Skip to content

Instantly share code, notes, and snippets.

@cneill
Last active June 17, 2016 19:05
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save cneill/29a59040a6282751ce2dc54a6a65594c to your computer and use it in GitHub Desktop.
Save cneill/29a59040a6282751ce2dc54a6a65594c to your computer and use it in GitHub Desktop.
{
"errors": [],
"failures": {
"localhost:9000/test": {
"500_errors": {
"description": "This request returns an error with status code 501, which might indicate some server-side fault that could lead to further vulnerabilities",
"payloads": [
{
"confidence": "High",
"param": {
"location": "data",
"method": "POST",
"type": "application/json",
"variables": [
"test"
]
},
"signals": [
"HTTP_STATUS_CODE_501"
"STRING_PRESENCE"
],
"strings": [
"AND (SELECT 1 FROM(SELECT COUNT(*),CONCAT('x',(SELECT (ELT(1=1,1))),'x',FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)",
"blah",
"blah",
"blah"
]
},
{
"confidence": "Medium",
"param": {
"location": "data",
"method": "POST",
"type": "application/json",
"variables": [
"test"
]
},
"signals": [
"HTTP_STATUS_CODE_501"
],
"strings": [
"AND EXTRACTVALUE(1,CONCAT('','x',(SELECT (ELT(1=1,1))),'x'))",
"blah",
"blah"
]
},
],
"severity": "Low"
}
}
},
"stats": {
"High": 0,
"Low": 1,
"Medium": 0
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment