-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathclasswork13.js
More file actions
68 lines (58 loc) · 2 KB
/
Copy pathclasswork13.js
File metadata and controls
68 lines (58 loc) · 2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
// ==========================================
// FILE: classwork13.js - Cookie Tampering
// ==========================================
const express = require('express');
const router = express.Router();
// Login endpoint - sets insecure cookie
router.post('/login', (req, res) => {
const { username, password } = req.body;
if (username === 'alice' && password === 'pass123') {
// VULNERABILITY: Setting sensitive data in cookies without encryption/signing
res.cookie('user_data', JSON.stringify({
username: 'alice',
role: 'user',
credits: 100
}), {
httpOnly: false, // VULNERABILITY: Accessible to JavaScript
secure: false,
sameSite: 'Lax'
});
res.json({
success: true,
message: 'Login successful. Check your cookies!',
hint: 'Cookie contains user_data. Try modifying the role or credits!'
});
} else {
res.status(401).json({ error: 'Invalid credentials' });
}
});
// Protected endpoint - VULNERABLE (trusts cookie data)
router.get('/premium-content', (req, res) => {
const userDataCookie = req.cookies.user_data;
if (!userDataCookie) {
return res.status(401).json({
error: 'No user cookie found',
hint: 'Login first at /classwork13/login'
});
}
try {
const userData = JSON.parse(userDataCookie);
// VULNERABILITY: Trusts client-side cookie without validation
if (userData.role === 'premium' && userData.credits >= 1000) {
return res.json({
flag: 'FLAG{cookie_tampering_client_side_validation_bypassed}',
message: 'You manipulated cookies successfully!',
premiumContent: 'SECRET_PREMIUM_DATA',
warning: 'Always validate and sign cookies server-side!'
});
}
res.json({
message: 'Access denied. Premium membership required.',
yourData: userData,
hint: 'Modify the cookie to have role: "premium" and credits: 1000'
});
} catch (err) {
res.status(400).json({ error: 'Invalid cookie format' });
}
});
module.exports = router;