Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

⛏️ Write a test to check whether we can create/update an object with invalid URLs #655

Open
5 tasks
arjun-akto opened this issue Oct 13, 2023 · 5 comments
Assignees
Labels
hacktoberfest yaml requires yaml knowledge

Comments

@arjun-akto
Copy link
Contributor

💭 Introduction:

We want to test to check whether an attacker can create/update entity with an invalid URL.

🎯 Requirements:

  1. Filters - API with Web URL as an input in GET query parameter or JSON body parameter

  2. Execute - It should replace the value with

  • special characters
  • A very long string (> 255 characters)
  • Use whitespaces
  • Invalid SSN
  • A negative integer
  • A very long integer causing integer overflow
  • Zero
  • NULL
  • Malicious Host URLs
  • URLs having special Characters, possibly breaking the URL structure when executed internally
  1. Validation - If the application responds with a exception trace, it is a vulnerability.

✅ Task summary:

  • Ask to be assigned to the issue.
  • Wait to be assigned. We will try to assign in less than 2 hours.
  • Signup for [Akto]
  • Fork the [tests-library] repository, create a new branch and commit the yaml file which will be called in your test.
  • Submit both the PR here.

📚 Reading

You can find a detailed documentation of test editor rules [here]

Find 100+ examples of YAML tests [here]

🙋🏼‍♂️ Questions:

If you have questions, need any help, or just want to hang out, make sure to join us on our [Discord server].

@arjun-akto arjun-akto added yaml requires yaml knowledge hacktoberfest labels Oct 13, 2023
@heysagnik
Copy link

I would love to work on this issue please kindly assign me

@arjun-akto
Copy link
Contributor Author

Hi @heysagnik . I have assigned the issue to you. Please feel free to connect us on our Discord server for any doubts.

@STUDIOUS-WOLF
Copy link

Hi @arjun-akto, @heysagnik I would like to contribute to this issue if no one is working on it

@heysagnik
Copy link

yeah you may work, I am not getting what actually to be done.

@arjun-akto
Copy link
Contributor Author

Hi @STUDIOUS-WOLF , I have assigned the issue to you. Please feel free to connect us on our Discord server for any doubts.

ayushaga14 pushed a commit that referenced this issue Jan 3, 2024
set slice limit to 100 and add logs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
hacktoberfest yaml requires yaml knowledge
Projects
None yet
Development

No branches or pull requests

3 participants