae9ff7 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp new file mode 100644 index 0000000..3873025 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..1e25a7c --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp new file mode 100644 index 0000000..75a1365 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp new file mode 100644 index 0000000..03e4ffc --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..1e0d95a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..42d8494 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp new file mode 100644 index 0000000..5d0fa4a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | "; + String linuxPrefix = "cat " + defaultFileName + " | "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp new file mode 100644 index 0000000..b2bb923 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | "; + String linuxPrefix = "cat " + defaultFileName + " | "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/include.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/include.jsp new file mode 100644 index 0000000..a357805 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/include.jsp @@ -0,0 +1,145 @@ +<%@page import="java.io.*" %> +<%@page import="java.net.*" %> +<%@page import="com.sectooladdict.encoders.HtmlEncoder" %> +<%@page import="com.sectooladdict.constants.SystemConstants" %> +<%@page import="com.sectooladdict.constants.FileConstants" %> +<%@page import="com.sectooladdict.constants.ContentConstants" %> +<%@page import="com.sectooladdict.enums.VulnerabilityType" %> +<%@page import="com.sectooladdict.enums.ResponseType" %> +<%@page import="com.sectooladdict.enums.DefaultInputType" %> +<%@page import="com.sectooladdict.enums.FileAccessRestriction" %> +<%@page import="com.sectooladdict.enums.FileInjectionContext" %> +<%@page import="com.sectooladdict.enums.PrefixRequirement" %> +<%@page import="com.sectooladdict.enums.OsType" %> + +<% +//set debug flag from main config +boolean debugMode = SystemConstants.DEBUG_FLAG_DEFAULT_STATE; + +//begin setting group definitions +//-------------------------------- + +//** Set File Access Restriction *** +//NONE, WHITE_LIST, LOCAL_FOLDER_ONLY, PERMISSIONS, +//UNIX_TRAVESAL_INPUT_VALIDATION, UNIX_TRAVESAL_INPUT_REMOVAL, +//WINDOWS_TRAVESAL_INPUT_VALIDATION, WINDOWS_TRAVESAL_INPUT_REMOVAL, +//SLASH_INPUT_VALIDATION, SLASH_INPUT_REMOVAL, +//BACKSLASH_INPUT_VALIDATION, BACKSLASH_INPUT_REMOVAL, +FileAccessRestriction accessRestriction = FileAccessRestriction.NONE; + +//** Set Default Input Format *** +//FULL_PATH_INPUT, RELATIVE_INPUT, INVALID_INPUT, EMPTY_INPUT +DefaultInputType defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX; + +//set path requirement +//ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, +//FTP_DIRECTIVE, HTTP_DIRECTIVE, +PrefixRequirement prefixRequired = PrefixRequirement.ANY; + +//*** set OS simulation (unix default) *** +//WINDOWS, UNIX +OsType osSimulated = OsType.ANY; + +//*** Set Default Response Type *** +//ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 +ResponseType invalidResponseType = ResponseType.ERROR_500; + +//*** Set Default Content Type *** +//CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") +String validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + +//*** Set Default Prefix String *** +String prefix = ""; //"",[cmd.exe /c ] [command] +//*** Set Default Prefix String *** +String postfix = ""; //"",|[command] &[command] >>[command] >[command] <[command] <[command] + +//obtain deliminters and path information +String fileDelimiter = System.getProperty("file.separator"); +String lineDelimiter = System.getProperty("line.separator"); + +//Initial Path/URL: +String DefaultInitialPath = ""; //Empty +//Current User Directory File Object +File directory = new File ("."); +//User Directory Path - Absolute +String userPath = System.getProperty("user.dir"); +///Deployement Path Root - Absolute +String documentRootPath = + getServletConfig().getServletContext().getRealPath(""); +//Relative path of current file - Absolute +String currentFilePath = request.getRealPath(request.getServletPath()); +//Relative path of current directory - Absolute - No Final Line Delimiter +String currentDirPath = request.getRealPath( + (request.getServletPath()).split("/Case")[0]); +//Web Path of Root - Relative +String contextPath = this.getServletContext().getContextPath(); +//Web Path of File - Relative and *NOT* including ROOT (!) +String contextPathFile = request.getServletPath(); +//Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!) +String contextRelativeDirPath = (request.getServletPath()).split("/Case")[0]; + +if (debugMode == true) { + String BR = "
"; + String FontStart = ""; + String FontEnd = ""; + + System.out.println ("File delimiter: " + fileDelimiter); + out.println (FontStart + "File delimiter: " + FontEnd + fileDelimiter + BR); + System.out.println ("Line delimiter (encoded):" + HtmlEncoder.htmlEncode(lineDelimiter)); + out.println (FontStart + "Line delimiter (encoded): " + FontEnd + + HtmlEncoder.htmlEncode(HtmlEncoder.htmlEncode(lineDelimiter)) + BR); + + //User Directory Path - Absolute + System.out.println ("User Directory Path (Absolute): " + userPath); + out.println (FontStart + "User Directory Path (Absolute): " + FontEnd + userPath + BR); + ///Deployement Path Root - Absolute + System.out.println ("Deployment Path Root (Absolute): " + documentRootPath); + out.println (FontStart + "Deployment Path Root (Absolute): " + FontEnd + documentRootPath + BR); + //Relative path of current file - Absolute + System.out.println ("Deployment Path Current File (Absolute): " + currentFilePath); + out.println (FontStart + "Deployment Path Current File (Absolute): " + FontEnd + currentFilePath + BR); + //Relative path of current directory - Absolute + System.out.println ("Deployment Path Current Directory (Absolute): " + currentDirPath); + out.println (FontStart + "Deployment Path Current Directory (Absolute): " + FontEnd + currentDirPath + BR); + //Web Path of Root - Relative + System.out.println ("Web Path Root (Relative): " + contextPath); + out.println (FontStart + "Web Path Root (Relative): " + FontEnd + contextPath + BR); + //Web Path of File - Relative and *NOT* including ROOT (!) + System.out.println ("Web Path of File (Relative-no-root): " + contextPathFile); + out.println (FontStart + "Web Path of File (Relative-no-root): " + FontEnd + contextPathFile + BR); + //Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!) + System.out.println ("Web Path of Dir (Relative-no-root): " + contextRelativeDirPath); + out.println (FontStart + "Web Path of Dir (Relative-no-root): " + FontEnd + contextRelativeDirPath + BR); + //Full URL: + System.out.println("request URL: " + request.getRequestURL()); + out.println(FontStart + "request URL: " + FontEnd + request.getRequestURL() + BR); + + //System.out.println(request.getRealPath("/")); + + try { + System.out.println ("Current directory's canonical path: " + + directory.getCanonicalPath()); + out.println (FontStart + "Current directory's canonical path: " + + FontEnd + directory.getCanonicalPath() + BR); + System.out.println ("Current directory's absolute path: " + + directory.getAbsolutePath()); + out.println (FontStart + "Current directory's absolute path: " + + FontEnd + directory.getAbsolutePath() + BR); + } catch(Exception e) { + System.out.println("Exceptione is =" + e.getMessage()); + } + + out.println(BR + BR); +} // end of debug if + +//****ways to get the file **** +//1)context.getRequestDispatcher("/").forward(request, response); +//2)File file = new File (currentDirPath + targetFile); +//3)is = getServletContext().getResourceAsStream(contextRelativeDirPath + targetFile); +//4)is = new FileInputStream(currentDirPath + targetFile); +//5)URL url = new URL(URLInitialPath + targetFile); +// URLConnection urlconn = url.openConnection(); +//6)FORWARD (FP) +//6)REDIRECT (FP) + +%> \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/index.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/index.jsp new file mode 100644 index 0000000..a8ada8a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-GET-500Error/index.jsp @@ -0,0 +1,1315 @@ +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +Evaluation of OS Command Injection Detection Accuracy - HTTP GET Method + + + +<%@ include file="include.jsp"%> + +<% + String defaultFullOsCommandInputWithoutPrefix = null; + String defaultFullOsCommandInputWithPrefix = null; + String defaultPostfixOsCommandInputWithInitialCommand = null; + String defaultPostfixOsCommandInputWithoutInitialCommand = null; + String defaultEmptyInput = null; + String defaultPartialInput = null; + String defaultPostfixValueInput = null; + String defaultPostfixCommandInput = null; + String defaultInvalidInput = null; + + + boolean isWindows = System.getProperty("os.name").contains("Win"); + + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultFullOsCommandInputWithoutPrefix = "dir"; + defaultFullOsCommandInputWithPrefix = "cmd.exe /c dir"; + + defaultPostfixOsCommandInputWithInitialCommand = "findstr Java"; + defaultPostfixOsCommandInputWithoutInitialCommand = "Java"; + defaultEmptyInput = ""; + defaultPartialInput = "eclipse.ini"; + defaultPostfixValueInput = "Build"; + defaultPostfixCommandInput = " | findstr Build"; + defaultInvalidInput = "dfdflkjsh"; + } else { + defaultFullOsCommandInputWithoutPrefix = "ls"; + defaultFullOsCommandInputWithPrefix = "ls"; + defaultEmptyInput = ""; + defaultPartialInput = "eclipse.ini"; + defaultPostfixValueInput = "Build"; + defaultPostfixCommandInput = " | grep Build"; + defaultInvalidInput = "dfdflkjsh"; + } +%> + +
OS Command Injection Test Cases - HTTP 200 Valid Responses:


+ +
+Injection Contexts Covered:
+1) Initial Statement/Command Context: Default OS Command Input with and without prefix:
+ [windows only: cmd.exe /c ]*OS COMMAND INJECTION*
+2) Internal Statement/Command Context: Input integrated in the middle of a fixed OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*[ | postfix-fixed-commands]
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*
+3) Internal Statement/Command Context: Input integrated in postfix section of an OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ][ | postfix-fixed-commands ]*INPUT*
+
+
+
+ + + Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (with prefix), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneFull OS Command With PrefixANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): cmd.exe /c dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default EMPTY input (invalid), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default INVALID input (invalid), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (no prefix), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneFull OS Command No PrefixANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NonePartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): | cat /etc/passwd
+
+
+ + + + Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+
+
+ + + + Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+
+
+ + + Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneFull OS Postfix CommandANYPostfix Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYPostfix Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYPostfix Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NonePartial OS Postfix CommandANYPostfix Statement/Command (After initial postfix command)NoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+
+
+ + + + + Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYPostfix Statement/Command (After initial postfix command)NoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+
+
+ + + + + + Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYPostfix Statement/Command (After initial postfix command)NoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+
+
+ + + + + Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default PARTIAL input (filename), using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NonePartial Command (filename)ANYMid Statement/Command with Fixed PostfixNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent14.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent14.txt
+
+
+ + + + + Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default EMPTY input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYMid Statement/Command with Fixed PostfixNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent15.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent15.txt
+
+
+ + + + + Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default INVALID input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYMid Statement/Command with Fixed PostfixNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent16.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent16.txt
+
+
+ + + + + Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input ValidationPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent17.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent17.txt
+
+
+ + + + + Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input ValidationEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent18.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent18.txt
+
+
+ + + + + Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input ValidationInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent19.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent19.txt
+
+
+ + + + + Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input RemovalPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent20.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent20.txt
+
+
+ + + + + Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input RemovalEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent21.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent21.txt
+
+
+ + + + + Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input RemovalInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent22.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent22.txt
+
+
+ + + + Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input ValidationPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent23.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent23.txt
+
+
+ + + + Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input ValidationEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent24.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent24.txt
+
+
+ + + + Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input ValidationInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent25.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent25.txt
+
+
+ + + + Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input RemovalPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent26.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent26.txt
+
+
+ + + + Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input RemovalEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent27.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent27.txt
+
+
+ + + + Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input RemovalInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent28.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent28.txt
+
+
+ + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp new file mode 100644 index 0000000..72f6c7e --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp new file mode 100644 index 0000000..4b68682 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | "; + String linuxPrefix = "cat " + defaultFileName + " | "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp new file mode 100644 index 0000000..f99c538 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr "; + String linuxPrefix = "cat " + defaultFileName + " | grep "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..04d12f8 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr "; + String linuxPrefix = "cat " + defaultFileName + " | grep "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..5ec94bb --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr "; + String linuxPrefix = "cat " + defaultFileName + " | grep "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp new file mode 100644 index 0000000..96fa22a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp @@ -0,0 +1,321 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + String linuxPostfix = "| grep Java"; + String windowsPostfix = "| findstr Java"; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + postfix = windowsPostfix; + } else { + prefix = linuxPrefix; + postfix = linuxPostfix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..da38958 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,321 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + String linuxPostfix = "| grep Java"; + String windowsPostfix = "| findstr Java"; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + postfix = windowsPostfix; + } else { + prefix = linuxPrefix; + postfix = linuxPostfix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..70849cc --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp @@ -0,0 +1,321 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + String linuxPostfix = "| grep Java"; + String windowsPostfix = "| findstr Java"; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + postfix = windowsPostfix; + } else { + prefix = linuxPrefix; + postfix = linuxPostfix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp new file mode 100644 index 0000000..5a774c0 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp new file mode 100644 index 0000000..fe4d7dc --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp new file mode 100644 index 0000000..3a96365 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..89de206 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp new file mode 100644 index 0000000..52ca8d7 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp new file mode 100644 index 0000000..53eca1b --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp new file mode 100644 index 0000000..af5c857 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp new file mode 100644 index 0000000..5b7f33d --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp new file mode 100644 index 0000000..7f73872 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp new file mode 100644 index 0000000..38e2baa --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp new file mode 100644 index 0000000..96ace3a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp new file mode 100644 index 0000000..0ae9ff7 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp new file mode 100644 index 0000000..3873025 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..1e25a7c --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp new file mode 100644 index 0000000..75a1365 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp new file mode 100644 index 0000000..03e4ffc --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..1e0d95a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..42d8494 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp new file mode 100644 index 0000000..5d0fa4a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | "; + String linuxPrefix = "cat " + defaultFileName + " | "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp new file mode 100644 index 0000000..b2bb923 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | "; + String linuxPrefix = "cat " + defaultFileName + " | "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/include.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/include.jsp new file mode 100644 index 0000000..2ab7639 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/include.jsp @@ -0,0 +1,145 @@ +<%@page import="java.io.*" %> +<%@page import="java.net.*" %> +<%@page import="com.sectooladdict.encoders.HtmlEncoder" %> +<%@page import="com.sectooladdict.constants.SystemConstants" %> +<%@page import="com.sectooladdict.constants.FileConstants" %> +<%@page import="com.sectooladdict.constants.ContentConstants" %> +<%@page import="com.sectooladdict.enums.VulnerabilityType" %> +<%@page import="com.sectooladdict.enums.ResponseType" %> +<%@page import="com.sectooladdict.enums.DefaultInputType" %> +<%@page import="com.sectooladdict.enums.FileAccessRestriction" %> +<%@page import="com.sectooladdict.enums.FileInjectionContext" %> +<%@page import="com.sectooladdict.enums.PrefixRequirement" %> +<%@page import="com.sectooladdict.enums.OsType" %> + +<% +//set debug flag from main config +boolean debugMode = SystemConstants.DEBUG_FLAG_DEFAULT_STATE; + +//begin setting group definitions +//-------------------------------- + +//** Set File Access Restriction *** +//NONE, WHITE_LIST, LOCAL_FOLDER_ONLY, PERMISSIONS, +//UNIX_TRAVESAL_INPUT_VALIDATION, UNIX_TRAVESAL_INPUT_REMOVAL, +//WINDOWS_TRAVESAL_INPUT_VALIDATION, WINDOWS_TRAVESAL_INPUT_REMOVAL, +//SLASH_INPUT_VALIDATION, SLASH_INPUT_REMOVAL, +//BACKSLASH_INPUT_VALIDATION, BACKSLASH_INPUT_REMOVAL, +FileAccessRestriction accessRestriction = FileAccessRestriction.NONE; + +//** Set Default Input Format *** +//FULL_PATH_INPUT, RELATIVE_INPUT, INVALID_INPUT, EMPTY_INPUT +DefaultInputType defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX; + +//set path requirement +//ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, +//FTP_DIRECTIVE, HTTP_DIRECTIVE, +PrefixRequirement prefixRequired = PrefixRequirement.ANY; + +//*** set OS simulation (unix default) *** +//WINDOWS, UNIX +OsType osSimulated = OsType.ANY; + +//*** Set Default Response Type *** +//ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 +ResponseType invalidResponseType = ResponseType.ERROR_200; + +//*** Set Default Content Type *** +//CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") +String validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + +//*** Set Default Prefix String *** +String prefix = ""; //"",[cmd.exe /c ] [command] +//*** Set Default Prefix String *** +String postfix = ""; //"",|[command] &[command] >>[command] >[command] <[command] <[command] + +//obtain deliminters and path information +String fileDelimiter = System.getProperty("file.separator"); +String lineDelimiter = System.getProperty("line.separator"); + +//Initial Path/URL: +String DefaultInitialPath = ""; //Empty +//Current User Directory File Object +File directory = new File ("."); +//User Directory Path - Absolute +String userPath = System.getProperty("user.dir"); +///Deployement Path Root - Absolute +String documentRootPath = + getServletConfig().getServletContext().getRealPath(""); +//Relative path of current file - Absolute +String currentFilePath = request.getRealPath(request.getServletPath()); +//Relative path of current directory - Absolute - No Final Line Delimiter +String currentDirPath = request.getRealPath( + (request.getServletPath()).split("/Case")[0]); +//Web Path of Root - Relative +String contextPath = this.getServletContext().getContextPath(); +//Web Path of File - Relative and *NOT* including ROOT (!) +String contextPathFile = request.getServletPath(); +//Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!) +String contextRelativeDirPath = (request.getServletPath()).split("/Case")[0]; + +if (debugMode == true) { + String BR = "
"; + String FontStart = ""; + String FontEnd = ""; + + System.out.println ("File delimiter: " + fileDelimiter); + out.println (FontStart + "File delimiter: " + FontEnd + fileDelimiter + BR); + System.out.println ("Line delimiter (encoded):" + HtmlEncoder.htmlEncode(lineDelimiter)); + out.println (FontStart + "Line delimiter (encoded): " + FontEnd + + HtmlEncoder.htmlEncode(HtmlEncoder.htmlEncode(lineDelimiter)) + BR); + + //User Directory Path - Absolute + System.out.println ("User Directory Path (Absolute): " + userPath); + out.println (FontStart + "User Directory Path (Absolute): " + FontEnd + userPath + BR); + ///Deployement Path Root - Absolute + System.out.println ("Deployment Path Root (Absolute): " + documentRootPath); + out.println (FontStart + "Deployment Path Root (Absolute): " + FontEnd + documentRootPath + BR); + //Relative path of current file - Absolute + System.out.println ("Deployment Path Current File (Absolute): " + currentFilePath); + out.println (FontStart + "Deployment Path Current File (Absolute): " + FontEnd + currentFilePath + BR); + //Relative path of current directory - Absolute + System.out.println ("Deployment Path Current Directory (Absolute): " + currentDirPath); + out.println (FontStart + "Deployment Path Current Directory (Absolute): " + FontEnd + currentDirPath + BR); + //Web Path of Root - Relative + System.out.println ("Web Path Root (Relative): " + contextPath); + out.println (FontStart + "Web Path Root (Relative): " + FontEnd + contextPath + BR); + //Web Path of File - Relative and *NOT* including ROOT (!) + System.out.println ("Web Path of File (Relative-no-root): " + contextPathFile); + out.println (FontStart + "Web Path of File (Relative-no-root): " + FontEnd + contextPathFile + BR); + //Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!) + System.out.println ("Web Path of Dir (Relative-no-root): " + contextRelativeDirPath); + out.println (FontStart + "Web Path of Dir (Relative-no-root): " + FontEnd + contextRelativeDirPath + BR); + //Full URL: + System.out.println("request URL: " + request.getRequestURL()); + out.println(FontStart + "request URL: " + FontEnd + request.getRequestURL() + BR); + + //System.out.println(request.getRealPath("/")); + + try { + System.out.println ("Current directory's canonical path: " + + directory.getCanonicalPath()); + out.println (FontStart + "Current directory's canonical path: " + + FontEnd + directory.getCanonicalPath() + BR); + System.out.println ("Current directory's absolute path: " + + directory.getAbsolutePath()); + out.println (FontStart + "Current directory's absolute path: " + + FontEnd + directory.getAbsolutePath() + BR); + } catch(Exception e) { + System.out.println("Exceptione is =" + e.getMessage()); + } + + out.println(BR + BR); +} // end of debug if + +//****ways to get the file **** +//1)context.getRequestDispatcher("/").forward(request, response); +//2)File file = new File (currentDirPath + targetFile); +//3)is = getServletContext().getResourceAsStream(contextRelativeDirPath + targetFile); +//4)is = new FileInputStream(currentDirPath + targetFile); +//5)URL url = new URL(URLInitialPath + targetFile); +// URLConnection urlconn = url.openConnection(); +//6)FORWARD (FP) +//6)REDIRECT (FP) + +%> \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/index.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/index.jsp new file mode 100644 index 0000000..3c4ea94 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-200Error/index.jsp @@ -0,0 +1,1315 @@ +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +Evaluation of OS Command Injection Detection Accuracy - HTTP GET Method + + + +<%@ include file="include.jsp"%> + +<% + String defaultFullOsCommandInputWithoutPrefix = null; + String defaultFullOsCommandInputWithPrefix = null; + String defaultPostfixOsCommandInputWithInitialCommand = null; + String defaultPostfixOsCommandInputWithoutInitialCommand = null; + String defaultEmptyInput = null; + String defaultPartialInput = null; + String defaultPostfixValueInput = null; + String defaultPostfixCommandInput = null; + String defaultInvalidInput = null; + + + boolean isWindows = System.getProperty("os.name").contains("Win"); + + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultFullOsCommandInputWithoutPrefix = "dir"; + defaultFullOsCommandInputWithPrefix = "cmd.exe /c dir"; + + defaultPostfixOsCommandInputWithInitialCommand = "findstr Java"; + defaultPostfixOsCommandInputWithoutInitialCommand = "Java"; + defaultEmptyInput = ""; + defaultPartialInput = "eclipse.ini"; + defaultPostfixValueInput = "Build"; + defaultPostfixCommandInput = " | findstr Build"; + defaultInvalidInput = "dfdflkjsh"; + } else { + defaultFullOsCommandInputWithoutPrefix = "ls"; + defaultFullOsCommandInputWithPrefix = "ls"; + defaultEmptyInput = ""; + defaultPartialInput = "eclipse.ini"; + defaultPostfixValueInput = "Build"; + defaultPostfixCommandInput = " | grep Build"; + defaultInvalidInput = "dfdflkjsh"; + } +%> + +
OS Command Injection Test Cases - HTTP 200 Valid Responses:


+ +
+Injection Contexts Covered:
+1) Initial Statement/Command Context: Default OS Command Input with and without prefix:
+ [windows only: cmd.exe /c ]*OS COMMAND INJECTION*
+2) Internal Statement/Command Context: Input integrated in the middle of a fixed OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*[ | postfix-fixed-commands]
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*
+3) Internal Statement/Command Context: Input integrated in postfix section of an OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ][ | postfix-fixed-commands ]*INPUT*
+
+
+
+ + + Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (with prefix), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneFull OS Command With PrefixANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): cmd.exe /c dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default EMPTY input (invalid), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default INVALID input (invalid), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (no prefix), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneFull OS Command No PrefixANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NonePartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): | cat /etc/passwd
+
+
+ + + + Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+
+
+ + + + Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+
+
+ + + Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneFull OS Postfix CommandANYPostfix Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYPostfix Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYPostfix Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NonePartial OS Postfix CommandANYPostfix Statement/Command (After initial postfix command)NoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+
+
+ + + + + Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYPostfix Statement/Command (After initial postfix command)NoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+
+
+ + + + + + Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYPostfix Statement/Command (After initial postfix command)NoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+
+
+ + + + + Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default PARTIAL input (filename), using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NonePartial Command (filename)ANYMid Statement/Command with Fixed PostfixNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent14.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent14.txt
+
+
+ + + + + Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default EMPTY input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYMid Statement/Command with Fixed PostfixNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent15.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent15.txt
+
+
+ + + + + Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default INVALID input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYMid Statement/Command with Fixed PostfixNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent16.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent16.txt
+
+
+ + + + + Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input ValidationPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent17.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent17.txt
+
+
+ + + + + Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input ValidationEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent18.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent18.txt
+
+
+ + + + + Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input ValidationInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent19.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent19.txt
+
+
+ + + + + Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input RemovalPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent20.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent20.txt
+
+
+ + + + + Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input RemovalEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent21.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent21.txt
+
+
+ + + + + Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input RemovalInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent22.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent22.txt
+
+
+ + + + Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input ValidationPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent23.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent23.txt
+
+
+ + + + Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input ValidationEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent24.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent24.txt
+
+
+ + + + Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input ValidationInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent25.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent25.txt
+
+
+ + + + Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input RemovalPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent26.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent26.txt
+
+
+ + + + Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input RemovalEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent27.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent27.txt
+
+
+ + + + Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input RemovalInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent28.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent28.txt
+
+
+ + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp new file mode 100644 index 0000000..72f6c7e --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp new file mode 100644 index 0000000..4b68682 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | "; + String linuxPrefix = "cat " + defaultFileName + " | "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp new file mode 100644 index 0000000..f99c538 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr "; + String linuxPrefix = "cat " + defaultFileName + " | grep "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..04d12f8 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr "; + String linuxPrefix = "cat " + defaultFileName + " | grep "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..5ec94bb --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | findstr "; + String linuxPrefix = "cat " + defaultFileName + " | grep "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp new file mode 100644 index 0000000..96fa22a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp @@ -0,0 +1,321 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + String linuxPostfix = "| grep Java"; + String windowsPostfix = "| findstr Java"; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + postfix = windowsPostfix; + } else { + prefix = linuxPrefix; + postfix = linuxPostfix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..da38958 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,321 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + String linuxPostfix = "| grep Java"; + String windowsPostfix = "| findstr Java"; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + postfix = windowsPostfix; + } else { + prefix = linuxPrefix; + postfix = linuxPostfix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..70849cc --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp @@ -0,0 +1,321 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + String linuxPostfix = "| grep Java"; + String windowsPostfix = "| findstr Java"; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + postfix = windowsPostfix; + } else { + prefix = linuxPrefix; + postfix = linuxPostfix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp new file mode 100644 index 0000000..5a774c0 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp new file mode 100644 index 0000000..fe4d7dc --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp new file mode 100644 index 0000000..3a96365 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..89de206 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp new file mode 100644 index 0000000..52ca8d7 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp new file mode 100644 index 0000000..53eca1b --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp new file mode 100644 index 0000000..af5c857 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.PIPE_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp new file mode 100644 index 0000000..5b7f33d --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp new file mode 100644 index 0000000..7f73872 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp new file mode 100644 index 0000000..38e2baa --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_VALIDATION; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp new file mode 100644 index 0000000..96ace3a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp new file mode 100644 index 0000000..0ae9ff7 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp new file mode 100644 index 0000000..3873025 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp @@ -0,0 +1,331 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //PIPE_INPUT_VALIDATION, PIPE_INPUT_REMOVAL, AMPERSAND_INPUT_VALIDATION, AMPERSAND_INPUT_REMOVAL + accessRestriction = FileAccessRestriction.AMPERSAND_INPUT_REMOVAL; + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if(accessRestriction == FileAccessRestriction.PIPE_INPUT_VALIDATION) { + if (InputValidator.validatePipe(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.PIPE_INPUT_REMOVAL) { + input = InputValidator.removePipe(input); + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_VALIDATION) { + if (InputValidator.validateAmpersand(input)) { + inputValidationFailure = true; + } + } else if(accessRestriction == FileAccessRestriction.AMPERSAND_INPUT_REMOVAL) { + input = InputValidator.removeAmpersand(input); + } else if(accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..1e25a7c --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp new file mode 100644 index 0000000..75a1365 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c "; + String linuxPrefix = ""; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "cmd.exe /c dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "dir"; + } else { + defaultInput = "ls"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp new file mode 100644 index 0000000..03e4ffc --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.PARTIAL_COMMAND; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp new file mode 100644 index 0000000..1e0d95a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp new file mode 100644 index 0000000..42d8494 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp @@ -0,0 +1,317 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.INVALID_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type "; + String linuxPrefix = "cat "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "eclipse.ini"; + } else { + defaultInput = "eclipse.ini"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "eclipse.ini"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp new file mode 100644 index 0000000..5d0fa4a --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | "; + String linuxPrefix = "cat " + defaultFileName + " | "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp new file mode 100644 index 0000000..b2bb923 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp @@ -0,0 +1,318 @@ +<%@page import="com.sectooladdict.enums.VulnerabilityType"%> +<%@page import="com.sectooladdict.constants.FileConstants"%> +<%@page import="com.sectooladdict.validators.InputValidator"%> + +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +OS Command Injection Test Case + + + + <%@ include file="include.jsp"%> + + <% + //*** Re-define Default Exposure Variables - Per Page *** + + //FULL_COMMAND_WITH_OS_PREFIX, FULL_COMMAND_WITHOUT_OS_PREFIX, INVALID_INPUT , EMPTY_INPUT + //COMMAND_POSTFIX,PARTIAL_COMMAND + defaultInputType = DefaultInputType.EMPTY_INPUT; + + //ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, + //FTP_DIRECTIVE, HTTP_DIRECTIVE, + prefixRequired = PrefixRequirement.NONE; + + //WINDOWS, UNIX + osSimulated = OsType.ANY; + + //Use the default defined in include.jsp + //ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 + //invalidResponseType = ResponseType.ERROR_200; + + //Use the default defined in include.jsp + //CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") + //validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + + //OS_PATH, FILE_DIRECTIVE_URL, FTP_URL, HTTP_URL + //pathType = PathType.OS_PATH; + + %> + <% + String defaultFileName = "eclipse.ini"; + + boolean isWindows = System.getProperty("os.name").contains("Win"); + String windowsPrefix = "cmd.exe /c type " + defaultFileName + " | "; + String linuxPrefix = "cat " + defaultFileName + " | "; + String osCommand = ""; + String defaultInput = ""; + prefix = ""; + postfix = ""; + boolean isCommandError = false; + %> + <% + //First set the prefix according to the path type + if (isWindows) { //If OS Type = Windows Add the cmd prefix + prefix = windowsPrefix; + } else { + prefix = linuxPrefix; + } + + if(debugMode == true) { + System.out.println("*****Initial Prefix*****: " + prefix); + } + + if (defaultInputType == DefaultInputType.FULL_COMMAND_WITH_OS_PREFIX) { + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultInput = "findstr Java"; + } else { + defaultInput = "grep Java"; + } + } else if (defaultInputType == DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX) { + if (isWindows) { + defaultInput = "Java"; + } else { + defaultInput = "Java"; + } + } else if (defaultInputType == DefaultInputType.PARTIAL_COMMAND) { + //Statement structure: command [input] | postfix command + defaultInput = "Java"; + } else if (defaultInputType == DefaultInputType.COMMAND_POSTFIX) { + //Statement structure: command fixed-value | postfix command [input] + defaultInput = "Build"; //keyword in content.ini file for findstr/grep + } else if (defaultInputType == DefaultInputType.EMPTY_INPUT) { + defaultInput = ""; //intentionally flawd/empty input + } else if (defaultInputType == DefaultInputType.INVALID_INPUT) { + defaultInput = "fsdfsas"; //intentionally flawd/empty input + } + + + if(debugMode == true) { + System.out.println("*****default input*****: " + defaultInput); + } + %> + + <% + if (request.getParameter("target") == null) { + %> + <% + if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_TEXT_HTML)) { + %> + + Show Log: +
+
+
+
+
+ + <% + } else if (validResposeStream + .equals(ContentConstants.CONTENT_TYPE_STREAM)) { + %> + + Get Content: +
+
+
+
+
+ + <% + } else { + %> + + Get Content: +
+
+
+
+
+ + <% + } + %> + <% + } else { + + String input = request.getParameter("target"); + + boolean inputValidationFailure = false; + + //*************************** + //* Flawed Input Validation * + //*************************** + //Potential Input Validation / Removal + if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateUnixTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.UNIX_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator.removeUnixTraversal(input); + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_VALIDATION) { + if (InputValidator.validateWindowsTraversal(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.WINDOWS_TRAVESAL_INPUT_REMOVAL) { + input = InputValidator + .removeWindowsTraversal(input); + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_VALIDATION) { + if (InputValidator.validateSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.SLASH_INPUT_REMOVAL) { + input = InputValidator.removeSlash(input); + System.out.println("alskjalsdkjalsdkjalsdkj file: " + input); + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_VALIDATION) { + if (InputValidator.validateBackSlash(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.BACKSLASH_INPUT_REMOVAL) { + input = InputValidator.removeBackSlash(input); + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_VALIDATION) { + if (InputValidator.validateHttp(input)) { + inputValidationFailure = true; + } + } else if (accessRestriction == FileAccessRestriction.HTTP_INPUT_REMOVAL) { + input = InputValidator.removeHttp(input); + } else if (accessRestriction == FileAccessRestriction.WHITE_LIST) { + if (!(input.equals("content.ini") || input.equals("content") + || input.equals("content2.ini") || input.equals("content2") + )) { + inputValidationFailure = true; + } + } + + //*********************** + //* Vulnerability Logic * + //*********************** + BufferedInputStream bis = null; + + try { + + if (inputValidationFailure == true) { + throw new Exception("Input Validation Failure"); + } + + + if (debugMode == true) { + System.out.println("File:" + input); + System.out.println("prefix:" + prefix); + System.out.println("postfix:" + postfix); + System.out.println("Command to run:" + prefix + + input + postfix); + File f = new File("."); + System.out + .println("Current Absolute File Path: " + + f.getAbsolutePath()); + System.out + .println("Current Canonical Dir Path: " + + f.getCanonicalPath()); + } + + java.lang.Process tempProcess = null; + //run the command + try { + tempProcess = Runtime.getRuntime().exec(prefix + input + postfix); + tempProcess.waitFor(); + } catch (Exception e) { + isCommandError = true; + } + + if (!isCommandError) { + + //$$$set valid response content type$$$ + response.setContentType(validResposeStream); + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getInputStream()); + ServletOutputStream ouputStream = response + .getOutputStream(); + byte byteBuffer[] = new byte[8192]; + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + //out.println("
Error Stream:
"); + bis = new BufferedInputStream(tempProcess.getErrorStream()); + while (true) { + int bytesRead = bis.read(byteBuffer); + if (bytesRead < 0) + break; + ouputStream.write(byteBuffer, 0, bytesRead); + } + + ouputStream.flush(); + ouputStream.close(); + + byteBuffer = null; + + } else { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Invalid Input"); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "Content Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Invalid Input"); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } + + } catch (Exception e) { + //set errorneous response content type + //response.setContentType(validResposeStream); + + if (invalidResponseType == ResponseType.ERROR_500) { + response.sendError(500, "Exception details: " + e); + } else if (invalidResponseType == ResponseType.ERROR_404) { + response.sendError(404, "File Not Found"); + } else if (invalidResponseType == ResponseType.REDIRECT_302) { + response.sendRedirect("MissingResource.html"); + } else if (invalidResponseType == ResponseType.ERROR_200) { + out.println("Exception details: " + e); + } else if (invalidResponseType == ResponseType.VALID_200) { + out.println("The information is unavailable at this time.
" + + "Please try again later."); + } else if (invalidResponseType == ResponseType.IDENTICAL_200) { + //return a default empty value (found in the default file) + //if(validResposeStream.equals(ContentConstants.CONTENT_TYPE_TEXT_HTML) ) { + out.println("'input' is not recognized as an internal or external command, operable program or batch file."); + } + out.flush(); + } finally { + try { + bis.close(); + } catch(Exception e) { + //do nothing + } + } + + } //end of if/else block + %> + + + \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/include.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/include.jsp new file mode 100644 index 0000000..a357805 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/include.jsp @@ -0,0 +1,145 @@ +<%@page import="java.io.*" %> +<%@page import="java.net.*" %> +<%@page import="com.sectooladdict.encoders.HtmlEncoder" %> +<%@page import="com.sectooladdict.constants.SystemConstants" %> +<%@page import="com.sectooladdict.constants.FileConstants" %> +<%@page import="com.sectooladdict.constants.ContentConstants" %> +<%@page import="com.sectooladdict.enums.VulnerabilityType" %> +<%@page import="com.sectooladdict.enums.ResponseType" %> +<%@page import="com.sectooladdict.enums.DefaultInputType" %> +<%@page import="com.sectooladdict.enums.FileAccessRestriction" %> +<%@page import="com.sectooladdict.enums.FileInjectionContext" %> +<%@page import="com.sectooladdict.enums.PrefixRequirement" %> +<%@page import="com.sectooladdict.enums.OsType" %> + +<% +//set debug flag from main config +boolean debugMode = SystemConstants.DEBUG_FLAG_DEFAULT_STATE; + +//begin setting group definitions +//-------------------------------- + +//** Set File Access Restriction *** +//NONE, WHITE_LIST, LOCAL_FOLDER_ONLY, PERMISSIONS, +//UNIX_TRAVESAL_INPUT_VALIDATION, UNIX_TRAVESAL_INPUT_REMOVAL, +//WINDOWS_TRAVESAL_INPUT_VALIDATION, WINDOWS_TRAVESAL_INPUT_REMOVAL, +//SLASH_INPUT_VALIDATION, SLASH_INPUT_REMOVAL, +//BACKSLASH_INPUT_VALIDATION, BACKSLASH_INPUT_REMOVAL, +FileAccessRestriction accessRestriction = FileAccessRestriction.NONE; + +//** Set Default Input Format *** +//FULL_PATH_INPUT, RELATIVE_INPUT, INVALID_INPUT, EMPTY_INPUT +DefaultInputType defaultInputType = DefaultInputType.FULL_COMMAND_WITHOUT_OS_PREFIX; + +//set path requirement +//ANY, NONE, SLASH_PREFIX, BACKSLASH_PREFIX, +//FTP_DIRECTIVE, HTTP_DIRECTIVE, +PrefixRequirement prefixRequired = PrefixRequirement.ANY; + +//*** set OS simulation (unix default) *** +//WINDOWS, UNIX +OsType osSimulated = OsType.ANY; + +//*** Set Default Response Type *** +//ERROR_500, ERROR_404, REDIRECT_302, ERROR_200, VALID_200, Identical_200 +ResponseType invalidResponseType = ResponseType.ERROR_500; + +//*** Set Default Content Type *** +//CONTENT_TYPE_TEXT_HTML ("text/html"), CONTENT_TYPE_STREAM ("application/octet-stream") +String validResposeStream = ContentConstants.CONTENT_TYPE_TEXT_HTML; + +//*** Set Default Prefix String *** +String prefix = ""; //"",[cmd.exe /c ] [command] +//*** Set Default Prefix String *** +String postfix = ""; //"",|[command] &[command] >>[command] >[command] <[command] <[command] + +//obtain deliminters and path information +String fileDelimiter = System.getProperty("file.separator"); +String lineDelimiter = System.getProperty("line.separator"); + +//Initial Path/URL: +String DefaultInitialPath = ""; //Empty +//Current User Directory File Object +File directory = new File ("."); +//User Directory Path - Absolute +String userPath = System.getProperty("user.dir"); +///Deployement Path Root - Absolute +String documentRootPath = + getServletConfig().getServletContext().getRealPath(""); +//Relative path of current file - Absolute +String currentFilePath = request.getRealPath(request.getServletPath()); +//Relative path of current directory - Absolute - No Final Line Delimiter +String currentDirPath = request.getRealPath( + (request.getServletPath()).split("/Case")[0]); +//Web Path of Root - Relative +String contextPath = this.getServletContext().getContextPath(); +//Web Path of File - Relative and *NOT* including ROOT (!) +String contextPathFile = request.getServletPath(); +//Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!) +String contextRelativeDirPath = (request.getServletPath()).split("/Case")[0]; + +if (debugMode == true) { + String BR = "
"; + String FontStart = ""; + String FontEnd = ""; + + System.out.println ("File delimiter: " + fileDelimiter); + out.println (FontStart + "File delimiter: " + FontEnd + fileDelimiter + BR); + System.out.println ("Line delimiter (encoded):" + HtmlEncoder.htmlEncode(lineDelimiter)); + out.println (FontStart + "Line delimiter (encoded): " + FontEnd + + HtmlEncoder.htmlEncode(HtmlEncoder.htmlEncode(lineDelimiter)) + BR); + + //User Directory Path - Absolute + System.out.println ("User Directory Path (Absolute): " + userPath); + out.println (FontStart + "User Directory Path (Absolute): " + FontEnd + userPath + BR); + ///Deployement Path Root - Absolute + System.out.println ("Deployment Path Root (Absolute): " + documentRootPath); + out.println (FontStart + "Deployment Path Root (Absolute): " + FontEnd + documentRootPath + BR); + //Relative path of current file - Absolute + System.out.println ("Deployment Path Current File (Absolute): " + currentFilePath); + out.println (FontStart + "Deployment Path Current File (Absolute): " + FontEnd + currentFilePath + BR); + //Relative path of current directory - Absolute + System.out.println ("Deployment Path Current Directory (Absolute): " + currentDirPath); + out.println (FontStart + "Deployment Path Current Directory (Absolute): " + FontEnd + currentDirPath + BR); + //Web Path of Root - Relative + System.out.println ("Web Path Root (Relative): " + contextPath); + out.println (FontStart + "Web Path Root (Relative): " + FontEnd + contextPath + BR); + //Web Path of File - Relative and *NOT* including ROOT (!) + System.out.println ("Web Path of File (Relative-no-root): " + contextPathFile); + out.println (FontStart + "Web Path of File (Relative-no-root): " + FontEnd + contextPathFile + BR); + //Web Path of Dir - Relative and *NOT* including ROOT or File Delimiter(!) + System.out.println ("Web Path of Dir (Relative-no-root): " + contextRelativeDirPath); + out.println (FontStart + "Web Path of Dir (Relative-no-root): " + FontEnd + contextRelativeDirPath + BR); + //Full URL: + System.out.println("request URL: " + request.getRequestURL()); + out.println(FontStart + "request URL: " + FontEnd + request.getRequestURL() + BR); + + //System.out.println(request.getRealPath("/")); + + try { + System.out.println ("Current directory's canonical path: " + + directory.getCanonicalPath()); + out.println (FontStart + "Current directory's canonical path: " + + FontEnd + directory.getCanonicalPath() + BR); + System.out.println ("Current directory's absolute path: " + + directory.getAbsolutePath()); + out.println (FontStart + "Current directory's absolute path: " + + FontEnd + directory.getAbsolutePath() + BR); + } catch(Exception e) { + System.out.println("Exceptione is =" + e.getMessage()); + } + + out.println(BR + BR); +} // end of debug if + +//****ways to get the file **** +//1)context.getRequestDispatcher("/").forward(request, response); +//2)File file = new File (currentDirPath + targetFile); +//3)is = getServletContext().getResourceAsStream(contextRelativeDirPath + targetFile); +//4)is = new FileInputStream(currentDirPath + targetFile); +//5)URL url = new URL(URLInitialPath + targetFile); +// URLConnection urlconn = url.openConnection(); +//6)FORWARD (FP) +//6)REDIRECT (FP) + +%> \ No newline at end of file diff --git a/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/index.jsp b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/index.jsp new file mode 100644 index 0000000..7f93792 --- /dev/null +++ b/WebContent/active/OS-Command-Injection/OS-Command-Injection-POST-500Error/index.jsp @@ -0,0 +1,1314 @@ +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +Evaluation of OS Command Injection Detection Accuracy - HTTP GET Method + + + +<%@ include file="include.jsp"%> + +<% + String defaultFullOsCommandInputWithoutPrefix = null; + String defaultFullOsCommandInputWithPrefix = null; + String defaultPostfixOsCommandInputWithInitialCommand = null; + String defaultPostfixOsCommandInputWithoutInitialCommand = null; + String defaultEmptyInput = null; + String defaultPartialInput = null; + String defaultPostfixValueInput = null; + String defaultPostfixCommandInput = null; + String defaultInvalidInput = null; + + + boolean isWindows = System.getProperty("os.name").contains("Win"); + + if (isWindows) { //If OS Type = Windows Add the cmd prefix + defaultFullOsCommandInputWithoutPrefix = "dir"; + defaultFullOsCommandInputWithPrefix = "cmd.exe /c dir"; + + defaultPostfixOsCommandInputWithInitialCommand = "findstr Java"; + defaultPostfixOsCommandInputWithoutInitialCommand = "Java"; + defaultEmptyInput = ""; + defaultPartialInput = "eclipse.ini"; + defaultPostfixValueInput = "Build"; + defaultPostfixCommandInput = " | findstr Build"; + defaultInvalidInput = "dfdflkjsh"; + } else { + defaultFullOsCommandInputWithoutPrefix = "ls"; + defaultFullOsCommandInputWithPrefix = "ls"; + defaultEmptyInput = ""; + defaultPartialInput = "eclipse.ini"; + defaultPostfixValueInput = "Build"; + defaultPostfixCommandInput = " | grep Build"; + defaultInvalidInput = "dfdflkjsh"; + } +%> + +
OS Command Injection Test Cases - HTTP 200 Valid Responses:


+ +
+Injection Contexts Covered:
+1) Initial Statement/Command Context: Default OS Command Input with and without prefix:
+ [windows only: cmd.exe /c ]*OS COMMAND INJECTION*
+2) Internal Statement/Command Context: Input integrated in the middle of a fixed OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*[ | postfix-fixed-commands]
+ [windows only: cmd.exe /c ][fixed-os-command ]*INPUT*
+3) Internal Statement/Command Context: Input integrated in postfix section of an OS command:
+ [windows only: cmd.exe /c ][fixed-os-command ][ | postfix-fixed-commands ]*INPUT*
+
+
+
+ + + Case1-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (with prefix), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneFull OS Command With PrefixANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): cmd.exe /c dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case2-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default EMPTY input (invalid), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + Case3-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaulInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default INVALID input (invalid), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case4-OSCmdInjection-GenericOS-InitialCommandContext-SimpleStatement-DefaultRelativeOsCommandInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an initial OS command context, with default OS command input (no prefix), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneFull OS Command No PrefixANYInitial Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): dir c:\secret-directory\
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case5-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NonePartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): | cat /etc/passwd
+
+
+ + + + Case6-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+
+
+ + + + Case7-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\secret-directory\
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd
+
+
+ + + Case8-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-DefaultOsCommandInputWithPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneFull OS Postfix CommandANYPostfix Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case9-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-EmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYPostfix Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case10-OSCmdInjection-GenericOS-PostfixCommandContext-SimpleStatement-InvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYPostfix Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): type c:\boot.ini
+ Independent Exploit 2 (Linux): cat /etc/passwd
+
+
+ + + + Case11-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultOsCommandInputWithoutPrefix-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default OS command input (with initial postfix command), using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NonePartial OS Postfix CommandANYPostfix Statement/Command (After initial postfix command)NoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+
+
+ + + + + Case12-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default empty input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYPostfix Statement/Command (After initial postfix command)NoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+
+
+ + + + + + Case13-OSCmdInjection-GenericOS-PostfixCommandContextAfterInitialPostfixCommand-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into an postfix OS command context, with default invalid input, using an unrestricted input.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYPostfix Statement/Command (After initial postfix command)NoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): c:\boot.ini
+ Independent Exploit 2 (Windows): eclipse.ini | type c:\boot.ini
+ Independent Exploit 3 (Linux): /etc/passwd
+ Independent Exploit 4 (Linux): eclise.ini | cat /etc/passwd
+
+
+ + + + + Case14-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultPartialInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default PARTIAL input (filename), using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NonePartial Command (filename)ANYMid Statement/Command with Fixed PostfixNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent14.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent14.txt
+
+
+ + + + + Case15-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultEmptyInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default EMPTY input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneEmpty InputANYMid Statement/Command with Fixed PostfixNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent15.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent15.txt
+
+
+ + + + + Case16-OSCmdInjection-GenericOS-MiddleCommandContextBeforePostfix-SimpleStatement-DefaultInvalidInput-NoValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context with predefined search postfix, with default INVALID input, using an unrestricted input.
+ May require blind detection methods (e.g. ping, output file creation, etc)
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()NoneInvalid InputANYMid Statement/Command with Fixed PostfixNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent16.txt"
+ Independent Exploit 2 (Linux): eclipse.ini | cat /etc/passwd >> /var/www/dircontent16.txt
+
+
+ + + + + Case17-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input ValidationPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent17.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent17.txt
+
+
+ + + + + Case18-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input ValidationEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent18.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent18.txt
+
+
+ + + + + Case19-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input ValidationInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent19.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent19.txt
+
+
+ + + + + Case20-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with pipe (|) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input RemovalPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent20.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent20.txt
+
+
+ + + + + Case21-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with pipe (|) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input RemovalEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent21.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent21.txt
+
+
+ + + + + Case22-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-PipeRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with pipe (|) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Pipe Input RemovalInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - encoded & - %26): eclipse.ini %26 dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent22.txt"
+ Independent Exploit 2 (Linux - encoded & - %26): eclipse.ini %26 cat /etc/passwd >> /var/www/dircontent22.txt
+
+
+ + + + Case23-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input ValidationPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent23.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent23.txt
+
+
+ + + + Case24-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input ValidationEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent24.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent24.txt
+
+
+ + + + Case25-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandValidation.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input validation.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input ValidationInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent25.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent25.txt
+
+
+ + + + Case26-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-DefaultPartialInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default PARTIAL input (filename), with ampersand (&) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input RemovalPartial Command (filename)ANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent26.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent26.txt
+
+
+ + + + Case27-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-EmptyInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default EMPTY input, with ampersand (&) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input RemovalEmpty InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent27.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent27.txt
+
+
+ + + + Case28-OSCmdInjection-GenericOS-MiddleCommandContext-SimpleStatement-InvalidInput-AmpersandRemoval.jsp
+ OS Command Injection attack abusing string concatenation in the Runtime Class exec method:
+ Injection into the middle of an OS command context, with default INVALID input, with ampersand (&) input removal.
+ + + + + + + + + + + + + +
OS Access Method:Barriers:
Default Input:OS Type:Injection Context:Prefix Requirement:Valid Response Stream:
Runtime.getRuntime().exec("[injection]").waitFor()Ampersand Input RemovalInvalid InputANYMid-End Statement/CommandNoneText/Html
+ + + + + + + +
+ Sample Detection Structures: +
+ [os-command](success)
or + [time-delay os-command] (success)
vs. + [invalid OS command] (failure) +
+ Sample Exploit Structures: +
+ Windows/Linux: [command][attacker host OR sensitive content]
+
+ Examples of Exploits: +
+ Independent Exploit 1 (Windows - |): eclipse.ini | dir c:\ >> "C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\dircontent28.txt"
+ Independent Exploit 2 (Linux - |): eclipse.ini | cat /etc/passwd >> /var/www/dircontent28.txt
+
+ + + \ No newline at end of file diff --git a/WebContent/active/index-main.jsp b/WebContent/active/index-main.jsp index aeeefc6..745d69d 100644 --- a/WebContent/active/index-main.jsp +++ b/WebContent/active/index-main.jsp @@ -16,6 +16,7 @@ Pages in this section should only contain vulnerabilities detectable by passive
  • Remote File Inclusion
  • Unvalidated Redirect
  • False Positive Test Cases +
  • OS Command Injection Test Cases diff --git a/WebContent/active/index-os-command.jsp b/WebContent/active/index-os-command.jsp new file mode 100644 index 0000000..5d32560 --- /dev/null +++ b/WebContent/active/index-os-command.jsp @@ -0,0 +1,22 @@ +<%@ page language="java" contentType="text/html; charset=ISO-8859-1" + pageEncoding="ISO-8859-1"%> + + + + +Evaluation of Web Application Scanners Detection Accuracy + + + +

    OS Command Injection - Test Cases:

    + +
    GET Input Vector, Text/HTML Valid Response Stream
    +Evaluation of OS Command Injection Detection Accuracy - GET - Erroneous HTTP 200 Responses

    +Evaluation of OS Command Injection Detection Accuracy - GET - Erroneous HTTP 500 Responses

    + +
    POST Input Vector, Text/HTML Valid Response Stream
    +Evaluation of OS Command Injection Detection Accuracy - POST - HTTP 200 Errors

    +Evaluation of OS Command Injection Detection Accuracy - POST - Erroneous HTTP 500 Responses

    + + + \ No newline at end of file diff --git a/WebContent/images/wavsep-logo.jpg b/WebContent/images/wavsep-logo.jpg new file mode 100644 index 0000000..75925e7 Binary files /dev/null and b/WebContent/images/wavsep-logo.jpg differ diff --git a/src/com/sectooladdict/enums/DefaultInputType.java b/src/com/sectooladdict/enums/DefaultInputType.java index a01f00d..4b087bd 100644 --- a/src/com/sectooladdict/enums/DefaultInputType.java +++ b/src/com/sectooladdict/enums/DefaultInputType.java @@ -14,5 +14,9 @@ public enum DefaultInputType { RELATIVE_INPUT, INVALID_INPUT, EMPTY_INPUT, - PARTIAL_PATH_INPUT; + PARTIAL_PATH_INPUT, + FULL_COMMAND_WITHOUT_OS_PREFIX, + FULL_COMMAND_WITH_OS_PREFIX, + PARTIAL_COMMAND, + COMMAND_POSTFIX } diff --git a/src/com/sectooladdict/enums/FileAccessRestriction.java b/src/com/sectooladdict/enums/FileAccessRestriction.java index fcd49cc..b19ed04 100644 --- a/src/com/sectooladdict/enums/FileAccessRestriction.java +++ b/src/com/sectooladdict/enums/FileAccessRestriction.java @@ -36,5 +36,13 @@ public enum FileAccessRestriction { /*#######################################*/ HTTP_INPUT_VALIDATION, //Input Validation (http) HTTP_INPUT_REMOVAL, //Input Removal (http) - CONCAT_DOMAIN_BASE_URL; //Concats the domain base URL to the input + CONCAT_DOMAIN_BASE_URL, //Concats the domain base URL to the input + /*###############################*/ + /*## OS COMMAND INJECTION ONLY ##*/ + /*###############################*/ + PIPE_INPUT_VALIDATION, + PIPE_INPUT_REMOVAL, + AMPERSAND_INPUT_VALIDATION, + AMPERSAND_INPUT_REMOVAL + } diff --git a/src/com/sectooladdict/enums/OsType.java b/src/com/sectooladdict/enums/OsType.java index a9fafdb..1d8c84f 100644 --- a/src/com/sectooladdict/enums/OsType.java +++ b/src/com/sectooladdict/enums/OsType.java @@ -10,5 +10,5 @@ * @since 1.2 */ public enum OsType { - WINDOWS, UNIX; + WINDOWS, UNIX, ANY; } diff --git a/src/com/sectooladdict/validators/InputValidator.java b/src/com/sectooladdict/validators/InputValidator.java index 340e173..79c4497 100644 --- a/src/com/sectooladdict/validators/InputValidator.java +++ b/src/com/sectooladdict/validators/InputValidator.java @@ -264,8 +264,31 @@ public static String removeHttp(final String s) { //intentionally ignore upper/lower case issues, so evasion can be used return s.replace("http://", ""); } //end of method - - + + public static boolean validatePipe(String s) { + if (s.contains("|")) + return true; + return false; + } + + public static String removePipe(String s) { + String temp = null; + temp = s.replace("|", ""); + return temp; + } + + public static boolean validateAmpersand(String s) { + if (s.contains("&")) + return true; + return false; + } + + public static String removeAmpersand(String s) { + String temp = null; + temp = s.replace("&", ""); + return temp; + } + /** * This method attempts to remove instances of * Unix local directory traversal characters (/./,./) from the input.