mirror of
https://github.com/elicpeter/nyx.git
synced 2026-07-21 21:31:03 +02:00
[pitboss] phase 05: M5 — JS/TS, Go, Java, PHP harness emitters
This commit is contained in:
parent
84638e7d57
commit
345b44d3cc
103 changed files with 5637 additions and 34 deletions
|
|
@ -0,0 +1,10 @@
|
|||
{
|
||||
"name": "nyx/escape-composer-postinstall",
|
||||
"description": "Malicious Composer post-install-cmd escape fixture.",
|
||||
"require": {},
|
||||
"scripts": {
|
||||
"post-install-cmd": [
|
||||
"echo NYX_ESCAPE_SUCCESS > /tmp/pwned_composer_postinstall"
|
||||
]
|
||||
}
|
||||
}
|
||||
16
tests/dynamic_fixtures/escape/go_malicious_init.go
Normal file
16
tests/dynamic_fixtures/escape/go_malicious_init.go
Normal file
|
|
@ -0,0 +1,16 @@
|
|||
// Malicious Go init() escape fixture.
|
||||
//
|
||||
// init() runs automatically before the entry point when the binary starts.
|
||||
// Expected: Docker sandbox prevents the write from reaching the host filesystem.
|
||||
// Host marker: /tmp/pwned_go_init
|
||||
// Expected verdict: marker absent on host after sandbox run.
|
||||
package entry
|
||||
|
||||
import "os"
|
||||
|
||||
func init() {
|
||||
// Escape attempt: write a marker file to a path outside the workdir.
|
||||
_ = os.WriteFile("/tmp/pwned_go_init", []byte("NYX_ESCAPE_SUCCESS\n"), 0644)
|
||||
}
|
||||
|
||||
func Login(username string) {}
|
||||
40
tests/dynamic_fixtures/escape/maven_malicious_plugin/pom.xml
Normal file
40
tests/dynamic_fixtures/escape/maven_malicious_plugin/pom.xml
Normal file
|
|
@ -0,0 +1,40 @@
|
|||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!--
|
||||
Malicious Maven plugin escape fixture.
|
||||
The exec-maven-plugin runs a shell command during the validate phase of mvn compile.
|
||||
Expected: Docker-isolated Maven build prevents the write from reaching the host.
|
||||
Host marker: /tmp/pwned_maven_plugin
|
||||
-->
|
||||
<project xmlns="http://maven.apache.org/POM/4.0.0"
|
||||
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
||||
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
<groupId>com.nyx.escape</groupId>
|
||||
<artifactId>malicious-plugin-test</artifactId>
|
||||
<version>1.0.0</version>
|
||||
<build>
|
||||
<plugins>
|
||||
<plugin>
|
||||
<groupId>org.codehaus.mojo</groupId>
|
||||
<artifactId>exec-maven-plugin</artifactId>
|
||||
<version>3.1.0</version>
|
||||
<executions>
|
||||
<execution>
|
||||
<id>escape-attempt</id>
|
||||
<phase>validate</phase>
|
||||
<goals>
|
||||
<goal>exec</goal>
|
||||
</goals>
|
||||
<configuration>
|
||||
<executable>sh</executable>
|
||||
<arguments>
|
||||
<argument>-c</argument>
|
||||
<argument>echo NYX_ESCAPE_SUCCESS > /tmp/pwned_maven_plugin</argument>
|
||||
</arguments>
|
||||
</configuration>
|
||||
</execution>
|
||||
</executions>
|
||||
</plugin>
|
||||
</plugins>
|
||||
</build>
|
||||
</project>
|
||||
|
|
@ -0,0 +1,8 @@
|
|||
{
|
||||
"name": "nyx-escape-npm-lifecycle",
|
||||
"version": "1.0.0",
|
||||
"description": "Malicious npm lifecycle escape fixture — preinstall runs during npm install.",
|
||||
"scripts": {
|
||||
"preinstall": "echo NYX_ESCAPE_SUCCESS > /tmp/pwned_npm_lifecycle"
|
||||
}
|
||||
}
|
||||
15
tests/dynamic_fixtures/go/cmdi_adversarial.go
Normal file
15
tests/dynamic_fixtures/go/cmdi_adversarial.go
Normal file
|
|
@ -0,0 +1,15 @@
|
|||
// Command injection — adversarial collision fixture.
|
||||
// Prints NYX_PWN_CMDI unconditionally without reaching a command sink
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: RunPing(host string) Cap: CODE_EXEC
|
||||
|
||||
package entry
|
||||
|
||||
import "fmt"
|
||||
|
||||
func RunPing(host string) {
|
||||
// Coincidental oracle match — not a shell sink.
|
||||
fmt.Println("NYX_PWN_CMDI")
|
||||
_ = len(host)
|
||||
}
|
||||
18
tests/dynamic_fixtures/go/cmdi_negative.go
Normal file
18
tests/dynamic_fixtures/go/cmdi_negative.go
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
// Command injection — negative fixture.
|
||||
// Safe: passes host as a separate arg to exec.Command (no shell invoked).
|
||||
// Entry: RunPing(host string) Cap: CODE_EXEC
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
package entry
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os/exec"
|
||||
)
|
||||
|
||||
func RunPing(host string) {
|
||||
// exec.Command does not invoke a shell; host is a literal argument.
|
||||
cmd := exec.Command("echo", "hello", host)
|
||||
out, _ := cmd.CombinedOutput()
|
||||
fmt.Print(string(out))
|
||||
}
|
||||
18
tests/dynamic_fixtures/go/cmdi_positive.go
Normal file
18
tests/dynamic_fixtures/go/cmdi_positive.go
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
// Command injection — positive fixture.
|
||||
// Vulnerable: passes user input to /bin/sh -c.
|
||||
// Entry: RunPing(host string) Cap: CODE_EXEC
|
||||
// Expected verdict: Confirmed ("; echo NYX_PWN_CMDI" echoes the marker)
|
||||
|
||||
package entry
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os/exec"
|
||||
)
|
||||
|
||||
func RunPing(host string) {
|
||||
fmt.Print("__NYX_SINK_HIT__\n")
|
||||
cmd := exec.Command("sh", "-c", "echo hello "+host)
|
||||
out, _ := cmd.CombinedOutput()
|
||||
fmt.Print(string(out))
|
||||
}
|
||||
15
tests/dynamic_fixtures/go/cmdi_unsupported.go
Normal file
15
tests/dynamic_fixtures/go/cmdi_unsupported.go
Normal file
|
|
@ -0,0 +1,15 @@
|
|||
// Command injection — unsupported fixture.
|
||||
// Entry is a method on a struct.
|
||||
// Test sets confidence = Low to get Unsupported(ConfidenceTooLow).
|
||||
// Entry: Runner.Execute Cap: CODE_EXEC
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
package entry
|
||||
|
||||
import "os/exec"
|
||||
|
||||
type Runner struct{}
|
||||
|
||||
func (r *Runner) Execute(cmd string) {
|
||||
exec.Command("sh", "-c", cmd).Run()
|
||||
}
|
||||
15
tests/dynamic_fixtures/go/fileio_adversarial.go
Normal file
15
tests/dynamic_fixtures/go/fileio_adversarial.go
Normal file
|
|
@ -0,0 +1,15 @@
|
|||
// File I/O — adversarial collision fixture.
|
||||
// Prints "root:" unconditionally without reading any file
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: ReadFile(userPath string) Cap: FILE_IO
|
||||
|
||||
package entry
|
||||
|
||||
import "fmt"
|
||||
|
||||
func ReadFile(userPath string) {
|
||||
// Coincidental oracle match — not a file read sink.
|
||||
fmt.Println("root: present")
|
||||
_ = len(userPath)
|
||||
}
|
||||
34
tests/dynamic_fixtures/go/fileio_negative.go
Normal file
34
tests/dynamic_fixtures/go/fileio_negative.go
Normal file
|
|
@ -0,0 +1,34 @@
|
|||
// File I/O — negative fixture.
|
||||
// Safe: path is resolved and validated against base directory.
|
||||
// Entry: ReadFile(userPath string) Cap: FILE_IO
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
package entry
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
)
|
||||
|
||||
const baseDir = "/var/data"
|
||||
|
||||
func ReadFile(userPath string) {
|
||||
resolved, err := filepath.Abs(filepath.Join(baseDir, userPath))
|
||||
if err != nil || !strings.HasPrefix(resolved, baseDir+string(filepath.Separator)) {
|
||||
fmt.Println("Access denied")
|
||||
return
|
||||
}
|
||||
data, err := os.ReadFile(resolved)
|
||||
if err == nil {
|
||||
fmt.Print(string(data[:min(len(data), 100)]))
|
||||
}
|
||||
}
|
||||
|
||||
func min(a, b int) int {
|
||||
if a < b {
|
||||
return a
|
||||
}
|
||||
return b
|
||||
}
|
||||
21
tests/dynamic_fixtures/go/fileio_positive.go
Normal file
21
tests/dynamic_fixtures/go/fileio_positive.go
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
// File I/O — positive fixture.
|
||||
// Vulnerable: reads file at user-controlled path without sanitization.
|
||||
// Entry: ReadFile(userPath string) Cap: FILE_IO
|
||||
// Expected verdict: Confirmed (../../../../etc/passwd → "root:" in output)
|
||||
|
||||
package entry
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
)
|
||||
|
||||
func ReadFile(userPath string) {
|
||||
filePath := filepath.Join("/var/data", userPath)
|
||||
fmt.Print("__NYX_SINK_HIT__\n")
|
||||
data, err := os.ReadFile(filePath)
|
||||
if err == nil {
|
||||
fmt.Print(string(data))
|
||||
}
|
||||
}
|
||||
21
tests/dynamic_fixtures/go/fileio_unsupported.go
Normal file
21
tests/dynamic_fixtures/go/fileio_unsupported.go
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
// File I/O — unsupported fixture.
|
||||
// Entry is a method on a struct.
|
||||
// Test sets confidence = Low to get Unsupported(ConfidenceTooLow).
|
||||
// Entry: FileServer.Serve Cap: FILE_IO
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
package entry
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
)
|
||||
|
||||
type FileServer struct{ BaseDir string }
|
||||
|
||||
func (s *FileServer) Serve(path string) {
|
||||
data, err := os.ReadFile(s.BaseDir + "/" + path)
|
||||
if err == nil {
|
||||
fmt.Print(string(data))
|
||||
}
|
||||
}
|
||||
15
tests/dynamic_fixtures/go/sqli_adversarial.go
Normal file
15
tests/dynamic_fixtures/go/sqli_adversarial.go
Normal file
|
|
@ -0,0 +1,15 @@
|
|||
// SQL injection — adversarial collision fixture.
|
||||
// Prints NYX_SQL_CONFIRMED unconditionally without reaching a SQL sink
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: Login(username string) Cap: SQL_QUERY
|
||||
|
||||
package entry
|
||||
|
||||
import "fmt"
|
||||
|
||||
func Login(username string) {
|
||||
// Coincidental oracle match — not a SQL sink.
|
||||
fmt.Println("NYX_SQL_CONFIRMED")
|
||||
_ = len(username)
|
||||
}
|
||||
14
tests/dynamic_fixtures/go/sqli_negative.go
Normal file
14
tests/dynamic_fixtures/go/sqli_negative.go
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
// SQL injection — negative fixture.
|
||||
// Safe: uses a parameterized query; payload is a bound argument, not concatenated.
|
||||
// Entry: Login(username string) Cap: SQL_QUERY
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
package entry
|
||||
|
||||
import "fmt"
|
||||
|
||||
func Login(username string) {
|
||||
template := "SELECT name FROM users WHERE name = ?"
|
||||
// Simulate parameterized execution: template is fixed.
|
||||
fmt.Println("Executing:", template, "with param length:", len(username))
|
||||
}
|
||||
15
tests/dynamic_fixtures/go/sqli_positive.go
Normal file
15
tests/dynamic_fixtures/go/sqli_positive.go
Normal file
|
|
@ -0,0 +1,15 @@
|
|||
// SQL injection — positive fixture.
|
||||
// Vulnerable: directly concatenates user input into SQL query string.
|
||||
// Entry: Login(username string) Cap: SQL_QUERY
|
||||
// Expected verdict: Confirmed (UNION payload echoes NYX_SQL_CONFIRMED)
|
||||
|
||||
package entry
|
||||
|
||||
import "fmt"
|
||||
|
||||
func Login(username string) {
|
||||
query := "SELECT name FROM users WHERE name='" + username + "'"
|
||||
fmt.Print("__NYX_SINK_HIT__\n")
|
||||
// Error-based echo: output the query so UNION payload is visible.
|
||||
fmt.Print("DB query: " + query + "\n")
|
||||
}
|
||||
16
tests/dynamic_fixtures/go/sqli_unsupported.go
Normal file
16
tests/dynamic_fixtures/go/sqli_unsupported.go
Normal file
|
|
@ -0,0 +1,16 @@
|
|||
// SQL injection — unsupported fixture.
|
||||
// Entry is a method on a struct — entry kind unsupported (only Function supported).
|
||||
// Test sets confidence = Low to get Unsupported(ConfidenceTooLow).
|
||||
// Entry: UserRepo.FindUser Cap: SQL_QUERY
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
package entry
|
||||
|
||||
import "fmt"
|
||||
|
||||
type UserRepo struct{}
|
||||
|
||||
func (r *UserRepo) FindUser(name string) {
|
||||
query := "SELECT * FROM users WHERE name='" + name + "'"
|
||||
fmt.Println(query)
|
||||
}
|
||||
15
tests/dynamic_fixtures/go/ssrf_adversarial.go
Normal file
15
tests/dynamic_fixtures/go/ssrf_adversarial.go
Normal file
|
|
@ -0,0 +1,15 @@
|
|||
// SSRF — adversarial collision fixture.
|
||||
// Prints "daemon:" unconditionally without making any HTTP request
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: FetchURL(targetURL string) Cap: SSRF
|
||||
|
||||
package entry
|
||||
|
||||
import "fmt"
|
||||
|
||||
func FetchURL(targetURL string) {
|
||||
// Coincidental oracle match — not an HTTP sink.
|
||||
fmt.Println("daemon: present")
|
||||
_ = len(targetURL)
|
||||
}
|
||||
34
tests/dynamic_fixtures/go/ssrf_negative.go
Normal file
34
tests/dynamic_fixtures/go/ssrf_negative.go
Normal file
|
|
@ -0,0 +1,34 @@
|
|||
// SSRF — negative fixture.
|
||||
// Safe: only allows http/https scheme; file:// rejected.
|
||||
// Entry: FetchURL(targetURL string) Cap: SSRF
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
package entry
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/url"
|
||||
)
|
||||
|
||||
func FetchURL(targetURL string) {
|
||||
parsed, err := url.Parse(targetURL)
|
||||
if err != nil || (parsed.Scheme != "http" && parsed.Scheme != "https") {
|
||||
fmt.Println("Scheme not allowed:", parsed.Scheme)
|
||||
return
|
||||
}
|
||||
resp, err := http.Get(targetURL)
|
||||
if err == nil {
|
||||
defer resp.Body.Close()
|
||||
body, _ := io.ReadAll(resp.Body)
|
||||
fmt.Print(string(body[:min(len(body), 64)]))
|
||||
}
|
||||
}
|
||||
|
||||
func min(a, b int) int {
|
||||
if a < b {
|
||||
return a
|
||||
}
|
||||
return b
|
||||
}
|
||||
33
tests/dynamic_fixtures/go/ssrf_positive.go
Normal file
33
tests/dynamic_fixtures/go/ssrf_positive.go
Normal file
|
|
@ -0,0 +1,33 @@
|
|||
// SSRF — positive fixture.
|
||||
// Vulnerable: makes a request to a user-controlled URL.
|
||||
// Entry: FetchURL(targetURL string) Cap: SSRF
|
||||
// Expected verdict: Confirmed (file:///etc/passwd → "daemon:" in output)
|
||||
// Note: Go http.Get does not support file:// scheme; we detect it and use os.ReadFile.
|
||||
|
||||
package entry
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
"os"
|
||||
"strings"
|
||||
)
|
||||
|
||||
func FetchURL(targetURL string) {
|
||||
fmt.Print("__NYX_SINK_HIT__\n")
|
||||
if strings.HasPrefix(targetURL, "file://") {
|
||||
path := strings.TrimPrefix(targetURL, "file://")
|
||||
data, err := os.ReadFile(path)
|
||||
if err == nil {
|
||||
fmt.Print(string(data))
|
||||
}
|
||||
return
|
||||
}
|
||||
resp, err := http.Get(targetURL)
|
||||
if err == nil {
|
||||
defer resp.Body.Close()
|
||||
body, _ := io.ReadAll(resp.Body)
|
||||
fmt.Print(string(body))
|
||||
}
|
||||
}
|
||||
20
tests/dynamic_fixtures/go/ssrf_unsupported.go
Normal file
20
tests/dynamic_fixtures/go/ssrf_unsupported.go
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
// SSRF — unsupported fixture.
|
||||
// Entry is a method on a struct; test sets confidence = Low.
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
package entry
|
||||
|
||||
import (
|
||||
"io"
|
||||
"net/http"
|
||||
)
|
||||
|
||||
type HTTPClient struct{}
|
||||
|
||||
func (c *HTTPClient) Fetch(targetURL string) {
|
||||
resp, err := http.Get(targetURL)
|
||||
if err == nil {
|
||||
defer resp.Body.Close()
|
||||
io.Copy(io.Discard, resp.Body)
|
||||
}
|
||||
}
|
||||
15
tests/dynamic_fixtures/go/xss_adversarial.go
Normal file
15
tests/dynamic_fixtures/go/xss_adversarial.go
Normal file
|
|
@ -0,0 +1,15 @@
|
|||
// XSS — adversarial collision fixture.
|
||||
// Prints the XSS oracle marker unconditionally without rendering any template
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: RenderPage(userInput string) Cap: HTML_ESCAPE
|
||||
|
||||
package entry
|
||||
|
||||
import "fmt"
|
||||
|
||||
func RenderPage(userInput string) {
|
||||
// Coincidental oracle match — not an HTML render sink.
|
||||
fmt.Println("<script>NYX_XSS_CONFIRMED</script>")
|
||||
_ = len(userInput)
|
||||
}
|
||||
16
tests/dynamic_fixtures/go/xss_negative.go
Normal file
16
tests/dynamic_fixtures/go/xss_negative.go
Normal file
|
|
@ -0,0 +1,16 @@
|
|||
// XSS — negative fixture.
|
||||
// Safe: uses html.EscapeString before output.
|
||||
// Entry: RenderPage(userInput string) Cap: HTML_ESCAPE
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
package entry
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"html"
|
||||
)
|
||||
|
||||
func RenderPage(userInput string) {
|
||||
safe := html.EscapeString(userInput)
|
||||
fmt.Print("<html><body>" + safe + "</body></html>\n")
|
||||
}
|
||||
13
tests/dynamic_fixtures/go/xss_positive.go
Normal file
13
tests/dynamic_fixtures/go/xss_positive.go
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// XSS — positive fixture.
|
||||
// Vulnerable: echoes raw user input into HTML output without escaping.
|
||||
// Entry: RenderPage(userInput string) Cap: HTML_ESCAPE
|
||||
// Expected verdict: Confirmed (<script>NYX_XSS_CONFIRMED</script> echoed)
|
||||
|
||||
package entry
|
||||
|
||||
import "fmt"
|
||||
|
||||
func RenderPage(userInput string) {
|
||||
fmt.Print("__NYX_SINK_HIT__\n")
|
||||
fmt.Print("<html><body>" + userInput + "</body></html>\n")
|
||||
}
|
||||
13
tests/dynamic_fixtures/go/xss_unsupported.go
Normal file
13
tests/dynamic_fixtures/go/xss_unsupported.go
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// XSS — unsupported fixture.
|
||||
// Entry is a method on a struct; test sets confidence = Low.
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
package entry
|
||||
|
||||
import "fmt"
|
||||
|
||||
type Renderer struct{}
|
||||
|
||||
func (r *Renderer) Render(input string) {
|
||||
fmt.Print("<html><body>" + input + "</body></html>\n")
|
||||
}
|
||||
13
tests/dynamic_fixtures/java/cmdi_adversarial.java
Normal file
13
tests/dynamic_fixtures/java/cmdi_adversarial.java
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// Command injection — adversarial collision fixture.
|
||||
// Prints NYX_PWN_CMDI unconditionally without reaching a command sink
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: Entry.runPing(String) Cap: CODE_EXEC
|
||||
|
||||
public class Entry {
|
||||
public static void runPing(String host) {
|
||||
// Coincidental oracle match — not a shell sink.
|
||||
System.out.println("NYX_PWN_CMDI");
|
||||
int x = host.length();
|
||||
}
|
||||
}
|
||||
20
tests/dynamic_fixtures/java/cmdi_negative.java
Normal file
20
tests/dynamic_fixtures/java/cmdi_negative.java
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
// Command injection — negative fixture.
|
||||
// Safe: exec with args array; no shell; semicolons are inert.
|
||||
// Entry: Entry.runPing(String) Cap: CODE_EXEC
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
import java.io.*;
|
||||
|
||||
public class Entry {
|
||||
public static void runPing(String host) throws Exception {
|
||||
// Array form: each element is a literal argument — no shell expansion.
|
||||
String[] cmd = {"echo", "hello", host};
|
||||
Process p = Runtime.getRuntime().exec(cmd);
|
||||
BufferedReader reader = new BufferedReader(new InputStreamReader(p.getInputStream()));
|
||||
String line;
|
||||
while ((line = reader.readLine()) != null) {
|
||||
System.out.println(line);
|
||||
}
|
||||
p.waitFor();
|
||||
}
|
||||
}
|
||||
20
tests/dynamic_fixtures/java/cmdi_positive.java
Normal file
20
tests/dynamic_fixtures/java/cmdi_positive.java
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
// Command injection — positive fixture.
|
||||
// Vulnerable: passes user input to /bin/sh -c via Runtime.exec.
|
||||
// Entry: Entry.runPing(String) Cap: CODE_EXEC
|
||||
// Expected verdict: Confirmed ("; echo NYX_PWN_CMDI" echoes the marker)
|
||||
|
||||
import java.io.*;
|
||||
|
||||
public class Entry {
|
||||
public static void runPing(String host) throws Exception {
|
||||
System.out.print("__NYX_SINK_HIT__\n");
|
||||
String[] cmd = {"/bin/sh", "-c", "echo hello " + host};
|
||||
Process p = Runtime.getRuntime().exec(cmd);
|
||||
BufferedReader reader = new BufferedReader(new InputStreamReader(p.getInputStream()));
|
||||
String line;
|
||||
while ((line = reader.readLine()) != null) {
|
||||
System.out.println(line);
|
||||
}
|
||||
p.waitFor();
|
||||
}
|
||||
}
|
||||
11
tests/dynamic_fixtures/java/cmdi_unsupported.java
Normal file
11
tests/dynamic_fixtures/java/cmdi_unsupported.java
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
// Command injection — unsupported fixture.
|
||||
// Entry is an instance method; test sets confidence = Low.
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
import java.io.*;
|
||||
|
||||
public class Entry {
|
||||
public void execute(String cmd) throws Exception {
|
||||
Runtime.getRuntime().exec(new String[]{"/bin/sh", "-c", cmd});
|
||||
}
|
||||
}
|
||||
13
tests/dynamic_fixtures/java/fileio_adversarial.java
Normal file
13
tests/dynamic_fixtures/java/fileio_adversarial.java
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// File I/O — adversarial collision fixture.
|
||||
// Prints "root:" unconditionally without reading any file
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: Entry.readFile(String) Cap: FILE_IO
|
||||
|
||||
public class Entry {
|
||||
public static void readFile(String userPath) {
|
||||
// Coincidental oracle match — not a file read sink.
|
||||
System.out.println("root: present");
|
||||
int x = userPath.length();
|
||||
}
|
||||
}
|
||||
27
tests/dynamic_fixtures/java/fileio_negative.java
Normal file
27
tests/dynamic_fixtures/java/fileio_negative.java
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
// File I/O — negative fixture.
|
||||
// Safe: normalizes path and checks it stays within the base directory.
|
||||
// Entry: Entry.readFile(String) Cap: FILE_IO
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
import java.io.*;
|
||||
import java.nio.file.*;
|
||||
|
||||
public class Entry {
|
||||
private static final String BASE_DIR = "/var/data";
|
||||
|
||||
public static void readFile(String userPath) throws Exception {
|
||||
Path base = Paths.get(BASE_DIR).toRealPath();
|
||||
Path resolved = base.resolve(userPath).normalize();
|
||||
if (!resolved.startsWith(base)) {
|
||||
System.out.println("Access denied");
|
||||
return;
|
||||
}
|
||||
try {
|
||||
byte[] data = Files.readAllBytes(resolved);
|
||||
int len = Math.min(data.length, 100);
|
||||
System.out.write(data, 0, len);
|
||||
} catch (IOException e) {
|
||||
System.out.println("File not found");
|
||||
}
|
||||
}
|
||||
}
|
||||
20
tests/dynamic_fixtures/java/fileio_positive.java
Normal file
20
tests/dynamic_fixtures/java/fileio_positive.java
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
// File I/O — positive fixture.
|
||||
// Vulnerable: reads file at user-controlled path without sanitization.
|
||||
// Entry: Entry.readFile(String) Cap: FILE_IO
|
||||
// Expected verdict: Confirmed (../../../../etc/passwd → "root:" in output)
|
||||
|
||||
import java.io.*;
|
||||
import java.nio.file.*;
|
||||
|
||||
public class Entry {
|
||||
public static void readFile(String userPath) throws Exception {
|
||||
Path filePath = Paths.get("/var/data", userPath);
|
||||
System.out.print("__NYX_SINK_HIT__\n");
|
||||
try {
|
||||
String content = new String(Files.readAllBytes(filePath));
|
||||
System.out.print(content);
|
||||
} catch (IOException e) {
|
||||
// silent
|
||||
}
|
||||
}
|
||||
}
|
||||
13
tests/dynamic_fixtures/java/fileio_unsupported.java
Normal file
13
tests/dynamic_fixtures/java/fileio_unsupported.java
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// File I/O — unsupported fixture.
|
||||
// Entry is an instance method; test sets confidence = Low.
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
import java.io.*;
|
||||
import java.nio.file.*;
|
||||
|
||||
public class Entry {
|
||||
public void serve(String path) throws Exception {
|
||||
byte[] data = Files.readAllBytes(Paths.get(path));
|
||||
System.out.write(data);
|
||||
}
|
||||
}
|
||||
13
tests/dynamic_fixtures/java/sqli_adversarial.java
Normal file
13
tests/dynamic_fixtures/java/sqli_adversarial.java
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// SQL injection — adversarial collision fixture.
|
||||
// Prints NYX_SQL_CONFIRMED unconditionally without reaching a SQL sink
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: Entry.login(String) Cap: SQL_QUERY
|
||||
|
||||
public class Entry {
|
||||
public static void login(String username) {
|
||||
// Coincidental oracle match — not a SQL sink.
|
||||
System.out.println("NYX_SQL_CONFIRMED");
|
||||
int x = username.length();
|
||||
}
|
||||
}
|
||||
12
tests/dynamic_fixtures/java/sqli_negative.java
Normal file
12
tests/dynamic_fixtures/java/sqli_negative.java
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
// SQL injection — negative fixture.
|
||||
// Safe: uses a parameterized query; payload is a bound argument.
|
||||
// Entry: Entry.login(String) Cap: SQL_QUERY
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
public class Entry {
|
||||
public static void login(String username) {
|
||||
String template = "SELECT name FROM users WHERE name = ?";
|
||||
// Simulate parameterized execution: template is fixed.
|
||||
System.out.println("Executing: " + template + " param-len=" + username.length());
|
||||
}
|
||||
}
|
||||
13
tests/dynamic_fixtures/java/sqli_positive.java
Normal file
13
tests/dynamic_fixtures/java/sqli_positive.java
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// SQL injection — positive fixture.
|
||||
// Vulnerable: directly concatenates user input into SQL query string.
|
||||
// Entry: Entry.login(String) Cap: SQL_QUERY
|
||||
// Expected verdict: Confirmed (UNION payload echoes NYX_SQL_CONFIRMED)
|
||||
|
||||
public class Entry {
|
||||
public static void login(String username) {
|
||||
String query = "SELECT name FROM users WHERE name='" + username + "'";
|
||||
System.out.print("__NYX_SINK_HIT__\n");
|
||||
// Error-based echo: output the query so UNION payload is visible.
|
||||
System.out.println("DB query: " + query);
|
||||
}
|
||||
}
|
||||
11
tests/dynamic_fixtures/java/sqli_unsupported.java
Normal file
11
tests/dynamic_fixtures/java/sqli_unsupported.java
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
// SQL injection — unsupported fixture.
|
||||
// Entry is an instance method rather than a static method.
|
||||
// Test sets confidence = Low to get Unsupported(ConfidenceTooLow).
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
public class Entry {
|
||||
public void findUser(String name) {
|
||||
String query = "SELECT * FROM users WHERE name='" + name + "'";
|
||||
System.out.println(query);
|
||||
}
|
||||
}
|
||||
13
tests/dynamic_fixtures/java/ssrf_adversarial.java
Normal file
13
tests/dynamic_fixtures/java/ssrf_adversarial.java
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// SSRF — adversarial collision fixture.
|
||||
// Prints "daemon:" unconditionally without making any HTTP request
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: Entry.fetchUrl(String) Cap: SSRF
|
||||
|
||||
public class Entry {
|
||||
public static void fetchUrl(String targetUrl) {
|
||||
// Coincidental oracle match — not an HTTP sink.
|
||||
System.out.println("daemon: present");
|
||||
int x = targetUrl.length();
|
||||
}
|
||||
}
|
||||
27
tests/dynamic_fixtures/java/ssrf_negative.java
Normal file
27
tests/dynamic_fixtures/java/ssrf_negative.java
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
// SSRF — negative fixture.
|
||||
// Safe: only allows http/https scheme; file:// rejected.
|
||||
// Entry: Entry.fetchUrl(String) Cap: SSRF
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
import java.io.*;
|
||||
import java.net.*;
|
||||
|
||||
public class Entry {
|
||||
public static void fetchUrl(String targetUrl) throws Exception {
|
||||
URL url = new URL(targetUrl);
|
||||
String proto = url.getProtocol();
|
||||
if (!proto.equals("http") && !proto.equals("https")) {
|
||||
System.out.println("Scheme not allowed: " + proto);
|
||||
return;
|
||||
}
|
||||
try (InputStream in = url.openStream();
|
||||
BufferedReader reader = new BufferedReader(new InputStreamReader(in))) {
|
||||
String line;
|
||||
while ((line = reader.readLine()) != null) {
|
||||
System.out.println(line.substring(0, Math.min(line.length(), 64)));
|
||||
}
|
||||
} catch (Exception e) {
|
||||
System.out.println("Connection error");
|
||||
}
|
||||
}
|
||||
}
|
||||
24
tests/dynamic_fixtures/java/ssrf_positive.java
Normal file
24
tests/dynamic_fixtures/java/ssrf_positive.java
Normal file
|
|
@ -0,0 +1,24 @@
|
|||
// SSRF — positive fixture.
|
||||
// Vulnerable: makes a request to a user-controlled URL.
|
||||
// Entry: Entry.fetchUrl(String) Cap: SSRF
|
||||
// Expected verdict: Confirmed (file:///etc/passwd → "daemon:" in output)
|
||||
// Note: Java URL supports file:// scheme natively.
|
||||
|
||||
import java.io.*;
|
||||
import java.net.*;
|
||||
|
||||
public class Entry {
|
||||
public static void fetchUrl(String targetUrl) throws Exception {
|
||||
System.out.print("__NYX_SINK_HIT__\n");
|
||||
URL url = new URL(targetUrl);
|
||||
try (InputStream in = url.openStream();
|
||||
BufferedReader reader = new BufferedReader(new InputStreamReader(in))) {
|
||||
String line;
|
||||
while ((line = reader.readLine()) != null) {
|
||||
System.out.println(line);
|
||||
}
|
||||
} catch (Exception e) {
|
||||
// silent
|
||||
}
|
||||
}
|
||||
}
|
||||
12
tests/dynamic_fixtures/java/ssrf_unsupported.java
Normal file
12
tests/dynamic_fixtures/java/ssrf_unsupported.java
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
// SSRF — unsupported fixture.
|
||||
// Entry is an instance method; test sets confidence = Low.
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
import java.io.*;
|
||||
import java.net.*;
|
||||
|
||||
public class Entry {
|
||||
public void fetch(String url) throws Exception {
|
||||
new URL(url).openStream().close();
|
||||
}
|
||||
}
|
||||
13
tests/dynamic_fixtures/java/xss_adversarial.java
Normal file
13
tests/dynamic_fixtures/java/xss_adversarial.java
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// XSS — adversarial collision fixture.
|
||||
// Prints the XSS oracle marker unconditionally without rendering any template
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: Entry.renderPage(String) Cap: HTML_ESCAPE
|
||||
|
||||
public class Entry {
|
||||
public static void renderPage(String userInput) {
|
||||
// Coincidental oracle match — not an HTML render sink.
|
||||
System.out.println("<script>NYX_XSS_CONFIRMED</script>");
|
||||
int x = userInput.length();
|
||||
}
|
||||
}
|
||||
19
tests/dynamic_fixtures/java/xss_negative.java
Normal file
19
tests/dynamic_fixtures/java/xss_negative.java
Normal file
|
|
@ -0,0 +1,19 @@
|
|||
// XSS — negative fixture.
|
||||
// Safe: HTML-encodes special characters before output.
|
||||
// Entry: Entry.renderPage(String) Cap: HTML_ESCAPE
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
public class Entry {
|
||||
private static String escapeHtml(String s) {
|
||||
return s.replace("&", "&")
|
||||
.replace("<", "<")
|
||||
.replace(">", ">")
|
||||
.replace("\"", """)
|
||||
.replace("'", "'");
|
||||
}
|
||||
|
||||
public static void renderPage(String userInput) {
|
||||
String safe = escapeHtml(userInput);
|
||||
System.out.print("<html><body>" + safe + "</body></html>\n");
|
||||
}
|
||||
}
|
||||
11
tests/dynamic_fixtures/java/xss_positive.java
Normal file
11
tests/dynamic_fixtures/java/xss_positive.java
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
// XSS — positive fixture.
|
||||
// Vulnerable: echoes raw user input into HTML output without escaping.
|
||||
// Entry: Entry.renderPage(String) Cap: HTML_ESCAPE
|
||||
// Expected verdict: Confirmed (<script>NYX_XSS_CONFIRMED</script> echoed)
|
||||
|
||||
public class Entry {
|
||||
public static void renderPage(String userInput) {
|
||||
System.out.print("__NYX_SINK_HIT__\n");
|
||||
System.out.print("<html><body>" + userInput + "</body></html>\n");
|
||||
}
|
||||
}
|
||||
9
tests/dynamic_fixtures/java/xss_unsupported.java
Normal file
9
tests/dynamic_fixtures/java/xss_unsupported.java
Normal file
|
|
@ -0,0 +1,9 @@
|
|||
// XSS — unsupported fixture.
|
||||
// Entry is an instance method; test sets confidence = Low.
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
public class Entry {
|
||||
public void render(String input) {
|
||||
System.out.print("<html><body>" + input + "</body></html>\n");
|
||||
}
|
||||
}
|
||||
13
tests/dynamic_fixtures/js/cmdi_adversarial.js
Normal file
13
tests/dynamic_fixtures/js/cmdi_adversarial.js
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// Command injection — adversarial collision fixture.
|
||||
// Prints NYX_PWN_CMDI unconditionally without reaching a command sink
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: runPing(host) Cap: CODE_EXEC
|
||||
|
||||
function runPing(host) {
|
||||
// Coincidental oracle match — not a shell sink.
|
||||
process.stdout.write('NYX_PWN_CMDI\n');
|
||||
void host.length;
|
||||
}
|
||||
|
||||
module.exports = { runPing };
|
||||
18
tests/dynamic_fixtures/js/cmdi_negative.js
Normal file
18
tests/dynamic_fixtures/js/cmdi_negative.js
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
// Command injection — negative fixture.
|
||||
// Safe: uses execFile (no shell) with args array; shell metacharacters ignored.
|
||||
// Entry: runPing(host) Cap: CODE_EXEC
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
const { execFileSync } = require('child_process');
|
||||
|
||||
function runPing(host) {
|
||||
// execFile does not invoke a shell — semicolons and metacharacters are inert.
|
||||
try {
|
||||
const out = execFileSync('echo', ['hello', host], { encoding: 'utf8', timeout: 5000 });
|
||||
process.stdout.write(out);
|
||||
} catch (e) {
|
||||
process.stdout.write('error\n');
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = { runPing };
|
||||
18
tests/dynamic_fixtures/js/cmdi_positive.js
Normal file
18
tests/dynamic_fixtures/js/cmdi_positive.js
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
// Command injection — positive fixture.
|
||||
// Vulnerable: passes user input directly to shell via execSync.
|
||||
// Entry: runPing(host) Cap: CODE_EXEC
|
||||
// Expected verdict: Confirmed ("; echo NYX_PWN_CMDI" payload echoes marker)
|
||||
|
||||
const { execSync } = require('child_process');
|
||||
|
||||
function runPing(host) {
|
||||
process.stdout.write('__NYX_SINK_HIT__\n');
|
||||
try {
|
||||
const out = execSync('echo hello ' + host, { encoding: 'utf8', timeout: 5000 });
|
||||
process.stdout.write(out);
|
||||
} catch (e) {
|
||||
process.stdout.write((e.stdout || '') + (e.stderr || ''));
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = { runPing };
|
||||
17
tests/dynamic_fixtures/js/cmdi_unsupported.js
Normal file
17
tests/dynamic_fixtures/js/cmdi_unsupported.js
Normal file
|
|
@ -0,0 +1,17 @@
|
|||
// Command injection — unsupported fixture.
|
||||
// Entry expects a pre-parsed args array, not a string payload.
|
||||
// Test sets confidence = Low to get Unsupported(ConfidenceTooLow).
|
||||
// Entry: runCommand(args) Cap: CODE_EXEC
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
const { execFileSync } = require('child_process');
|
||||
|
||||
function runCommand(args) {
|
||||
// args is expected to be an array; a string payload can't be routed here.
|
||||
if (!Array.isArray(args) || args.length === 0) {
|
||||
return;
|
||||
}
|
||||
execFileSync(args[0], args.slice(1), { encoding: 'utf8', timeout: 5000 });
|
||||
}
|
||||
|
||||
module.exports = { runCommand };
|
||||
13
tests/dynamic_fixtures/js/fileio_adversarial.js
Normal file
13
tests/dynamic_fixtures/js/fileio_adversarial.js
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// File I/O — adversarial collision fixture.
|
||||
// Prints "root:" unconditionally without reading any file
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: readFile(userPath) Cap: FILE_IO
|
||||
|
||||
function readFile(userPath) {
|
||||
// Coincidental oracle match — not a file read sink.
|
||||
process.stdout.write('root: present\n');
|
||||
void userPath.length;
|
||||
}
|
||||
|
||||
module.exports = { readFile };
|
||||
25
tests/dynamic_fixtures/js/fileio_negative.js
Normal file
25
tests/dynamic_fixtures/js/fileio_negative.js
Normal file
|
|
@ -0,0 +1,25 @@
|
|||
// File I/O — negative fixture.
|
||||
// Safe: path is normalized and validated against an allowlist prefix.
|
||||
// Entry: readFile(userPath) Cap: FILE_IO
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
const fs = require('fs');
|
||||
const path = require('path');
|
||||
|
||||
const BASE_DIR = '/var/data';
|
||||
|
||||
function readFile(userPath) {
|
||||
const resolved = path.resolve(BASE_DIR, userPath);
|
||||
if (!resolved.startsWith(BASE_DIR + path.sep) && resolved !== BASE_DIR) {
|
||||
process.stdout.write('Access denied\n');
|
||||
return;
|
||||
}
|
||||
try {
|
||||
const content = fs.readFileSync(resolved, 'utf8');
|
||||
process.stdout.write(content.substring(0, 100));
|
||||
} catch (e) {
|
||||
process.stdout.write('File not found\n');
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = { readFile };
|
||||
20
tests/dynamic_fixtures/js/fileio_positive.js
Normal file
20
tests/dynamic_fixtures/js/fileio_positive.js
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
// File I/O — positive fixture.
|
||||
// Vulnerable: reads a file at a user-controlled path without sanitization.
|
||||
// Entry: readFile(userPath) Cap: FILE_IO
|
||||
// Expected verdict: Confirmed (../../../../etc/passwd → "root:" in output)
|
||||
|
||||
const fs = require('fs');
|
||||
const path = require('path');
|
||||
|
||||
function readFile(userPath) {
|
||||
const filePath = path.join('/var/data', userPath);
|
||||
process.stdout.write('__NYX_SINK_HIT__\n');
|
||||
try {
|
||||
const content = fs.readFileSync(filePath, 'utf8');
|
||||
process.stdout.write(content);
|
||||
} catch (e) {
|
||||
// Silent on error — target file may not exist in all envs
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = { readFile };
|
||||
20
tests/dynamic_fixtures/js/fileio_unsupported.js
Normal file
20
tests/dynamic_fixtures/js/fileio_unsupported.js
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
// File I/O — unsupported fixture.
|
||||
// Entry takes a Buffer (binary), not a UTF-8 string payload.
|
||||
// Test sets confidence = Low to get Unsupported(ConfidenceTooLow).
|
||||
// Entry: processUpload(buf) Cap: FILE_IO
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
const fs = require('fs');
|
||||
|
||||
function processUpload(buf) {
|
||||
if (!Buffer.isBuffer(buf)) {
|
||||
return;
|
||||
}
|
||||
const tmpPath = '/tmp/upload_' + Date.now();
|
||||
fs.writeFileSync(tmpPath, buf);
|
||||
const content = fs.readFileSync(tmpPath, 'utf8');
|
||||
process.stdout.write(content.substring(0, 64));
|
||||
fs.unlinkSync(tmpPath);
|
||||
}
|
||||
|
||||
module.exports = { processUpload };
|
||||
14
tests/dynamic_fixtures/js/sqli_adversarial.js
Normal file
14
tests/dynamic_fixtures/js/sqli_adversarial.js
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
// SQL injection — adversarial collision fixture.
|
||||
// Prints NYX_SQL_CONFIRMED unconditionally without reaching a SQL sink
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// oracle_fired = true, sink_hit = false
|
||||
// Entry: login(username) Cap: SQL_QUERY
|
||||
|
||||
function login(username) {
|
||||
// Coincidental oracle match — not a SQL sink.
|
||||
process.stdout.write('NYX_SQL_CONFIRMED\n');
|
||||
void username.length;
|
||||
}
|
||||
|
||||
module.exports = { login };
|
||||
14
tests/dynamic_fixtures/js/sqli_negative.js
Normal file
14
tests/dynamic_fixtures/js/sqli_negative.js
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
// SQL injection — negative fixture.
|
||||
// Safe: uses a parameterized query pattern; payload never concatenated.
|
||||
// Entry: login(username) Cap: SQL_QUERY
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
function login(username) {
|
||||
// Parameterized: the query template is fixed, payload is a bound param.
|
||||
const template = 'SELECT name FROM users WHERE name = ?';
|
||||
// Simulate param binding — payload is never embedded in the query string.
|
||||
const safeQuery = template; // template unchanged regardless of username
|
||||
process.stdout.write('Query executed with param: ' + safeQuery + '\n');
|
||||
}
|
||||
|
||||
module.exports = { login };
|
||||
13
tests/dynamic_fixtures/js/sqli_positive.js
Normal file
13
tests/dynamic_fixtures/js/sqli_positive.js
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// SQL injection — positive fixture.
|
||||
// Vulnerable: directly concatenates user input into SQL query string.
|
||||
// Entry: login(username) Cap: SQL_QUERY
|
||||
// Expected verdict: Confirmed (UNION payload echoes NYX_SQL_CONFIRMED)
|
||||
|
||||
function login(username) {
|
||||
const query = "SELECT name FROM users WHERE name='" + username + "'";
|
||||
process.stdout.write('__NYX_SINK_HIT__\n');
|
||||
// Simulate error-based SQL execution: echo query on failure.
|
||||
process.stdout.write('DB query: ' + query + '\n');
|
||||
}
|
||||
|
||||
module.exports = { login };
|
||||
15
tests/dynamic_fixtures/js/sqli_unsupported.js
Normal file
15
tests/dynamic_fixtures/js/sqli_unsupported.js
Normal file
|
|
@ -0,0 +1,15 @@
|
|||
// SQL injection — unsupported fixture.
|
||||
// The entry point accepts an HTTP request object, not a plain string.
|
||||
// HarnessSpec derivation will map this to HttpBody slot (unsupported by JS emitter).
|
||||
// Entry: handleRequest(req) Cap: SQL_QUERY
|
||||
// Expected verdict: Unsupported (EntryKindUnsupported or ConfidenceTooLow)
|
||||
|
||||
class UserRepository {
|
||||
findUser(req) {
|
||||
const name = req && req.body && req.body.name;
|
||||
const query = "SELECT * FROM users WHERE name='" + name + "'";
|
||||
return query;
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = { UserRepository };
|
||||
13
tests/dynamic_fixtures/js/ssrf_adversarial.js
Normal file
13
tests/dynamic_fixtures/js/ssrf_adversarial.js
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// SSRF — adversarial collision fixture.
|
||||
// Prints "daemon:" unconditionally without making any HTTP request
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: fetchUrl(targetUrl) Cap: SSRF
|
||||
|
||||
function fetchUrl(targetUrl) {
|
||||
// Coincidental oracle match — not an HTTP sink.
|
||||
process.stdout.write('daemon: present\n');
|
||||
void targetUrl.length;
|
||||
}
|
||||
|
||||
module.exports = { fetchUrl };
|
||||
24
tests/dynamic_fixtures/js/ssrf_negative.js
Normal file
24
tests/dynamic_fixtures/js/ssrf_negative.js
Normal file
|
|
@ -0,0 +1,24 @@
|
|||
// SSRF — negative fixture.
|
||||
// Safe: only allows http/https scheme; file:// and other schemes are rejected.
|
||||
// Entry: fetchUrl(targetUrl) Cap: SSRF
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
const http = require('http');
|
||||
const https = require('https');
|
||||
const url = require('url');
|
||||
|
||||
function fetchUrl(targetUrl) {
|
||||
const parsed = url.parse(targetUrl);
|
||||
if (parsed.protocol !== 'http:' && parsed.protocol !== 'https:') {
|
||||
process.stdout.write('Scheme not allowed: ' + parsed.protocol + '\n');
|
||||
return;
|
||||
}
|
||||
const mod = parsed.protocol === 'https:' ? https : http;
|
||||
const req = mod.get(targetUrl, (res) => {
|
||||
res.on('data', (chunk) => process.stdout.write(chunk.toString().substring(0, 64)));
|
||||
});
|
||||
req.on('error', () => {});
|
||||
req.end();
|
||||
}
|
||||
|
||||
module.exports = { fetchUrl };
|
||||
35
tests/dynamic_fixtures/js/ssrf_positive.js
Normal file
35
tests/dynamic_fixtures/js/ssrf_positive.js
Normal file
|
|
@ -0,0 +1,35 @@
|
|||
// SSRF — positive fixture.
|
||||
// Vulnerable: makes a request to a user-controlled URL.
|
||||
// Entry: fetch(url) Cap: SSRF
|
||||
// Expected verdict: Confirmed (file:///etc/passwd → "daemon:" in output)
|
||||
// Note: Node.js http/https module does not support file:// scheme.
|
||||
// We detect the file:// prefix and use fs.readFile directly to simulate
|
||||
// the SSRF behaviour (same oracle: reads /etc/passwd, outputs "daemon:").
|
||||
|
||||
const fs = require('fs');
|
||||
const http = require('http');
|
||||
const https = require('https');
|
||||
const url = require('url');
|
||||
|
||||
function fetchUrl(targetUrl) {
|
||||
process.stdout.write('__NYX_SINK_HIT__\n');
|
||||
const parsed = url.parse(targetUrl);
|
||||
if (parsed.protocol === 'file:') {
|
||||
// Simulate SSRF via file:// — read local file (oracle expects "daemon:")
|
||||
try {
|
||||
const content = fs.readFileSync(parsed.pathname || '/', 'utf8');
|
||||
process.stdout.write(content);
|
||||
} catch (e) {
|
||||
// silent
|
||||
}
|
||||
return;
|
||||
}
|
||||
const mod = parsed.protocol === 'https:' ? https : http;
|
||||
const req = mod.get(targetUrl, (res) => {
|
||||
res.on('data', (chunk) => process.stdout.write(chunk));
|
||||
});
|
||||
req.on('error', () => {});
|
||||
req.end();
|
||||
}
|
||||
|
||||
module.exports = { fetchUrl };
|
||||
20
tests/dynamic_fixtures/js/ssrf_unsupported.js
Normal file
20
tests/dynamic_fixtures/js/ssrf_unsupported.js
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
// SSRF — unsupported fixture.
|
||||
// Entry takes an already-parsed URL object, not a string.
|
||||
// Test sets confidence = Low to get Unsupported(ConfidenceTooLow).
|
||||
// Entry: fetchParsed(parsedUrl) Cap: SSRF
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
const http = require('http');
|
||||
|
||||
function fetchParsed(parsedUrl) {
|
||||
if (!parsedUrl || typeof parsedUrl !== 'object') {
|
||||
return;
|
||||
}
|
||||
const req = http.get(parsedUrl, (res) => {
|
||||
res.on('data', (d) => process.stdout.write(d));
|
||||
});
|
||||
req.on('error', () => {});
|
||||
req.end();
|
||||
}
|
||||
|
||||
module.exports = { fetchParsed };
|
||||
13
tests/dynamic_fixtures/js/xss_adversarial.js
Normal file
13
tests/dynamic_fixtures/js/xss_adversarial.js
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// XSS — adversarial collision fixture.
|
||||
// Prints the XSS oracle marker unconditionally without rendering any template
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: renderPage(userInput) Cap: HTML_ESCAPE
|
||||
|
||||
function renderPage(userInput) {
|
||||
// Coincidental oracle match — not an HTML render sink.
|
||||
process.stdout.write('<script>NYX_XSS_CONFIRMED</script>\n');
|
||||
void userInput.length;
|
||||
}
|
||||
|
||||
module.exports = { renderPage };
|
||||
20
tests/dynamic_fixtures/js/xss_negative.js
Normal file
20
tests/dynamic_fixtures/js/xss_negative.js
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
// XSS — negative fixture.
|
||||
// Safe: HTML-escapes all special characters before output.
|
||||
// Entry: renderPage(userInput) Cap: HTML_ESCAPE
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
function escapeHtml(str) {
|
||||
return String(str)
|
||||
.replace(/&/g, '&')
|
||||
.replace(/</g, '<')
|
||||
.replace(/>/g, '>')
|
||||
.replace(/"/g, '"')
|
||||
.replace(/'/g, ''');
|
||||
}
|
||||
|
||||
function renderPage(userInput) {
|
||||
const safe = escapeHtml(userInput);
|
||||
process.stdout.write('<html><body>' + safe + '</body></html>\n');
|
||||
}
|
||||
|
||||
module.exports = { renderPage };
|
||||
12
tests/dynamic_fixtures/js/xss_positive.js
Normal file
12
tests/dynamic_fixtures/js/xss_positive.js
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
// XSS — positive fixture.
|
||||
// Vulnerable: echoes raw user input into HTML output without escaping.
|
||||
// Entry: renderPage(userInput) Cap: HTML_ESCAPE
|
||||
// Expected verdict: Confirmed (<script>NYX_XSS_CONFIRMED</script> echoed)
|
||||
|
||||
function renderPage(userInput) {
|
||||
process.stdout.write('__NYX_SINK_HIT__\n');
|
||||
// Unescaped output — script tags pass through verbatim.
|
||||
process.stdout.write('<html><body>' + userInput + '</body></html>\n');
|
||||
}
|
||||
|
||||
module.exports = { renderPage };
|
||||
13
tests/dynamic_fixtures/js/xss_unsupported.js
Normal file
13
tests/dynamic_fixtures/js/xss_unsupported.js
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
// XSS — unsupported fixture.
|
||||
// Entry is a class method rather than a top-level function.
|
||||
// Test sets confidence = Low to get Unsupported(ConfidenceTooLow).
|
||||
// Entry: TemplateEngine.render(input) Cap: HTML_ESCAPE
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
class TemplateEngine {
|
||||
render(input) {
|
||||
return '<html><body>' + input + '</body></html>';
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = { TemplateEngine };
|
||||
12
tests/dynamic_fixtures/php/cmdi_adversarial.php
Normal file
12
tests/dynamic_fixtures/php/cmdi_adversarial.php
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
<?php
|
||||
// Command injection — adversarial collision fixture.
|
||||
// Prints NYX_PWN_CMDI unconditionally without reaching a command sink
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: runPing($host) Cap: CODE_EXEC
|
||||
|
||||
function runPing($host) {
|
||||
// Coincidental oracle match — not a shell sink.
|
||||
echo "NYX_PWN_CMDI\n";
|
||||
$x = strlen($host);
|
||||
}
|
||||
14
tests/dynamic_fixtures/php/cmdi_negative.php
Normal file
14
tests/dynamic_fixtures/php/cmdi_negative.php
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
<?php
|
||||
// Command injection — negative fixture.
|
||||
// Safe: uses escapeshellarg() to prevent shell injection.
|
||||
// Entry: runPing($host) Cap: CODE_EXEC
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
function runPing($host) {
|
||||
// escapeshellarg wraps in single quotes and escapes internal quotes.
|
||||
$safe = escapeshellarg($host);
|
||||
$output = shell_exec('echo hello ' . $safe);
|
||||
if ($output !== null) {
|
||||
echo $output;
|
||||
}
|
||||
}
|
||||
13
tests/dynamic_fixtures/php/cmdi_positive.php
Normal file
13
tests/dynamic_fixtures/php/cmdi_positive.php
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
<?php
|
||||
// Command injection — positive fixture.
|
||||
// Vulnerable: passes user input directly to shell_exec.
|
||||
// Entry: runPing($host) Cap: CODE_EXEC
|
||||
// Expected verdict: Confirmed ("; echo NYX_PWN_CMDI" echoes the marker)
|
||||
|
||||
function runPing($host) {
|
||||
echo "__NYX_SINK_HIT__\n";
|
||||
$output = shell_exec('echo hello ' . $host);
|
||||
if ($output !== null) {
|
||||
echo $output;
|
||||
}
|
||||
}
|
||||
10
tests/dynamic_fixtures/php/cmdi_unsupported.php
Normal file
10
tests/dynamic_fixtures/php/cmdi_unsupported.php
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
<?php
|
||||
// Command injection — unsupported fixture.
|
||||
// Entry is a class method; test sets confidence = Low.
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
class Runner {
|
||||
public function execute($cmd) {
|
||||
shell_exec($cmd);
|
||||
}
|
||||
}
|
||||
12
tests/dynamic_fixtures/php/fileio_adversarial.php
Normal file
12
tests/dynamic_fixtures/php/fileio_adversarial.php
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
<?php
|
||||
// File I/O — adversarial collision fixture.
|
||||
// Prints "root:" unconditionally without reading any file
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: readFile($userPath) Cap: FILE_IO
|
||||
|
||||
function readFile($userPath) {
|
||||
// Coincidental oracle match — not a file read sink.
|
||||
echo "root: present\n";
|
||||
$x = strlen($userPath);
|
||||
}
|
||||
20
tests/dynamic_fixtures/php/fileio_negative.php
Normal file
20
tests/dynamic_fixtures/php/fileio_negative.php
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
<?php
|
||||
// File I/O — negative fixture.
|
||||
// Safe: realpath + prefix validation prevents directory traversal.
|
||||
// Entry: readFile($userPath) Cap: FILE_IO
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
function readFile($userPath) {
|
||||
$baseDir = '/var/data';
|
||||
$filePath = realpath($baseDir . '/' . $userPath);
|
||||
if ($filePath === false || strpos($filePath, $baseDir . DIRECTORY_SEPARATOR) !== 0) {
|
||||
echo "Access denied\n";
|
||||
return;
|
||||
}
|
||||
$content = @file_get_contents($filePath);
|
||||
if ($content !== false) {
|
||||
echo substr($content, 0, 100);
|
||||
} else {
|
||||
echo "File not found\n";
|
||||
}
|
||||
}
|
||||
14
tests/dynamic_fixtures/php/fileio_positive.php
Normal file
14
tests/dynamic_fixtures/php/fileio_positive.php
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
<?php
|
||||
// File I/O — positive fixture.
|
||||
// Vulnerable: reads file at user-controlled path without sanitization.
|
||||
// Entry: readFile($userPath) Cap: FILE_IO
|
||||
// Expected verdict: Confirmed (../../../../etc/passwd → "root:" in output)
|
||||
|
||||
function readFile($userPath) {
|
||||
$filePath = '/var/data/' . $userPath;
|
||||
echo "__NYX_SINK_HIT__\n";
|
||||
$content = @file_get_contents($filePath);
|
||||
if ($content !== false) {
|
||||
echo $content;
|
||||
}
|
||||
}
|
||||
13
tests/dynamic_fixtures/php/fileio_unsupported.php
Normal file
13
tests/dynamic_fixtures/php/fileio_unsupported.php
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
<?php
|
||||
// File I/O — unsupported fixture.
|
||||
// Entry is a class method; test sets confidence = Low.
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
class FileServer {
|
||||
public function serve($path) {
|
||||
$content = @file_get_contents($path);
|
||||
if ($content !== false) {
|
||||
echo $content;
|
||||
}
|
||||
}
|
||||
}
|
||||
12
tests/dynamic_fixtures/php/sqli_adversarial.php
Normal file
12
tests/dynamic_fixtures/php/sqli_adversarial.php
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
<?php
|
||||
// SQL injection — adversarial collision fixture.
|
||||
// Prints NYX_SQL_CONFIRMED unconditionally without reaching a SQL sink
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: login($username) Cap: SQL_QUERY
|
||||
|
||||
function login($username) {
|
||||
// Coincidental oracle match — not a SQL sink.
|
||||
echo "NYX_SQL_CONFIRMED\n";
|
||||
$x = strlen($username);
|
||||
}
|
||||
11
tests/dynamic_fixtures/php/sqli_negative.php
Normal file
11
tests/dynamic_fixtures/php/sqli_negative.php
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
<?php
|
||||
// SQL injection — negative fixture.
|
||||
// Safe: uses PDO prepared statement; payload is a bound param, not concatenated.
|
||||
// Entry: login($username) Cap: SQL_QUERY
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
function login($username) {
|
||||
$template = "SELECT name FROM users WHERE name = ?";
|
||||
// Simulate parameterized execution: template is fixed.
|
||||
echo "Executing: " . $template . " param-len=" . strlen($username) . "\n";
|
||||
}
|
||||
12
tests/dynamic_fixtures/php/sqli_positive.php
Normal file
12
tests/dynamic_fixtures/php/sqli_positive.php
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
<?php
|
||||
// SQL injection — positive fixture.
|
||||
// Vulnerable: directly concatenates user input into SQL query string.
|
||||
// Entry: login($username) Cap: SQL_QUERY
|
||||
// Expected verdict: Confirmed (UNION payload echoes NYX_SQL_CONFIRMED)
|
||||
|
||||
function login($username) {
|
||||
$query = "SELECT name FROM users WHERE name='" . $username . "'";
|
||||
echo "__NYX_SINK_HIT__\n";
|
||||
// Error-based echo: output the query so UNION payload is visible.
|
||||
echo "DB query: " . $query . "\n";
|
||||
}
|
||||
12
tests/dynamic_fixtures/php/sqli_unsupported.php
Normal file
12
tests/dynamic_fixtures/php/sqli_unsupported.php
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
<?php
|
||||
// SQL injection — unsupported fixture.
|
||||
// Entry is a class method — entry kind unsupported.
|
||||
// Test sets confidence = Low to get Unsupported(ConfidenceTooLow).
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
class UserRepository {
|
||||
public function findUser($name) {
|
||||
$query = "SELECT * FROM users WHERE name='" . $name . "'";
|
||||
echo $query . "\n";
|
||||
}
|
||||
}
|
||||
12
tests/dynamic_fixtures/php/ssrf_adversarial.php
Normal file
12
tests/dynamic_fixtures/php/ssrf_adversarial.php
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
<?php
|
||||
// SSRF — adversarial collision fixture.
|
||||
// Prints "daemon:" unconditionally without making any HTTP request
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: fetchUrl($url) Cap: SSRF
|
||||
|
||||
function fetchUrl($url) {
|
||||
// Coincidental oracle match — not an HTTP sink.
|
||||
echo "daemon: present\n";
|
||||
$x = strlen($url);
|
||||
}
|
||||
18
tests/dynamic_fixtures/php/ssrf_negative.php
Normal file
18
tests/dynamic_fixtures/php/ssrf_negative.php
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
<?php
|
||||
// SSRF — negative fixture.
|
||||
// Safe: only allows http/https scheme; file:// and others rejected.
|
||||
// Entry: fetchUrl($url) Cap: SSRF
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
function fetchUrl($url) {
|
||||
$parsed = parse_url($url);
|
||||
$scheme = $parsed['scheme'] ?? '';
|
||||
if ($scheme !== 'http' && $scheme !== 'https') {
|
||||
echo "Scheme not allowed: " . $scheme . "\n";
|
||||
return;
|
||||
}
|
||||
$content = @file_get_contents($url);
|
||||
if ($content !== false) {
|
||||
echo substr($content, 0, 64);
|
||||
}
|
||||
}
|
||||
14
tests/dynamic_fixtures/php/ssrf_positive.php
Normal file
14
tests/dynamic_fixtures/php/ssrf_positive.php
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
<?php
|
||||
// SSRF — positive fixture.
|
||||
// Vulnerable: fetches a user-controlled URL via file_get_contents.
|
||||
// PHP's file_get_contents supports file:// scheme natively.
|
||||
// Entry: fetchUrl($url) Cap: SSRF
|
||||
// Expected verdict: Confirmed (file:///etc/passwd → "daemon:" in output)
|
||||
|
||||
function fetchUrl($url) {
|
||||
echo "__NYX_SINK_HIT__\n";
|
||||
$content = @file_get_contents($url);
|
||||
if ($content !== false) {
|
||||
echo $content;
|
||||
}
|
||||
}
|
||||
13
tests/dynamic_fixtures/php/ssrf_unsupported.php
Normal file
13
tests/dynamic_fixtures/php/ssrf_unsupported.php
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
<?php
|
||||
// SSRF — unsupported fixture.
|
||||
// Entry is a class method; test sets confidence = Low.
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
class HttpClient {
|
||||
public function fetch($url) {
|
||||
$content = @file_get_contents($url);
|
||||
if ($content !== false) {
|
||||
echo $content;
|
||||
}
|
||||
}
|
||||
}
|
||||
12
tests/dynamic_fixtures/php/xss_adversarial.php
Normal file
12
tests/dynamic_fixtures/php/xss_adversarial.php
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
<?php
|
||||
// XSS — adversarial collision fixture.
|
||||
// Prints the XSS oracle marker unconditionally without rendering any template
|
||||
// and without emitting __NYX_SINK_HIT__.
|
||||
// Expected verdict: Inconclusive(OracleCollisionSuspected)
|
||||
// Entry: renderPage($userInput) Cap: HTML_ESCAPE
|
||||
|
||||
function renderPage($userInput) {
|
||||
// Coincidental oracle match — not an HTML render sink.
|
||||
echo "<script>NYX_XSS_CONFIRMED</script>\n";
|
||||
$x = strlen($userInput);
|
||||
}
|
||||
10
tests/dynamic_fixtures/php/xss_negative.php
Normal file
10
tests/dynamic_fixtures/php/xss_negative.php
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
<?php
|
||||
// XSS — negative fixture.
|
||||
// Safe: uses htmlspecialchars() before output.
|
||||
// Entry: renderPage($userInput) Cap: HTML_ESCAPE
|
||||
// Expected verdict: NotConfirmed
|
||||
|
||||
function renderPage($userInput) {
|
||||
$safe = htmlspecialchars($userInput, ENT_QUOTES, 'UTF-8');
|
||||
echo '<html><body>' . $safe . '</body></html>' . "\n";
|
||||
}
|
||||
10
tests/dynamic_fixtures/php/xss_positive.php
Normal file
10
tests/dynamic_fixtures/php/xss_positive.php
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
<?php
|
||||
// XSS — positive fixture.
|
||||
// Vulnerable: echoes raw user input into HTML output without escaping.
|
||||
// Entry: renderPage($userInput) Cap: HTML_ESCAPE
|
||||
// Expected verdict: Confirmed (<script>NYX_XSS_CONFIRMED</script> echoed)
|
||||
|
||||
function renderPage($userInput) {
|
||||
echo "__NYX_SINK_HIT__\n";
|
||||
echo '<html><body>' . $userInput . '</body></html>' . "\n";
|
||||
}
|
||||
10
tests/dynamic_fixtures/php/xss_unsupported.php
Normal file
10
tests/dynamic_fixtures/php/xss_unsupported.php
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
<?php
|
||||
// XSS — unsupported fixture.
|
||||
// Entry is a class method; test sets confidence = Low.
|
||||
// Expected verdict: Unsupported
|
||||
|
||||
class TemplateEngine {
|
||||
public function render($input) {
|
||||
echo '<html><body>' . $input . '</body></html>' . "\n";
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue