mirror of
https://github.com/elicpeter/nyx.git
synced 2026-06-18 20:15:14 +02:00
Dynamic (#77)
This commit is contained in:
parent
55247b7fcd
commit
991c84a1eb
1464 changed files with 225448 additions and 1985 deletions
13
tests/dynamic_fixtures/python/xss_adversarial.py
Normal file
13
tests/dynamic_fixtures/python/xss_adversarial.py
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
"""XSS — adversarial collision fixture.
|
||||
|
||||
Outputs the XSS marker string unconditionally without it being a real
|
||||
HTML sink (e.g., a test that checks for a string literal).
|
||||
Expected verdict: Inconclusive(OracleCollisionSuspected).
|
||||
"""
|
||||
|
||||
|
||||
def render_comment(user_input):
|
||||
"""Prints oracle marker outside of any HTML rendering context."""
|
||||
# Coincidental match — not an HTML sink.
|
||||
print("<script>NYX_XSS_CONFIRMED</script>")
|
||||
return user_input
|
||||
Loading…
Add table
Add a link
Reference in a new issue