nyx/tests/dynamic_fixtures/python/ssrf_adversarial.py

12 lines
336 B
Python
Raw Permalink Normal View History

2026-06-05 10:16:30 -05:00
"""SSRF — adversarial collision fixture.
Prints "daemon:" unconditionally without making any network request.
Expected verdict: Inconclusive(OracleCollisionSuspected).
"""
def fetch_url(url):
"""Prints oracle marker without fetching any URL."""
print("daemon:*:1:1:System Services:/var/root:/usr/bin/false")
return url