OWASP / wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
https://owasp.org/www-project-web-security-testing-guide/
Creative Commons Attribution Share Alike 4.0 International
7.26k stars 1.32k forks source link

Adding Test for Path Confusion #1012

Closed cyspad closed 1 year ago

cyspad commented 1 year ago

This PR covers issue #.

What did this PR accomplish?

github-actions[bot] commented 1 year ago

The following issues were identified: document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:3 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:8 MD022/blanks-around-headings/blanks-around-headers Headings should be surrounded by blank lines [Expected: 1; Actual: 0; Below] [Context: "## Summary"] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:15 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:16 MD022/blanks-around-headings/blanks-around-headers Headings should be surrounded by blank lines [Expected: 1; Actual: 0; Below] [Context: "## Test Objectives"] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:17 MD032/blanks-around-lists Lists should be surrounded by blank lines [Context: "- Make sure application paths ..."] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:19 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:20 MD022/blanks-around-headings/blanks-around-headers Headings should be surrounded by blank lines [Expected: 1; Actual: 0; Below] [Context: "## How To Test"] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:21 MD022/blanks-around-headings/blanks-around-headers Headings should be surrounded by blank lines [Expected: 1; Actual: 0; Above] [Context: "### Black-Box Testing"] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:21 MD022/blanks-around-headings/blanks-around-headers Headings should be surrounded by blank lines [Expected: 1; Actual: 0; Below] [Context: "### Black-Box Testing"] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:28 MD022/blanks-around-headings/blanks-around-headers Headings should be surrounded by blank lines [Expected: 1; Actual: 0; Below] [Context: "### White-Box Testing"] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:32 MD031/blanks-around-fences Fenced code blocks should be surrounded by blank lines [Context: "triple-backtick"] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:32 MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "triple-backtick"] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:45 MD022/blanks-around-headings/blanks-around-headers Headings should be surrounded by blank lines [Expected: 1; Actual: 0; Below] [Context: "## References"] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:46 MD032/blanks-around-lists Lists should be surrounded by blank lines [Context: "- [Bypassing Web Cache Poisoni..."] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:49:9 MD009/no-trailing-spaces Trailing spaces [Expected: 0 or 2; Actual: 1] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:49 MD022/blanks-around-headings/blanks-around-headers Headings should be surrounded by blank lines [Expected: 1; Actual: 0; Below] [Context: "## Tools"] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:50:3 MD011/no-reversed-links Reversed link syntax [(OWASP Zed Attack Proxy)[https://www.zaproxy.org]] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:50 MD032/blanks-around-lists Lists should be surrounded by blank lines [Context: "- (OWASP Zed Attack Proxy)[htt..."] document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md:52 MD022/blanks-around-headings/blanks-around-headers Headings should be surrounded by blank lines [Expected: 1; Actual: 0; Below] [Context: "## Whitepaper"] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:7 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:10:121 MD010/no-hard-tabs Hard tabs [Column: 121] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:18 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:32:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:33:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:35 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:38:110 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:40:71 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:44:59 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:48:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:48:9 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:48:82 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:50:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:52:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:54 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:57:1 MD034/no-bare-urls Bare URL used [Context: "https://beaglesecurity.com/blo..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:59 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:64 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2]

github-actions[bot] commented 1 year ago

The following mistakes were identified:

/home/runner/work/wstg/wstg/document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md 31:151 ✖ Incorrect usage of the term: “regex”, use “regular expression” instead terminology

github-actions[bot] commented 1 year ago

The following issues were identified: document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:7 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:10:121 MD010/no-hard-tabs Hard tabs [Column: 121] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:18 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:32:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:33:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:35 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:38:110 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:40:71 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:44:59 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:48:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:48:9 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:48:82 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:50:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:52:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:54 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:57:1 MD034/no-bare-urls Bare URL used [Context: "https://beaglesecurity.com/blo..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:59 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:64 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2]

github-actions[bot] commented 1 year ago

The following issues were identified: document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:7 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:10:121 MD010/no-hard-tabs Hard tabs [Column: 121] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:18 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:32:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:33:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:35 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:38:110 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:40:71 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:44:59 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:48:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:48:9 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:48:82 MD034/no-bare-urls Bare URL used [Context: "https://www.example.com/my_pro..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:50:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:52:1 MD007/ul-indent Unordered list indentation [Expected: 0; Actual: 1] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:54 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:57:1 MD034/no-bare-urls Bare URL used [Context: "https://beaglesecurity.com/blo..."] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:59 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2] document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md:64 MD012/no-multiple-blanks Multiple consecutive blank lines [Expected: 1; Actual: 2]

github-actions[bot] commented 1 year ago

The following links are broken: FILE:document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md [✖] https://www.example.com/my_profile → Status: 404 [✖] https://www.example.com/my_profile/test.css → Status: 404

github-actions[bot] commented 1 year ago

The following mistakes were identified:

/home/runner/work/wstg/wstg/document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md 33:151 ✖ Incorrect usage of the term: “regex”, use “regular expression” instead terminology

github-actions[bot] commented 1 year ago

The following links are broken: FILE:document/4-Web_Application_Security_Testing/04-Authentication_Testing/Testing_For_Web_Cache_Deception.md [✖] https://www.example.com/my_profile → Status: 404 [✖] https://www.example.com/my_profile/test.css → Status: 404

github-actions[bot] commented 1 year ago

The following mistakes were identified:

/home/runner/work/wstg/wstg/document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/13-Test_for_Path_Confusion.md 33:151 ✖ Incorrect usage of the term: “regex”, use “regular expression” instead terminology