Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 6 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,11 @@ All notable changes to this project will be documented in this file.

The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/).

## 2025-09-02

### Changed
- Unvalidated-Redirect/Redirect-FalsePositives-GET/Case09... now uses the default host from the first configured engine (identified via JMX) instead of the requested host name (which could have been from a manipulated Host header).

## 2025-08-30
- Imported OS Command Injection tests from [Reinforced Wavsep](https://github.com/luigiurbano/Reinforced-Wavsep) at commit [962d566](https://github.com/luigiurbano/Reinforced-Wavsep/commit/962d566ebe51a3f64f772b6c1856d99f1150ba4a).

Expand Down Expand Up @@ -34,4 +39,4 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/).
- JSPs to use correct exceptions.

### Removed
- Eclipse files.
- Eclipse files.
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
<%@page import="com.sectooladdict.enums.VulnerabilityType"%>
<%@page import="com.sectooladdict.constants.FileConstants"%>
<%@page import="com.sectooladdict.validators.InputValidator"%>
<%@ page import="javax.management.ObjectName,javax.management.MBeanServer,java.lang.management.ManagementFactory,java.util.Set" %>

<%
//First set the prefix according to the path type
Expand Down Expand Up @@ -282,9 +283,24 @@
}

if (defaultInputType == DefaultInputType.RELATIVE_INPUT) {
// This had previously been using request.getServerName().
// However, that actually means that it 'trusts' the Host
// header from the traffic, which turns this test which was
// meant to be a FP case into a TP case for scenarios when
// headers are being manipulated by a scanner.
// There should only be one configured (default is localhost)
MBeanServer mbs = ManagementFactory.getPlatformMBeanServer();
ObjectName engineObj = new ObjectName("Catalina:type=Engine,*");
Set<ObjectName> engines = mbs.queryNames(engineObj, null);
String defaultHost = "";
if (!engines.isEmpty()) {
ObjectName engine = engines.iterator().next();
defaultHost = (String) mbs.getAttribute(engine, "defaultHost");
}

//relative to current dir path
defaultBasePath = FileConstants.HTTP_PREFIX
+ request.getServerName() + ":" +
+ defaultHost + ":" +
request.getServerPort() + request.getContextPath() +
Comment thread
kingthorin marked this conversation as resolved.
contextRelativeDirPath + "/";
targetFile = defaultBasePath + targetFile;
Expand Down Expand Up @@ -346,4 +362,4 @@
%>

</body>
</html>
</html>