| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
A node project to demonstrate srcclr agent's vulnerable methods feature for JavaScript
git clone https://github.com/srcclr/example-javascript-vulnerable-methods.git cd example-javascript-vulnerable-methods npm install node index.js
The vulnerable method is called twice during the server startup, however another one needs to be trigged by issuing a request to the endpoint by running the following command in another terminal to trigger the code execution vulnerability in js-yaml:load
curl --path-as-is 'http://127.0.0.1:8001/api/'
Use the following to trigger the directory traversal vulnerability (SID-20301)in algo-httpserv:serve
curl --path-as-is 'http://127.0.0.1/8001/../../../../../../etc/passwd'
git clone https://github.com/srcclr/example-javascript-vulnerable-methods.git cd example-javascript-vulnerable-methods npm install node larvitbase-api.js
and then run the following command in another terminal
curl --path-as-is 'http://127.0.0.1:8001/../../../../hacked'
You can see the JavaScript filehacked.js is executed in the server side.
brew tap srcclr/srcclr brew install srcclr srcclr activate srcclr scan --url https://github.com/srcclr/example-javascript-vulnerable-methods
| Back | FazBrowse Home | New Git URL |