Generated on Wed, 15 Jun 2022 17:56:10

Summary of Alerts

Risk Level Number of Alerts
High
1
Medium
3
Low
0
Informational
2

Alerts

Name Risk Level Number of Instances
Anti-CSRF Tokens Check High 1
CORS Misconfiguration Medium 1
Corsair - CORS Misconfigured Medium 1
Hidden File Found Medium 1
Cookie Slack Detector Informational 1
User Agent Fuzzer Informational 1

Passing Rules

Name Rule Type Threshold Strength
Directory Browsing Active MEDIUM MEDIUM
Path Traversal Active MEDIUM MEDIUM
Remote File Inclusion Active MEDIUM MEDIUM
XSLT Injection Active MEDIUM MEDIUM
Server Side Code Injection Active MEDIUM MEDIUM
Advanced SQL Injection Active MEDIUM MEDIUM
XPath Injection Active MEDIUM MEDIUM
Remote OS Command Injection Active MEDIUM MEDIUM
XML External Entity Attack Active MEDIUM MEDIUM
Expression Language Injection Active MEDIUM MEDIUM
Generic Padding Oracle Active MEDIUM MEDIUM
Source Code Disclosure - Git Active MEDIUM MEDIUM
Source Code Disclosure - SVN Active MEDIUM MEDIUM
SOAP Action Spoofing Active MEDIUM MEDIUM
Source Code Disclosure - File Inclusion Active MEDIUM MEDIUM
SOAP XML Injection Active MEDIUM MEDIUM
Insecure HTTP Method Active MEDIUM MEDIUM
HTTP Parameter Pollution Active MEDIUM MEDIUM
Heartbleed OpenSSL Vulnerability Active MEDIUM MEDIUM
Cross-Domain Misconfiguration Active MEDIUM MEDIUM
Source Code Disclosure - CVE-2012-1823 Active MEDIUM MEDIUM
Buffer Overflow Active MEDIUM MEDIUM
Remote Code Execution - CVE-2012-1823 Active MEDIUM MEDIUM
Format String Error Active MEDIUM MEDIUM
Integer Overflow Error Active MEDIUM MEDIUM
Cloud Metadata Potentially Exposed Active MEDIUM MEDIUM
External Redirect Active MEDIUM MEDIUM
Source Code Disclosure - /WEB-INF folder Active MEDIUM MEDIUM
HTTPS Content Available via HTTP Active MEDIUM MEDIUM
Remote Code Execution - Shell Shock Active MEDIUM MEDIUM
Relative Path Confusion Active MEDIUM MEDIUM
CRLF Injection Active MEDIUM MEDIUM
Example Active Scan Rule: Denial of Service Active MEDIUM MEDIUM
An example active scan rule which loads data from a file Active MEDIUM MEDIUM
Parameter Tampering Active MEDIUM MEDIUM
Server Side Include Active MEDIUM MEDIUM
GET for POST Active MEDIUM MEDIUM
Cross Site Scripting (Reflected) Active MEDIUM MEDIUM
Session Fixation Active MEDIUM MEDIUM
Cross Site Scripting (Persistent) Active MEDIUM MEDIUM
LDAP Injection Active MEDIUM MEDIUM
Cross Site Scripting (Persistent) - Prime Active MEDIUM MEDIUM
Cross Site Scripting (Persistent) - Spider Active MEDIUM MEDIUM
SQL Injection Active MEDIUM MEDIUM
SQL Injection - MySQL Active MEDIUM MEDIUM
SQL Injection - Hypersonic SQL Active MEDIUM MEDIUM
SQL Injection - Oracle Active MEDIUM MEDIUM
SQL Injection - PostgreSQL Active MEDIUM MEDIUM
Possible Username Enumeration Active MEDIUM MEDIUM
SQL Injection - SQLite Active MEDIUM MEDIUM
Proxy Disclosure Active MEDIUM MEDIUM
Cross Site Scripting (DOM Based) Active MEDIUM MEDIUM
SQL Injection - MsSQL Active MEDIUM MEDIUM
ELMAH Information Leak Active MEDIUM MEDIUM
Trace.axd Information Leak Active MEDIUM MEDIUM
.htaccess Information Leak Active MEDIUM MEDIUM
NoSQL Injection - MongoDB Active MEDIUM MEDIUM
.env Information Leak Active MEDIUM MEDIUM
JWT Scan Rule Active MEDIUM MEDIUM
Bypassing 403 Active MEDIUM MEDIUM
Web Cache Deception Active MEDIUM MEDIUM
Active MEDIUM MEDIUM
Spring Actuator Information Leak Active MEDIUM MEDIUM
Log4Shell Active MEDIUM MEDIUM
Backup File Disclosure Active MEDIUM MEDIUM
HTTP Only Site Active MEDIUM MEDIUM
Httpoxy - Proxy Header Misuse Active MEDIUM MEDIUM
Content Cacheability Passive MEDIUM -
Private IP Disclosure Passive MEDIUM -
Session ID in URL Rewrite Passive MEDIUM -
Cookie without SameSite Attribute Passive MEDIUM -
CSP Passive MEDIUM -
X-Debug-Token Information Leak Passive MEDIUM -
Username Hash Found Passive MEDIUM -
X-AspNet-Version Response Header Passive MEDIUM -
Permissions Policy Header Not Set Passive MEDIUM -
Insecure JSF ViewState Passive MEDIUM -
Script Passive Scan Rules Passive MEDIUM -
Sub Resource Integrity Attribute Missing Passive MEDIUM -
Stats Passive Scan Rule Passive MEDIUM -
Java Serialization Object Passive MEDIUM -
Vulnerable JS Library Passive MEDIUM -
Insufficient Site Isolation Against Spectre Vulnerability Passive MEDIUM -
Use of SAML Passive MEDIUM -
In Page Banner Information Leak Passive MEDIUM -
Charset Mismatch Passive MEDIUM -
Cookie No HttpOnly Flag Passive MEDIUM -
Absence of Anti-CSRF Tokens Passive MEDIUM -
Cookie Without Secure Flag Passive MEDIUM -
Incomplete or No Cache-control Header Set Passive MEDIUM -
Example Passive Scan Rule: Denial of Service Passive MEDIUM -
Cross-Domain JavaScript Source File Inclusion Passive MEDIUM -
An example passive scan rule which loads data from a file. Passive MEDIUM -
Content-Type Header Missing Passive MEDIUM -
Anti-clickjacking Header Passive MEDIUM -
X-Content-Type-Options Header Missing Passive MEDIUM -
Application Error Disclosure Passive MEDIUM -
Information Disclosure - Debug Error Messages Passive MEDIUM -
Information Disclosure - Sensitive Information in URL Passive MEDIUM -
Information Disclosure - Sensitive Information in HTTP Referrer Header Passive MEDIUM -
Information Disclosure - Suspicious Comments Passive MEDIUM -
Base64 Disclosure Passive MEDIUM -
WSDL File Detection Passive MEDIUM -
Loosely Scoped Cookie Passive MEDIUM -
Timestamp Disclosure Passive MEDIUM -
Viewstate Passive MEDIUM -
Cross-Domain Misconfiguration Passive MEDIUM -
Source Code Disclosure Passive MEDIUM -
Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s) Passive MEDIUM -
Secure Pages Include Mixed Content Passive MEDIUM -
Weak Authentication Method Passive MEDIUM -
Dangerous JS Functions Passive MEDIUM -

Sites

https://optimizationguide-pa.googleapis.com

HTTP Response Code Number of Responses

No Authentication Statistics Found

Parameter Name Type Flags Times Used # Values

https://accounts.google.com

HTTP Response Code Number of Responses

No Authentication Statistics Found

Parameter Name Type Flags Times Used # Values

http://192.168.2.47

HTTP Response Code Number of Responses

No Authentication Statistics Found

Parameter Name Type Flags Times Used # Values

Alert Detail

High
Anti-CSRF Tokens Check
Description
A cross-site request forgery is an attack that involves forcing a victim to send an HTTP request to a target destination without their knowledge or intent in order to perform an action as the victim. The underlying cause is application functionality using predictable URL/form actions in a repeatable way. The nature of the attack is that CSRF exploits the trust that a web site has for a user. By contrast, cross-site scripting (XSS) exploits the trust that a user has for a web site. Like XSS, CSRF attacks are not necessarily cross-site, but they can be. Cross-site request forgery is also known as CSRF, XSRF, one-click attack, session riding, confused deputy, and sea surf.

CSRF attacks are effective in a number of situations, including:

* The victim has an active session on the target site.

* The victim is authenticated via HTTP auth on the target site.

* The victim is on the same local network as the target site.

CSRF has primarily been used to perform an action against a target site using the victim's privileges, but recent techniques have been discovered to disclose information by gaining access to the response. The risk of information disclosure is dramatically increased when the target site is vulnerable to XSS, because XSS can be used as a platform for CSRF, allowing the attack to operate within the bounds of the same-origin policy.
URL http://192.168.2.47/online_test/web_standard_onedb//ess/main/view_lateabsent_summary.php
Method GET
Parameter
Attack
Evidence <form name = 'myform' id='myform' style='width:100%;float:right;' method='POST' >
Request Header - size: 623 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,284 bytes.
Response Body - size: 42,831 bytes.
Instances 1
Solution
Phase: Architecture and Design

Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.

For example, use anti-CSRF packages such as the OWASP CSRFGuard.

Phase: Implementation

Ensure that your application is free of cross-site scripting issues, because most CSRF defenses can be bypassed using attacker-controlled script.

Phase: Architecture and Design

Generate a unique nonce for each form, place the nonce into the form, and verify the nonce upon receipt of the form. Be sure that the nonce is not predictable (CWE-330).

Note that this can be bypassed using XSS.

Identify especially dangerous operations. When the user performs a dangerous operation, send a separate confirmation request to ensure that the user intended to perform that operation.

Note that this can be bypassed using XSS.

Use the ESAPI Session Management control.

This control includes a component for CSRF.

Do not use the GET method for any request that triggers a state change.

Phase: Implementation

Check the HTTP Referer header to see if the request originated from an expected page. This could break legitimate functionality, because users or proxies may have disabled sending the Referer for privacy reasons.
Reference http://projects.webappsec.org/Cross-Site-Request-Forgery
http://cwe.mitre.org/data/definitions/352.html
Tags OWASP_2021_A05
WSTG-v42-SESS-05
OWASP_2017_A06
CWE Id 352
WASC Id 9
Plugin Id 20012
Medium
CORS Misconfiguration
Description
This CORS misconfiguration could allow an attacker to perform AJAX queries to the vulnerable website from a malicious page loaded by the victim's user agent.

In order to perform authenticated AJAX queries, the server must specify the header "Access-Control-Allow-Credentials: true" and the "Access-Control-Allow-Origin" header must be set to null or the malicious page's domain. Even if this misconfiguration doesn't allow authenticated AJAX requests, unauthenticated sensitive content can still be accessed (e.g intranet websites).

A malicious page can belong to a malicious website but also a trusted website with flaws (e.g XSS, support of HTTP without TLS allowing code injection through MITM, etc).
URL http://192.168.2.47/online_test/web_standard_onedb//ess/main/view_lateabsent_summary.php
Method GET
Parameter
Attack Origin: http://kKOBxoJL.com
Evidence Access-Control-Allow-Origin: *
Request Header - size: 671 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,284 bytes.
Response Body - size: 42,831 bytes.
Instances 1
Solution
If a web resource contains sensitive information, the origin should be properly specified in the Access-Control-Allow-Origin header. Only trusted websites needing this resource should be specified in this header, with the most secured protocol supported.
Reference https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS
https://portswigger.net/web-security/cors
Tags OWASP_2021_A01
WSTG-v42-CLNT-07
OWASP_2017_A05
CWE Id 942
WASC Id 14
Plugin Id 40040
Medium
Corsair - CORS Misconfigured
Description
Cross Origin Resource Sharing (CORS) is misconfigured.

Test performed: Injecting a fake origin
URL http://192.168.2.47/online_test/web_standard_onedb//ess/main/view_lateabsent_summary.php
Method GET
Parameter Origin
Attack https://example.com
Evidence https://example.com
Request Header - size: 671 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,284 bytes.
Response Body - size: 42,831 bytes.
Instances 1
Solution
Configure CORS in a more restrictive way, to give access only the sites allowed to access your domain.
Reference N/A
Tags
CWE Id 942
WASC Id 14
Plugin Id 50000
Medium
Hidden File Found
Description
A sensitive file was identified as accessible or available. This may leak administrative, configuration, or credential information which can be leveraged by a malicious individual to further attack the system or conduct social engineering efforts.
URL http://192.168.2.47/adminer.php
Method GET
Parameter
Attack
Evidence HTTP/1.1 200 OK
Request Header - size: 585 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,341 bytes.
Response Body - size: 4,296 bytes.
Instances 1
Solution
Consider whether or not the component is actually required in production, if it isn't then disable it. If it is then ensure access to it requires appropriate authentication and authorization, or limit exposure to internal systems or specific source IPs, etc.
Reference https://blog.hboeck.de/archives/892-Introducing-Snallygaster-a-Tool-to-Scan-for-Secrets-on-Web-Servers.html
Tags OWASP_2021_A05
WSTG-v42-CONF-05
OWASP_2017_A06
CWE Id 538
WASC Id 13
Plugin Id 40035
Informational
Cookie Slack Detector
Description
Repeated GET requests: drop a different cookie each time, followed by normal request with all cookies to stabilize session, compare responses against original baseline GET. This can reveal areas where cookie based authentication/attributes are not actually enforced.
URL http://192.168.2.47/online_test/web_standard_onedb//ess/main/view_lateabsent_summary.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 642 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,284 bytes.
Response Body - size: 42,831 bytes.
Instances 1
Solution
Reference http://projects.webappsec.org/Fingerprinting
Tags OWASP_2021_A05
WSTG-v42-SESS-02
OWASP_2017_A06
CWE Id 200
WASC Id 45
Plugin Id 90027
Informational
User Agent Fuzzer
Description
Check for differences in response based on fuzzed User Agent (eg. mobile sites, access as a Search Engine Crawler). Compares the response statuscode and the hashcode of the response body with the original response.
URL http://192.168.2.47/online_test/web_standard_onedb//ess/main/view_lateabsent_summary.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 667 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,284 bytes.
Response Body - size: 42,951 bytes.
Instances 1
Solution
Reference https://owasp.org/wstg
Tags
CWE Id
WASC Id
Plugin Id 10104