Skip to content

Harden CSP JSONP output - #263

Open
tobymoreno wants to merge 3 commits into
OWASP-CTF:dc34-ctffrom
tobymoreno:fix/dvwa-csp-jsonp-injection
Open

tobymoreno wants to merge 3 commits into
OWASP-CTF:dc34-ctffrom
tobymoreno:fix/dvwa-csp-jsonp-injection

Conversation

@tobymoreno

@tobymoreno tobymoreno commented Aug 9, 2026 •

Copy link
Copy Markdown

Summary

  • restrict JSONP to the one callback required by the CSP client
  • reject missing or injected callbacks with HTTP 400 and no reflected body
  • serve JSONP using the JavaScript content type
  • remove hidden POST markup reflection from High and Impossible
  • render JSONP response values with textContent
  • add source guardrails plus authenticated runtime exploit tests
  • add an unprivileged pull_request workflow that builds the exact PR image

OWASP mapping

  • A05:2025 Injection
  • CWE-79, CWE-94, CWE-116

Validation

  • 4 source regression tests pass
  • 4 authenticated runtime smoke tests pass with resource warnings treated as errors
  • runtime flow resets the database, logs in, changes security levels, checks core pages, preserves valid JSONP, rejects four callback payloads, and rejects hidden markup reflection
  • PHP syntax checks pass in a freshly rebuilt DVWA container
  • workflow YAML parses and git diff --check passes

CI note

The new pull_request workflow will become active after this workflow file exists on the base branch; GitHub currently runs only the base branch score workflow for this PR.

Allow only the expected JSONP callback, return JavaScript with the correct content type, remove hidden markup reflection from high security levels, and render response values as text.

Signed-off-by: Toby Moreno <chris.moreno.ctr@km.spaceforce.mil>
@github-actions

github-actions Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

🏆 DVWA — CTF Patch Score

░░░░░░░░░░░░░░░░░░░░  0 / 108 pts  (0%)

0 / 55 challenges patched

Per-challenge detail is withheld — it would reveal the rubric.

Commit: 49a4092 · scoring run

No points yet — this commit didn't solve any challenges, so there's nothing on the leaderboard for it. Patch a vulnerability and push again! 💪

Toby Moreno added 2 commits August 9, 2026 09:31
Build and exercise the exact PR image in an unprivileged pull-request workflow. Reset and authenticate DVWA through HTTP, verify benign CSP behavior, and reject callback and markup injection payloads.

Signed-off-by: Toby Moreno <chris.moreno.ctr@km.spaceforce.mil>
Signed-off-by: Toby Moreno <chris.moreno.ctr@km.spaceforce.mil>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant