Skip to content

fix(file-ops): implement whitelist validation for file operations (CW… - #273

Open
markuszaki wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
markuszaki:fix/owasp-file-ops
Open

markuszaki wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
markuszaki:fix/owasp-file-ops

Conversation

@markuszaki

Copy link
Copy Markdown

…E-22/434/601)

Security fixes for 9 challenges across 3 vulnerability types:

File Inclusion (CWE-22):

  • Added whitelist of allowed files (index.php, about.php, contact.php, help.php)
  • Used basename() to strip directory traversal attempts
  • Blocked protocol wrappers (://, php://, file://, data://, etc.)
  • Default to index.php for invalid requests

File Upload (CWE-434):

  • Implemented extension whitelist (jpg, jpeg, png, gif)
  • Added MIME type validation using finfo
  • Random filename generation using random_bytes() to prevent prediction
  • File size validation (100KB limit)
  • getimagesize() validation for high security level

Open Redirect (CWE-601):

  • Whitelist of allowed redirect targets
  • Protocol wrapper detection and blocking
  • basename() to prevent path traversal
  • Proper error responses (400) for invalid targets

Files modified:

  • vulnerabilities/fi/source/{low,medium,high}.php
  • vulnerabilities/upload/source/{low,medium,high}.php
  • vulnerabilities/open_redirect/source/{low,medium,high}.php

…E-22/434/601)

Security fixes for 9 challenges across 3 vulnerability types:

File Inclusion (CWE-22):
- Added whitelist of allowed files (index.php, about.php, contact.php, help.php)
- Used basename() to strip directory traversal attempts
- Blocked protocol wrappers (://, php://, file://, data://, etc.)
- Default to index.php for invalid requests

File Upload (CWE-434):
- Implemented extension whitelist (jpg, jpeg, png, gif)
- Added MIME type validation using finfo
- Random filename generation using random_bytes() to prevent prediction
- File size validation (100KB limit)
- getimagesize() validation for high security level

Open Redirect (CWE-601):
- Whitelist of allowed redirect targets
- Protocol wrapper detection and blocking
- basename() to prevent path traversal
- Proper error responses (400) for invalid targets

Files modified:
- vulnerabilities/fi/source/{low,medium,high}.php
- vulnerabilities/upload/source/{low,medium,high}.php
- vulnerabilities/open_redirect/source/{low,medium,high}.php
@github-actions

github-actions Bot commented Aug 9, 2026

Copy link
Copy Markdown

🏆 DVWA — CTF Patch Score

█░░░░░░░░░░░░░░░░░░░  3 / 108 pts  (3%)

2 / 55 challenges patched

Per-challenge detail is withheld — it would reveal the rubric.

Commit: 0f74ad6 · scoring run

🎉 Your result is on the leaderboard — see where you rank! 🏆

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant