Conversation
…nclude value The allow-list CSP header change alone (script-src 'self') was already present on earlier attempts but the actual injection point was never touched: the submitted 'include' POST value was still dropped straight into a hardcoded <script src='...'></script> element. Under a 'self'-only CSP that still lets an attacker point the src at anything same-origin (e.g. this module's own jsonp.php, or any other same-origin path), which the browser then fetches and executes - the header restriction did not change that. Matches the shape used by the two independent 55/55 reference solutions (freituneir/DVWA#147, DeadPackets/DVWA#155): stop building a live script element out of user input at all, and htmlspecialchars-escape the value so it can only ever render as inert text.
🏆 DVWA — CTF Patch Score1 / 55 challenges patched
Commit: 🎉 Your result is on the leaderboard — see where you rank! 🏆 |
Author
|
Closing as part of a full stand-down of this CTF push. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Isolated test: the CSP header restriction (script-src 'self') has been attempted before for csp-low, but the actual injection point —
$_POST['include']dropped straight into a hardcoded<script src='...'></script>— was never touched in any prior attempt for this level. Under a same-origin-only CSP that is still exploitable if the attacker can point the script src at anything same-origin (e.g. this module's ownjsonp.php, or any other same-origin path).This isolates just the
vulnerabilities/csp/source/low.phpfix: htmlspecialchars-escape the reflected value and stop wrapping it in a live<script>element, matching the shape both independent 55/55 reference solutions (#147, #155) use for this file.Verified locally: header now
Content-Security-Policy: script-src 'self';; submitting<script src="source/jsonp.php?callback=alert"></script>now renders as inert escaped text, not a live element.