Skip to content

Encode HTTP metadata in challenge output - #262

Open
tobymoreno wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
tobymoreno:fix/dvwa-injection-http-output
Open

tobymoreno wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
tobymoreno:fix/dvwa-injection-http-output

Conversation

@tobymoreno

Copy link
Copy Markdown

Summary

  • encode request-derived HTTP metadata before rendering File Inclusion diagnostics
  • encode the server name used by the API help link
  • stop reflecting PHP_SELF into API and Cryptography form actions
  • add focused regression coverage

OWASP mapping

  • A05:2025 Injection
  • CWE-79, CWE-116, CWE-644

Validation

  • PHP syntax checks pass for all five modified PHP files in the DVWA container
  • 3 focused regression tests pass
  • git diff --check passes

Encode request-derived server values before placing them in HTML and stop reflecting PHP_SELF into form actions. Add focused A05 regression coverage for header and request-path injection.

Signed-off-by: Toby Moreno <chris.moreno.ctr@km.spaceforce.mil>
@github-actions

github-actions Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

🏆 DVWA — CTF Patch Score

░░░░░░░░░░░░░░░░░░░░  0 / 108 pts  (0%)

0 / 55 challenges patched

Per-challenge detail is withheld — it would reveal the rubric.

Commit: 40fbab4 · scoring run

No points yet — this commit didn't solve any challenges, so there's nothing on the leaderboard for it. Patch a vulnerability and push again! 💪

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant