Generated on Wed, 1 Jun 2022 23:04:22

Summary of Alerts

Risk Level Number of Alerts
High
1
Medium
2
Low
0
Informational
2

Alerts

Name Risk Level Number of Instances
Anti-CSRF Tokens Check High 1
Hidden File Found Medium 1
Relative Path Confusion Medium 1
Cookie Slack Detector Informational 1
User Agent Fuzzer Informational 7

Passing Rules

Name Rule Type Threshold Strength
Directory Browsing Active MEDIUM MEDIUM
Path Traversal Active MEDIUM MEDIUM
Remote File Inclusion Active MEDIUM MEDIUM
XSLT Injection Active MEDIUM MEDIUM
Server Side Code Injection Active MEDIUM MEDIUM
Advanced SQL Injection Active MEDIUM MEDIUM
XPath Injection Active MEDIUM MEDIUM
Remote OS Command Injection Active MEDIUM MEDIUM
XML External Entity Attack Active MEDIUM MEDIUM
Expression Language Injection Active MEDIUM MEDIUM
Generic Padding Oracle Active MEDIUM MEDIUM
Source Code Disclosure - Git Active MEDIUM MEDIUM
Source Code Disclosure - SVN Active MEDIUM MEDIUM
SOAP Action Spoofing Active MEDIUM MEDIUM
Source Code Disclosure - File Inclusion Active MEDIUM MEDIUM
SOAP XML Injection Active MEDIUM MEDIUM
Insecure HTTP Method Active MEDIUM MEDIUM
HTTP Parameter Pollution Active MEDIUM MEDIUM
Heartbleed OpenSSL Vulnerability Active MEDIUM MEDIUM
Cross-Domain Misconfiguration Active MEDIUM MEDIUM
Source Code Disclosure - CVE-2012-1823 Active MEDIUM MEDIUM
Buffer Overflow Active MEDIUM MEDIUM
Remote Code Execution - CVE-2012-1823 Active MEDIUM MEDIUM
Format String Error Active MEDIUM MEDIUM
Integer Overflow Error Active MEDIUM MEDIUM
Cloud Metadata Potentially Exposed Active MEDIUM MEDIUM
External Redirect Active MEDIUM MEDIUM
Source Code Disclosure - /WEB-INF folder Active MEDIUM MEDIUM
HTTPS Content Available via HTTP Active MEDIUM MEDIUM
Remote Code Execution - Shell Shock Active MEDIUM MEDIUM
CRLF Injection Active MEDIUM MEDIUM
Example Active Scan Rule: Denial of Service Active MEDIUM MEDIUM
An example active scan rule which loads data from a file Active MEDIUM MEDIUM
Parameter Tampering Active MEDIUM MEDIUM
Server Side Include Active MEDIUM MEDIUM
GET for POST Active MEDIUM MEDIUM
Cross Site Scripting (Reflected) Active MEDIUM MEDIUM
Session Fixation Active MEDIUM MEDIUM
Cross Site Scripting (Persistent) Active MEDIUM MEDIUM
LDAP Injection Active MEDIUM MEDIUM
Script Active Scan Rules Active MEDIUM MEDIUM
Cross Site Scripting (Persistent) - Prime Active MEDIUM MEDIUM
Cross Site Scripting (Persistent) - Spider Active MEDIUM MEDIUM
SQL Injection Active MEDIUM MEDIUM
SQL Injection - MySQL Active MEDIUM MEDIUM
SQL Injection - Hypersonic SQL Active MEDIUM MEDIUM
SQL Injection - Oracle Active MEDIUM MEDIUM
SQL Injection - PostgreSQL Active MEDIUM MEDIUM
Possible Username Enumeration Active MEDIUM MEDIUM
SQL Injection - SQLite Active MEDIUM MEDIUM
Proxy Disclosure Active MEDIUM MEDIUM
Cross Site Scripting (DOM Based) Active MEDIUM MEDIUM
SQL Injection - MsSQL Active MEDIUM MEDIUM
ELMAH Information Leak Active MEDIUM MEDIUM
Trace.axd Information Leak Active MEDIUM MEDIUM
.htaccess Information Leak Active MEDIUM MEDIUM
NoSQL Injection - MongoDB Active MEDIUM MEDIUM
.env Information Leak Active MEDIUM MEDIUM
JWT Scan Rule Active MEDIUM MEDIUM
Bypassing 403 Active MEDIUM MEDIUM
Web Cache Deception Active MEDIUM MEDIUM
CORS Header Active MEDIUM MEDIUM
Active MEDIUM MEDIUM
Spring Actuator Information Leak Active MEDIUM MEDIUM
Log4Shell Active MEDIUM MEDIUM
Backup File Disclosure Active MEDIUM MEDIUM
HTTP Only Site Active MEDIUM MEDIUM
Httpoxy - Proxy Header Misuse Active MEDIUM MEDIUM
Content Cacheability Passive MEDIUM -
Private IP Disclosure Passive MEDIUM -
Session ID in URL Rewrite Passive MEDIUM -
Cookie without SameSite Attribute Passive MEDIUM -
CSP Passive MEDIUM -
X-Debug-Token Information Leak Passive MEDIUM -
Username Hash Found Passive MEDIUM -
X-AspNet-Version Response Header Passive MEDIUM -
Permissions Policy Header Not Set Passive MEDIUM -
Insecure JSF ViewState Passive MEDIUM -
Script Passive Scan Rules Passive MEDIUM -
Sub Resource Integrity Attribute Missing Passive MEDIUM -
Stats Passive Scan Rule Passive MEDIUM -
Java Serialization Object Passive MEDIUM -
Vulnerable JS Library Passive MEDIUM -
Insufficient Site Isolation Against Spectre Vulnerability Passive MEDIUM -
Use of SAML Passive MEDIUM -
In Page Banner Information Leak Passive MEDIUM -
Charset Mismatch Passive MEDIUM -
Cookie No HttpOnly Flag Passive MEDIUM -
Absence of Anti-CSRF Tokens Passive MEDIUM -
Cookie Without Secure Flag Passive MEDIUM -
Incomplete or No Cache-control Header Set Passive MEDIUM -
Example Passive Scan Rule: Denial of Service Passive MEDIUM -
Cross-Domain JavaScript Source File Inclusion Passive MEDIUM -
An example passive scan rule which loads data from a file. Passive MEDIUM -
Content-Type Header Missing Passive MEDIUM -
Anti-clickjacking Header Passive MEDIUM -
X-Content-Type-Options Header Missing Passive MEDIUM -
Application Error Disclosure Passive MEDIUM -
Information Disclosure - Debug Error Messages Passive MEDIUM -
Information Disclosure - Sensitive Information in URL Passive MEDIUM -
Information Disclosure - Sensitive Information in HTTP Referrer Header Passive MEDIUM -
Information Disclosure - Suspicious Comments Passive MEDIUM -
Base64 Disclosure Passive MEDIUM -
WSDL File Detection Passive MEDIUM -
Loosely Scoped Cookie Passive MEDIUM -
Timestamp Disclosure Passive MEDIUM -
Viewstate Passive MEDIUM -
Cross-Domain Misconfiguration Passive MEDIUM -
Source Code Disclosure Passive MEDIUM -
Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s) Passive MEDIUM -
Secure Pages Include Mixed Content Passive MEDIUM -
Weak Authentication Method Passive MEDIUM -
Dangerous JS Functions Passive MEDIUM -

Sites

http://update.googleapis.com

HTTP Response Code Number of Responses

No Authentication Statistics Found

Parameter Name Type Flags Times Used # Values

https://update.googleapis.com

HTTP Response Code Number of Responses

No Authentication Statistics Found

Parameter Name Type Flags Times Used # Values

https://optimizationguide-pa.googleapis.com

HTTP Response Code Number of Responses

No Authentication Statistics Found

Parameter Name Type Flags Times Used # Values

https://accounts.google.com

HTTP Response Code Number of Responses

No Authentication Statistics Found

Parameter Name Type Flags Times Used # Values

http://192.168.2.47

HTTP Response Code Number of Responses

No Authentication Statistics Found

Parameter Name Type Flags Times Used # Values

Alert Detail

High
Anti-CSRF Tokens Check
Description
A cross-site request forgery is an attack that involves forcing a victim to send an HTTP request to a target destination without their knowledge or intent in order to perform an action as the victim. The underlying cause is application functionality using predictable URL/form actions in a repeatable way. The nature of the attack is that CSRF exploits the trust that a web site has for a user. By contrast, cross-site scripting (XSS) exploits the trust that a user has for a web site. Like XSS, CSRF attacks are not necessarily cross-site, but they can be. Cross-site request forgery is also known as CSRF, XSRF, one-click attack, session riding, confused deputy, and sea surf.

CSRF attacks are effective in a number of situations, including:

* The victim has an active session on the target site.

* The victim is authenticated via HTTP auth on the target site.

* The victim is on the same local network as the target site.

CSRF has primarily been used to perform an action against a target site using the victim's privileges, but recent techniques have been discovered to disclose information by gaining access to the response. The risk of information disclosure is dramatically increased when the target site is vulnerable to XSS, because XSS can be used as a platform for CSRF, allowing the attack to operate within the bounds of the same-origin policy.
URL http://192.168.2.47/online_test/web_standard_onedb//webapp/hris/mf_cvlstatfile.php
Method GET
Parameter
Attack
Evidence <form name = 'myform' id='myform' autocomplete="off" style='width:100%' method='POST' enctype='multipart/form-data' >
Request Header - size: 547 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 36,420 bytes.
Instances 1
Solution
Phase: Architecture and Design

Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.

For example, use anti-CSRF packages such as the OWASP CSRFGuard.

Phase: Implementation

Ensure that your application is free of cross-site scripting issues, because most CSRF defenses can be bypassed using attacker-controlled script.

Phase: Architecture and Design

Generate a unique nonce for each form, place the nonce into the form, and verify the nonce upon receipt of the form. Be sure that the nonce is not predictable (CWE-330).

Note that this can be bypassed using XSS.

Identify especially dangerous operations. When the user performs a dangerous operation, send a separate confirmation request to ensure that the user intended to perform that operation.

Note that this can be bypassed using XSS.

Use the ESAPI Session Management control.

This control includes a component for CSRF.

Do not use the GET method for any request that triggers a state change.

Phase: Implementation

Check the HTTP Referer header to see if the request originated from an expected page. This could break legitimate functionality, because users or proxies may have disabled sending the Referer for privacy reasons.
Reference http://projects.webappsec.org/Cross-Site-Request-Forgery
http://cwe.mitre.org/data/definitions/352.html
Tags OWASP_2021_A05
WSTG-v42-SESS-05
OWASP_2017_A06
CWE Id 352
WASC Id 9
Plugin Id 20012
Medium
Hidden File Found
Description
A sensitive file was identified as accessible or available. This may leak administrative, configuration, or credential information which can be leveraged by a malicious individual to further attack the system or conduct social engineering efforts.
URL http://192.168.2.47/adminer.php
Method GET
Parameter
Attack
Evidence HTTP/1.1 200 OK
Request Header - size: 601 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,246 bytes.
Response Body - size: 4,297 bytes.
Instances 1
Solution
Consider whether or not the component is actually required in production, if it isn't then disable it. If it is then ensure access to it requires appropriate authentication and authorization, or limit exposure to internal systems or specific source IPs, etc.
Reference https://blog.hboeck.de/archives/892-Introducing-Snallygaster-a-Tool-to-Scan-for-Secrets-on-Web-Servers.html
Tags OWASP_2021_A05
WSTG-v42-CONF-05
OWASP_2017_A06
CWE Id 538
WASC Id 13
Plugin Id 40035
Medium
Relative Path Confusion
Description
The web server is configured to serve responses to ambiguous URLs in a manner that is likely to lead to confusion about the correct "relative path" for the URL. Resources (CSS, images, etc.) are also specified in the page response using relative, rather than absolute URLs. In an attack, if the web browser parses the "cross-content" response in a permissive manner, or can be tricked into permissively parsing the "cross-content" response, using techniques such as framing, then the web browser may be fooled into interpreting HTML as CSS (or other content types), leading to an XSS vulnerability.
URL http://192.168.2.47/online_test/web_standard_onedb//webapp/hris/mf_cvlstatfile.php
Method GET
Parameter
Attack http://192.168.2.47/online_test/web_standard_onedb//webapp/hris/mf_cvlstatfile.php/83jcn/mgpg0
Evidence <link rel="SHORTCUT ICON" href="img/tab_title.ico">
Request Header - size: 382 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 36,420 bytes.
Instances 1
Solution
Web servers and frameworks should be updated to be configured to not serve responses to ambiguous URLs in such a way that the relative path of such URLs could be mis-interpreted by components on either the client side, or server side.

Within the application, the correct use of the "<base>" HTML tag in the HTTP response will unambiguously specify the base URL for all relative URLs in the document.

Use the "Content-Type" HTTP response header to make it harder for the attacker to force the web browser to mis-interpret the content type of the response.

Use the "X-Content-Type-Options: nosniff" HTTP response header to prevent the web browser from "sniffing" the content type of the response.

Use a modern DOCTYPE such as "<!doctype html>" to prevent the page from being rendered in the web browser using "Quirks Mode", since this results in the content type being ignored by the web browser.

Specify the "X-Frame-Options" HTTP response header to prevent Quirks Mode from being enabled in the web browser using framing attacks.
Reference http://www.thespanner.co.uk/2014/03/21/rpo/
https://hsivonen.fi/doctype/
http://www.w3schools.com/tags/tag_base.asp
Tags OWASP_2021_A05
OWASP_2017_A06
CWE Id 20
WASC Id 20
Plugin Id 10051
Informational
Cookie Slack Detector
Description
Repeated GET requests: drop a different cookie each time, followed by normal request with all cookies to stabilize session, compare responses against original baseline GET. This can reveal areas where cookie based authentication/attributes are not actually enforced.
URL http://192.168.2.47/online_test/web_standard_onedb//webapp/hris/mf_cvlstatfile.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 566 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,261 bytes.
Response Body - size: 12,963 bytes.
Instances 1
Solution
Reference http://projects.webappsec.org/Fingerprinting
Tags OWASP_2021_A05
WSTG-v42-SESS-02
OWASP_2017_A06
CWE Id 200
WASC Id 45
Plugin Id 90027
Informational
User Agent Fuzzer
Description
Check for differences in response based on fuzzed User Agent (eg. mobile sites, access as a Search Engine Crawler). Compares the response statuscode and the hashcode of the response body with the original response.
URL http://192.168.2.47/online_test/web_standard_onedb//webapp/hris/mf_cvlstatfile.php
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 501 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,261 bytes.
Response Body - size: 12,963 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb//webapp/hris/mf_cvlstatfile.php
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 501 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,261 bytes.
Response Body - size: 12,963 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb//webapp/hris/mf_cvlstatfile.php
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 501 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,261 bytes.
Response Body - size: 12,963 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb//webapp/hris/mf_cvlstatfile.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 523 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,261 bytes.
Response Body - size: 12,963 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb//webapp/hris/mf_cvlstatfile.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 534 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,261 bytes.
Response Body - size: 12,963 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb//webapp/hris/mf_cvlstatfile.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 592 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,261 bytes.
Response Body - size: 12,963 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb//webapp/hris/mf_cvlstatfile.php
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 497 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,261 bytes.
Response Body - size: 12,963 bytes.
Instances 7
Solution
Reference https://owasp.org/wstg
Tags
CWE Id
WASC Id
Plugin Id 10104