mirror of
https://github.com/Strategic-Automation/violin.git
synced 2026-08-14 12:33:37 +02:00
- _method_route_in_text now accepts '-X POST <url>' reproduction commands (quoted URLs no longer break the match) — recovers referral-abuse - coupon-100-discount: decisive patterns (INTERNAL100 / 'discounted to $0') kill the false positive from a neg-qty finding whose checkout sent coupon_code:null - weak-admin-creds: decisive patterns (DefaultCredentials / admin:password) stop mass-assign role-granted text from confirming it - vuln-research playbook + hypothesis template: mandate 1:N Linked findings (an unlinked FIND file scores 0 even with perfect evidence) Calibration still 20/20 + 0/0. Latest run re-scored: 6/20, now all true positives (false coupon + false creds removed, referral recovered).
305 lines
6.7 KiB
JSON
305 lines
6.7 KiB
JSON
{
|
|
"target": "duck-store.escape.tech",
|
|
"total_challenges": 20,
|
|
"source": "Redpick benchmark walkthroughs — 20 article-parity vulnerabilities",
|
|
"challenges": [
|
|
{
|
|
"id": "weak-admin-creds",
|
|
"category": "authentication",
|
|
"playbook": "auth-bypass",
|
|
"severity": "critical",
|
|
"endpoint": "POST /api/v1/auth/login",
|
|
"patterns": [
|
|
"admin",
|
|
"password",
|
|
"DefaultCredentials"
|
|
],
|
|
"require": [
|
|
"ADMIN_ROLE_GRANTED"
|
|
],
|
|
"decisive_patterns": [
|
|
"DefaultCredentials",
|
|
"admin/password",
|
|
"admin:password",
|
|
"\"password\":\"password\""
|
|
]
|
|
},
|
|
{
|
|
"id": "jwt-alg-none",
|
|
"category": "authentication",
|
|
"playbook": "jwt-attacks",
|
|
"severity": "critical",
|
|
"endpoint": "Any authenticated endpoint",
|
|
"patterns": [
|
|
"alg",
|
|
"none",
|
|
"jwt",
|
|
"algorithm"
|
|
]
|
|
},
|
|
{
|
|
"id": "totp-bypass",
|
|
"category": "authentication",
|
|
"playbook": "auth-bypass",
|
|
"severity": "critical",
|
|
"endpoint": "POST /api/v1/auth/login/totp",
|
|
"patterns": [
|
|
"totp",
|
|
"2fa",
|
|
"bypass",
|
|
"TOTPSecret"
|
|
]
|
|
},
|
|
{
|
|
"id": "idor-user-profiles",
|
|
"category": "access-control",
|
|
"playbook": "idor-access-control",
|
|
"severity": "critical",
|
|
"endpoint": "GET /api/v1/users/{uuid}",
|
|
"patterns": [
|
|
"/api/v1/users/",
|
|
"uuid",
|
|
"UserProfile"
|
|
]
|
|
},
|
|
{
|
|
"id": "mass-assign-role",
|
|
"category": "access-control",
|
|
"playbook": "auth-bypass",
|
|
"severity": "critical",
|
|
"endpoint": "PUT /api/v1/users/me/profile",
|
|
"patterns": [
|
|
"role",
|
|
"admin",
|
|
"UserUpdate",
|
|
"mass.assignment"
|
|
]
|
|
},
|
|
{
|
|
"id": "coupon-100-discount",
|
|
"category": "business-logic",
|
|
"playbook": "business-logic",
|
|
"severity": "critical",
|
|
"endpoint": "POST /api/v1/orders/checkout",
|
|
"patterns": [
|
|
"coupon",
|
|
"discount",
|
|
"100",
|
|
"checkout"
|
|
],
|
|
"decisive_patterns": [
|
|
"INTERNAL100",
|
|
"discounted to $0",
|
|
"100% discount"
|
|
]
|
|
},
|
|
{
|
|
"id": "referral-abuse",
|
|
"category": "business-logic",
|
|
"playbook": "business-logic",
|
|
"severity": "critical",
|
|
"endpoint": "POST /api/v1/auth/register",
|
|
"patterns": [
|
|
"referral",
|
|
"referrer",
|
|
"credit",
|
|
"RegisterRequest"
|
|
],
|
|
"require": [
|
|
"CREDIT_GRANTED"
|
|
]
|
|
},
|
|
{
|
|
"id": "sqli-color-filter",
|
|
"category": "injection",
|
|
"playbook": "sqli",
|
|
"severity": "high",
|
|
"endpoint": "GET /api/v1/products/filter/by-color",
|
|
"patterns": [
|
|
"filter",
|
|
"by-color",
|
|
"sql",
|
|
"ProductColor"
|
|
]
|
|
},
|
|
{
|
|
"id": "xss-testimonials",
|
|
"category": "injection",
|
|
"playbook": "xss",
|
|
"severity": "high",
|
|
"endpoint": "POST /api/v1/testimonials/",
|
|
"patterns": [
|
|
"testimonial",
|
|
"guest_avatar_url",
|
|
"xss",
|
|
"script"
|
|
],
|
|
"require": [
|
|
"script",
|
|
"xss",
|
|
"guest_avatar_url"
|
|
]
|
|
},
|
|
{
|
|
"id": "ssrf-image-import",
|
|
"category": "server-side",
|
|
"playbook": "ssrf",
|
|
"severity": "high",
|
|
"endpoint": "POST /api/v1/uploads/import-from-url",
|
|
"patterns": [
|
|
"import-from-url",
|
|
"ImageImport",
|
|
"ssrf"
|
|
]
|
|
},
|
|
{
|
|
"id": "ssrf-fetch-url",
|
|
"category": "server-side",
|
|
"playbook": "ssrf",
|
|
"severity": "high",
|
|
"endpoint": "GET /api/v1/uploads/fetch-url",
|
|
"patterns": [
|
|
"fetch-url",
|
|
"FetchUrl",
|
|
"link-preview"
|
|
]
|
|
},
|
|
{
|
|
"id": "unauth-testimonial-mod",
|
|
"category": "access-control",
|
|
"playbook": "access-control",
|
|
"severity": "high",
|
|
"endpoint": "PUT /api/v1/testimonials/{id}",
|
|
"patterns": [
|
|
"testimonial",
|
|
"unauth",
|
|
"PUT",
|
|
"TestimonialUpdate"
|
|
]
|
|
},
|
|
{
|
|
"id": "idor-order-details",
|
|
"category": "access-control",
|
|
"playbook": "idor-access-control",
|
|
"severity": "high",
|
|
"endpoint": "GET /api/v1/orders/{id}",
|
|
"patterns": [
|
|
"/api/v1/orders/",
|
|
"order_id",
|
|
"OrderDetail"
|
|
]
|
|
},
|
|
{
|
|
"id": "bac-admin-users",
|
|
"category": "access-control",
|
|
"playbook": "access-control",
|
|
"severity": "high",
|
|
"endpoint": "GET /api/v1/admin/users",
|
|
"patterns": [
|
|
"/api/v1/admin/users",
|
|
"UserList",
|
|
"admin"
|
|
]
|
|
},
|
|
{
|
|
"id": "neg-quantity-cart",
|
|
"category": "business-logic",
|
|
"playbook": "business-logic",
|
|
"severity": "high",
|
|
"endpoint": [
|
|
"PUT /api/v1/cart/items/{id}",
|
|
"POST /api/v1/cart/add"
|
|
],
|
|
"patterns": [
|
|
"quantity",
|
|
"-1",
|
|
"cart",
|
|
"CartItem"
|
|
],
|
|
"require": [
|
|
"NEGATIVE_NUMBER"
|
|
]
|
|
},
|
|
{
|
|
"id": "shipping-bypass",
|
|
"category": "business-logic",
|
|
"playbook": "business-logic",
|
|
"severity": "high",
|
|
"endpoint": "POST /api/v1/orders/checkout",
|
|
"patterns": [
|
|
"shipping",
|
|
"cost",
|
|
"bypass",
|
|
"ShippingInfo"
|
|
],
|
|
"decisive_patterns": [
|
|
"shipping_cost",
|
|
"shipping-cost",
|
|
"ShippingInfo",
|
|
"shipping cost"
|
|
]
|
|
},
|
|
{
|
|
"id": "coupon-info-disclosure",
|
|
"category": "information",
|
|
"playbook": "api-security",
|
|
"severity": "medium",
|
|
"endpoint": "GET /api/v1/orders/coupons",
|
|
"patterns": [
|
|
"/api/v1/orders/coupons",
|
|
"CouponList",
|
|
"disclosure"
|
|
]
|
|
},
|
|
{
|
|
"id": "no-rate-limiting",
|
|
"category": "misconfiguration",
|
|
"playbook": "api-security",
|
|
"severity": "medium",
|
|
"endpoint": "POST /api/v1/auth/login",
|
|
"patterns": [
|
|
"rate",
|
|
"429",
|
|
"brute",
|
|
"throttle"
|
|
],
|
|
"absence": true,
|
|
"require_any": [
|
|
"consecutive",
|
|
"rapid",
|
|
"attempts",
|
|
"lockout",
|
|
"throttle",
|
|
"429"
|
|
]
|
|
},
|
|
{
|
|
"id": "open-redirect",
|
|
"category": "misconfiguration",
|
|
"playbook": "security-misconfiguration",
|
|
"severity": "medium",
|
|
"endpoint": "/...?redirect=",
|
|
"patterns": [
|
|
"redirect",
|
|
"open.redirect",
|
|
"location"
|
|
],
|
|
"require": [
|
|
"EXTERNAL_REDIRECT"
|
|
]
|
|
},
|
|
{
|
|
"id": "user-enumeration",
|
|
"category": "information",
|
|
"playbook": "api-security",
|
|
"severity": "low",
|
|
"endpoint": "GET /api/v1/users/",
|
|
"patterns": [
|
|
"/api/v1/users/",
|
|
"username",
|
|
"enumeration"
|
|
]
|
|
}
|
|
]
|
|
}
|