-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathclasswork14.js
More file actions
63 lines (51 loc) · 1.93 KB
/
Copy pathclasswork14.js
File metadata and controls
63 lines (51 loc) · 1.93 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
// ==========================================
// FILE: classwork14.js - Response Header Injection
// ==========================================
const express = require('express');
const router = express.Router();
// Search endpoint - VULNERABLE to header injection
router.get('/search', (req, res) => {
const query = req.query.q;
if (!query) {
return res.status(400).json({ error: 'Missing search query' });
}
// VULNERABILITY: Reflecting user input in headers without sanitization
// This can lead to HTTP Response Splitting in some contexts
try {
res.set('X-Search-Query', query);
res.set('X-Search-Results', '5');
// Check if user injected newlines to add custom headers
const customFlag = req.headers['x-injected-header'];
if (customFlag === 'injected-by-attacker') {
return res.json({
flag: 'FLAG{response_header_injection_detected}',
message: 'You successfully injected a custom header!',
results: [],
warning: 'Header injection can lead to response splitting attacks!'
});
}
res.json({
query: query,
results: ['Result 1', 'Result 2', 'Result 3'],
hint: 'Try using a proxy to inject X-Injected-Header: injected-by-attacker'
});
} catch (err) {
res.status(500).json({ error: 'Invalid characters in query' });
}
});
// Redirect endpoint - VULNERABLE to open redirect via response manipulation
router.get('/redirect', (req, res) => {
const target = req.query.target || '/dashboard';
// VULNERABILITY: Allows arbitrary redirects
res.set('X-Redirect-Target', target);
// If user manipulated response to change X-Redirect-Target header
if (req.query.manipulated === 'true') {
return res.json({
flag: 'FLAG{open_redirect_via_header_manipulation}',
message: 'You manipulated the redirect target!',
warning: 'Always whitelist redirect targets!'
});
}
res.redirect(target);
});
module.exports = router;