Open asriz7777 opened 5 years ago
Project : FXABAC TEST
Template : ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1
Run Id : 8a808011699a990101699ab3901a2277
Job : Default
Env : Default
Category : Hijack_Level1
Tags : [FX Top 10 - API Vulnerability, Data_Access_Control]
Severity : Major
Region : FXLabs/US_WEST_1
Result : fail
Status Code : 400
Headers : {X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZTAwMjk4NDctNWMzMy00MDBmLTk5OTctOTZkNTZkYTE0Yjlh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:30 GMT]}
Endpoint : http://13.56.210.25/api/v1/autocode-generator
Request :
{
"abacResources" : [ {
"createBody" : "D30Vjc9l",
"createEndpoint" : "D30Vjc9l",
"createUserAuth" : "D30Vjc9l",
"createdBy" : "",
"createdDate" : "",
"deleteEndpoint" : "D30Vjc9l",
"enumValues" : "D30Vjc9l",
"generatorId" : "D30Vjc9l",
"id" : "",
"inactive" : false,
"initScriptName" : "D30Vjc9l",
"lock" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"resourceName" : "D30Vjc9l",
"scripts" : [ {
"body" : "D30Vjc9l",
"deleteEndPoint" : "D30Vjc9l",
"endpoint" : "D30Vjc9l",
"resourceName" : "D30Vjc9l",
"scriptName" : "D30Vjc9l",
"scriptType" : "D30Vjc9l",
"sequence" : "2035536466",
"userAuth" : "D30Vjc9l",
"validationScript" : false
} ],
"typeThreeCreateEndpoint" : "D30Vjc9l",
"validations" : [ {
"body" : "D30Vjc9l",
"endpoint" : "D30Vjc9l",
"inactive" : false,
"lock" : false,
"path" : "D30Vjc9l",
"userAuth" : "D30Vjc9l",
"validationType" : "D30Vjc9l"
} ],
"version" : ""
} ],
"assertionDescription" : "D30Vjc9l",
"assertions" : [ "D30Vjc9l" ],
"assertionsText" : "D30Vjc9l",
"authors" : "D30Vjc9l",
"category" : "SQL_Injection",
"coverageMultiplier" : "2035536466",
"currentScripts" : "2035536466",
"database" : {
"name" : "D30Vjc9l",
"version" : ""
},
"displayHeaderDescription" : "D30Vjc9l",
"displayHeaderLabel" : "D30Vjc9l",
"expectedScripts" : "2035536466",
"fixHours" : "D30Vjc9l",
"id" : "",
"inactive" : false,
"matches" : [ {
"allowRoles" : "D30Vjc9l",
"bodyProperties" : "D30Vjc9l",
"denyRoles" : "D30Vjc9l",
"id" : "",
"methods" : "D30Vjc9l",
"name" : "D30Vjc9l",
"pathPatterns" : "D30Vjc9l",
"queryParams" : "D30Vjc9l",
"resourceSamples" : "D30Vjc9l",
"value" : "D30Vjc9l"
} ],
"newlyAdded" : false,
"project" : "",
"sequenceOrder" : "2035536466",
"severity" : "Major",
"tags" : [ "D30Vjc9l" ],
"type" : "D30Vjc9l"
}
Response :
{
"timestamp" : "2019-03-20T10:44:30.983+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 71, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.AutoCodeGenerator[\"project\"])",
"path" : "/api/v1/autocode-generator"
}
Logs :
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/orgs]
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1] : Request [{
"billingEmail" : "giiSxxBS",
"company" : "Waters-Waters",
"createdBy" : "",
"createdDate" : "",
"description" : "giiSxxBS",
"id" : "",
"inactive" : false,
"location" : "giiSxxBS",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "giiSxxBS",
"orgPlan" : "TEAM",
"orgType" : "ENTERPRISE",
"version" : ""
}]
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:26.556+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/orgs"
}]
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTgyYjU1YTMtOTYxNS00NjFlLWFjN2EtZjIwNWIyNGNkNWEz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:25 GMT]}]
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1] : StatusCode [403]
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1] : Time [600]
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1] : Size [121]
2019-03-20 10:44:26 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTgyYjU1YTMtOTYxNS00NjFlLWFjN2EtZjIwNWIyNGNkNWEz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:25 GMT]}]
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTgyYjU1YTMtOTYxNS00NjFlLWFjN2EtZjIwNWIyNGNkNWEz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:25 GMT]}]
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTgyYjU1YTMtOTYxNS00NjFlLWFjN2EtZjIwNWIyNGNkNWEz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:25 GMT]}]
2019-03-20 10:44:26 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTgyYjU1YTMtOTYxNS00NjFlLWFjN2EtZjIwNWIyNGNkNWEz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:25 GMT]}]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/accounts]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1] : Request [{
"accessKey" : "P9VMCjmg",
"accountType" : "GitLab",
"createdBy" : "",
"createdDate" : "",
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "P9VMCjmg",
"org" : "",
"prop1" : "P9VMCjmg",
"prop2" : "P9VMCjmg",
"prop3" : "P9VMCjmg",
"region" : "P9VMCjmg",
"secretKey" : "P9VMCjmg",
"version" : ""
}]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:27.100+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 11, column: 11] (through reference chain: com.fxlabs.fxt.dto.clusters.Account[\"org\"])",
"path" : "/api/v1/accounts"
}]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZjdhYjk0N2ItYmEzMC00ZGQ1LTkwNGQtYmJhYzBkMGNmYjAy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:26 GMT]}]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1] : Time [542]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1] : Size [722]
2019-03-20 10:44:27 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZjdhYjk0N2ItYmEzMC00ZGQ1LTkwNGQtYmJhYzBkMGNmYjAy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:26 GMT]}]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZjdhYjk0N2ItYmEzMC00ZGQ1LTkwNGQtYmJhYzBkMGNmYjAy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:26 GMT]}]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZjdhYjk0N2ItYmEzMC00ZGQ1LTkwNGQtYmJhYzBkMGNmYjAy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:26 GMT]}]
2019-03-20 10:44:27 DEBUG [AccountCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZjdhYjk0N2ItYmEzMC00ZGQ1LTkwNGQtYmJhYzBkMGNmYjAy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:26 GMT]}]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/skills]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1] : Request [{
"accessKey" : "XqZfADIk",
"createdBy" : "",
"createdDate" : "",
"description" : "XqZfADIk",
"host" : "XqZfADIk",
"id" : "",
"inactive" : false,
"key" : "XqZfADIk",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "XqZfADIk",
"org" : "",
"prop1" : "XqZfADIk",
"prop2" : "XqZfADIk",
"prop3" : "XqZfADIk",
"prop4" : "XqZfADIk",
"prop5" : "XqZfADIk",
"secretKey" : "XqZfADIk",
"skillType" : "BOT_DEPLOYMENT",
"version" : ""
}]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:27.584+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 13, column: 11] (through reference chain: com.fxlabs.fxt.dto.skills.Skill[\"org\"])",
"path" : "/api/v1/skills"
}]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MzViYjczZTEtZDFkOC00Njc4LTkyMmYtMGYwNzVjYmQ3MTBi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:26 GMT]}]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1] : Time [482]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1] : Size [716]
2019-03-20 10:44:27 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MzViYjczZTEtZDFkOC00Njc4LTkyMmYtMGYwNzVjYmQ3MTBi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:26 GMT]}]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MzViYjczZTEtZDFkOC00Njc4LTkyMmYtMGYwNzVjYmQ3MTBi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:26 GMT]}]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MzViYjczZTEtZDFkOC00Njc4LTkyMmYtMGYwNzVjYmQ3MTBi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:26 GMT]}]
2019-03-20 10:44:27 DEBUG [SkillCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MzViYjczZTEtZDFkOC00Njc4LTkyMmYtMGYwNzVjYmQ3MTBi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:26 GMT]}]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/issue-trackers/issue-tracker-bot]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1] : Request [{
"account" : "",
"createdBy" : "",
"createdDate" : "",
"description" : "y5qqghAa",
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "y5qqghAa",
"org" : "",
"prop1" : "y5qqghAa",
"prop2" : "y5qqghAa",
"prop3" : "y5qqghAa",
"prop4" : "y5qqghAa",
"prop5" : "y5qqghAa",
"skill" : "",
"state" : "INACTIVE",
"version" : "",
"visibility" : "ORG_PUBLIC"
}]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:28.211+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 2, column: 15] (through reference chain: com.fxlabs.fxt.dto.it.IssueTracker[\"account\"])",
"path" : "/api/v1/issue-trackers/issue-tracker-bot"
}]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YTk2OTdjMmQtNTVlMS00YjZiLWJmNDQtMmE0ZjRmYTFjZDU0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:27 GMT]}]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1] : Time [622]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1] : Size [768]
2019-03-20 10:44:28 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YTk2OTdjMmQtNTVlMS00YjZiLWJmNDQtMmE0ZjRmYTFjZDU0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:27 GMT]}]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YTk2OTdjMmQtNTVlMS00YjZiLWJmNDQtMmE0ZjRmYTFjZDU0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:27 GMT]}]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YTk2OTdjMmQtNTVlMS00YjZiLWJmNDQtMmE0ZjRmYTFjZDU0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:27 GMT]}]
2019-03-20 10:44:28 DEBUG [IssueTrackerCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YTk2OTdjMmQtNTVlMS00YjZiLWJmNDQtMmE0ZjRmYTFjZDU0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:27 GMT]}]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/projects]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1] : Request [{
"account" : "",
"autoGenSuites" : "116908008",
"branch" : "3W2tLBgv",
"bugsOpen" : "116908008",
"createdBy" : "",
"createdDate" : "",
"description" : "3W2tLBgv",
"genPolicy" : "Create",
"id" : "",
"inactive" : false,
"isFileLoad" : "3W2tLBgv",
"issueTracker" : "",
"lastCommit" : "3W2tLBgv",
"lastSync" : null,
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "3W2tLBgv",
"openAPISpec" : "3W2tLBgv",
"openText" : "3W2tLBgv",
"org" : "",
"props" : null,
"url" : "3W2tLBgv",
"version" : ""
}]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:28.880+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 2, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.Project[\"account\"])",
"path" : "/api/v1/projects"
}]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTcwN2ZlZTItYWIyZi00NWU5LWFjZjQtOTg2NDJhYmFhZmEy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:28 GMT]}]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1] : Time [665]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1] : Size [744]
2019-03-20 10:44:28 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTcwN2ZlZTItYWIyZi00NWU5LWFjZjQtOTg2NDJhYmFhZmEy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:28 GMT]}]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTcwN2ZlZTItYWIyZi00NWU5LWFjZjQtOTg2NDJhYmFhZmEy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:28 GMT]}]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTcwN2ZlZTItYWIyZi00NWU5LWFjZjQtOTg2NDJhYmFhZmEy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:28 GMT]}]
2019-03-20 10:44:28 DEBUG [ProjectCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTcwN2ZlZTItYWIyZi00NWU5LWFjZjQtOTg2NDJhYmFhZmEy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:28 GMT]}]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/autocode-generator]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Request [{
"assertionDescription" : "OniZUVYD",
"assertionsText" : "OniZUVYD",
"authors" : "OniZUVYD",
"category" : "ABAC_Level1_Positive",
"coverageMultiplier" : "579387045",
"currentScripts" : "579387045",
"database" : {
"name" : "OniZUVYD",
"version" : ""
},
"displayHeaderDescription" : "OniZUVYD",
"displayHeaderLabel" : "OniZUVYD",
"expectedScripts" : "579387045",
"fixHours" : "OniZUVYD",
"id" : "",
"inactive" : false,
"newlyAdded" : false,
"project" : "",
"sequenceOrder" : "579387045",
"severity" : "Major",
"type" : "OniZUVYD"
}]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:29.651+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 19, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.AutoCodeGenerator[\"project\"])",
"path" : "/api/v1/autocode-generator"
}]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YWQ3ODAzYmQtYWRjYi00NjJkLWEzZDMtZmU3Mjc4MTRlNjdh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:28 GMT]}]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Time [770]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Size [751]
2019-03-20 10:44:29 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YWQ3ODAzYmQtYWRjYi00NjJkLWEzZDMtZmU3Mjc4MTRlNjdh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:28 GMT]}]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YWQ3ODAzYmQtYWRjYi00NjJkLWEzZDMtZmU3Mjc4MTRlNjdh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:28 GMT]}]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YWQ3ODAzYmQtYWRjYi00NjJkLWEzZDMtZmU3Mjc4MTRlNjdh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:28 GMT]}]
2019-03-20 10:44:29 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YWQ3ODAzYmQtYWRjYi00NjJkLWEzZDMtZmU3Mjc4MTRlNjdh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:28 GMT]}]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1] : URL [http://13.56.210.25/api/v1/projects]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1] : Method [POST]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1] : Request [{
"account" : "",
"autoGenSuites" : "758020139",
"branch" : "efH22qGh",
"bugsOpen" : "758020139",
"createdBy" : "",
"createdDate" : "",
"description" : "efH22qGh",
"genPolicy" : "Create",
"id" : "",
"inactive" : false,
"isFileLoad" : "efH22qGh",
"issueTracker" : "",
"lastCommit" : "efH22qGh",
"lastSync" : null,
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "efH22qGh",
"openAPISpec" : "efH22qGh",
"openText" : "efH22qGh",
"org" : "",
"props" : null,
"url" : "efH22qGh",
"version" : ""
}]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:30.088+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 2, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.Project[\"account\"])",
"path" : "/api/v1/projects"
}]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=Y2EyODk4YzgtZTJjYi00MDUxLWFhZjEtZWY5MmZlYjAzMGI0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:29 GMT]}]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1] : StatusCode [400]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1] : Time [434]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1] : Size [744]
2019-03-20 10:44:30 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=Y2EyODk4YzgtZTJjYi00MDUxLWFhZjEtZWY5MmZlYjAzMGI0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:29 GMT]}]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=Y2EyODk4YzgtZTJjYi00MDUxLWFhZjEtZWY5MmZlYjAzMGI0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:29 GMT]}]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=Y2EyODk4YzgtZTJjYi00MDUxLWFhZjEtZWY5MmZlYjAzMGI0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:29 GMT]}]
2019-03-20 10:44:30 DEBUG [ProjectCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=Y2EyODk4YzgtZTJjYi00MDUxLWFhZjEtZWY5MmZlYjAzMGI0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:29 GMT]}]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : URL [http://13.56.210.25/api/v1/autocode-generator]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Method [POST]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Request [{
"abacResources" : [ {
"createBody" : "D30Vjc9l",
"createEndpoint" : "D30Vjc9l",
"createUserAuth" : "D30Vjc9l",
"createdBy" : "",
"createdDate" : "",
"deleteEndpoint" : "D30Vjc9l",
"enumValues" : "D30Vjc9l",
"generatorId" : "D30Vjc9l",
"id" : "",
"inactive" : false,
"initScriptName" : "D30Vjc9l",
"lock" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"resourceName" : "D30Vjc9l",
"scripts" : [ {
"body" : "D30Vjc9l",
"deleteEndPoint" : "D30Vjc9l",
"endpoint" : "D30Vjc9l",
"resourceName" : "D30Vjc9l",
"scriptName" : "D30Vjc9l",
"scriptType" : "D30Vjc9l",
"sequence" : "2035536466",
"userAuth" : "D30Vjc9l",
"validationScript" : false
} ],
"typeThreeCreateEndpoint" : "D30Vjc9l",
"validations" : [ {
"body" : "D30Vjc9l",
"endpoint" : "D30Vjc9l",
"inactive" : false,
"lock" : false,
"path" : "D30Vjc9l",
"userAuth" : "D30Vjc9l",
"validationType" : "D30Vjc9l"
} ],
"version" : ""
} ],
"assertionDescription" : "D30Vjc9l",
"assertions" : [ "D30Vjc9l" ],
"assertionsText" : "D30Vjc9l",
"authors" : "D30Vjc9l",
"category" : "SQL_Injection",
"coverageMultiplier" : "2035536466",
"currentScripts" : "2035536466",
"database" : {
"name" : "D30Vjc9l",
"version" : ""
},
"displayHeaderDescription" : "D30Vjc9l",
"displayHeaderLabel" : "D30Vjc9l",
"expectedScripts" : "2035536466",
"fixHours" : "D30Vjc9l",
"id" : "",
"inactive" : false,
"matches" : [ {
"allowRoles" : "D30Vjc9l",
"bodyProperties" : "D30Vjc9l",
"denyRoles" : "D30Vjc9l",
"id" : "",
"methods" : "D30Vjc9l",
"name" : "D30Vjc9l",
"pathPatterns" : "D30Vjc9l",
"queryParams" : "D30Vjc9l",
"resourceSamples" : "D30Vjc9l",
"value" : "D30Vjc9l"
} ],
"newlyAdded" : false,
"project" : "",
"sequenceOrder" : "2035536466",
"severity" : "Major",
"tags" : [ "D30Vjc9l" ],
"type" : "D30Vjc9l"
}]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:30.983+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 71, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.AutoCodeGenerator[\"project\"])",
"path" : "/api/v1/autocode-generator"
}]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZTAwMjk4NDctNWMzMy00MDBmLTk5OTctOTZkNTZkYTE0Yjlh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:30 GMT]}]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : StatusCode [400]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Time [898]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Size [751]
2019-03-20 10:44:31 ERROR [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Assertion [@StatusCode == 401 OR @StatusCode == 403] resolved-to [400 == 401 OR 400 == 403] result [Failed]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : URL [http://13.56.210.25/api/v1/autocode-generator/]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Method [DELETE]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Request [null]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Response [{
"timestamp" : "2019-03-20T10:44:31.628+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/autocode-generator/"
}]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Response-Headers [{Allow=[GET, PUT, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=OTg1MmVmNTgtM2MzNC00Y2NjLTg3ODItOGQ3ZWYwZWE2NjQx; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:30 GMT]}]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : StatusCode [405]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Time [640]
2019-03-20 10:44:31 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Size [173]
2019-03-20 10:44:31 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
2019-03-20 10:44:32 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : URL [http://13.56.210.25/api/v1/projects/]
2019-03-20 10:44:32 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Method [DELETE]
2019-03-20 10:44:32 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Request [null]
2019-03-20 10:44:32 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:32 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Response [{
"timestamp" : "2019-03-20T10:44:32.415+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/projects/"
}]
2019-03-20 10:44:32 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Response-Headers [{Allow=[GET, POST, PUT], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=N2U5YTUwYjUtZmEyYi00MDNhLWI2M2UtNDIwNDBiYTdhYWM4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:31 GMT]}]
2019-03-20 10:44:32 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : StatusCode [405]
2019-03-20 10:44:32 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Time [786]
2019-03-20 10:44:32 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Size [163]
2019-03-20 10:44:32 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
2019-03-20 10:44:33 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : URL [http://13.56.210.25/api/v1/issue-trackers/issue-tracker-bot/]
2019-03-20 10:44:33 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Method [DELETE]
2019-03-20 10:44:33 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Request [null]
2019-03-20 10:44:33 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:33 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Response [{
"timestamp" : "2019-03-20T10:44:33.082+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/issue-trackers/issue-tracker-bot/"
}]
2019-03-20 10:44:33 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Response-Headers [{Allow=[POST, GET, PUT], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=M2FjNTYzNjAtMTIyZS00MDVhLWI0ODQtY2Y2MmVhMjY0ZTJk; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:33 GMT]}]
2019-03-20 10:44:33 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : StatusCode [405]
2019-03-20 10:44:33 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Time [665]
2019-03-20 10:44:33 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Size [187]
2019-03-20 10:44:33 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
2019-03-20 10:44:33 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : URL [http://13.56.210.25/api/v1/skills/]
2019-03-20 10:44:33 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Method [DELETE]
2019-03-20 10:44:33 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Request [null]
2019-03-20 10:44:33 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:33 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Response [{
"timestamp" : "2019-03-20T10:44:33.660+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/skills/"
}]
2019-03-20 10:44:33 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Response-Headers [{Allow=[GET, POST, PUT], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZDAwZmJlOWItMWY0Mi00ZWE5LTk0MjItMmIyNzIyNGY0NDYy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:33 GMT]}]
2019-03-20 10:44:33 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : StatusCode [405]
2019-03-20 10:44:33 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Time [577]
2019-03-20 10:44:33 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Size [161]
2019-03-20 10:44:33 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
2019-03-20 10:44:34 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : URL [http://13.56.210.25/api/v1/accounts/]
2019-03-20 10:44:34 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Method [DELETE]
2019-03-20 10:44:34 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Request [null]
2019-03-20 10:44:34 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:34 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Response [{
"timestamp" : "2019-03-20T10:44:34.381+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/accounts/"
}]
2019-03-20 10:44:34 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Response-Headers [{Allow=[GET, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZjQ3YjM4OTctNzYyOC00NDdhLTg4ZDMtYjViYTg4MDEwMzlm; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:34 GMT]}]
2019-03-20 10:44:34 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : StatusCode [405]
2019-03-20 10:44:34 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Time [719]
2019-03-20 10:44:34 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Size [163]
2019-03-20 10:44:34 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
2019-03-20 10:44:35 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : URL [http://13.56.210.25/api/v1/orgs/]
2019-03-20 10:44:35 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Method [DELETE]
2019-03-20 10:44:35 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request [null]
2019-03-20 10:44:35 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:35 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response [{
"timestamp" : "2019-03-20T10:44:35.049+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/orgs/"
}]
2019-03-20 10:44:35 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response-Headers [{Allow=[GET, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=M2FiNDgzYmYtNDc1Ni00MTQ2LTgxZTUtYzc5YTYwZDI4ZTNl; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:35 GMT]}]
2019-03-20 10:44:35 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : StatusCode [405]
2019-03-20 10:44:35 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Time [668]
2019-03-20 10:44:35 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Size [159]
2019-03-20 10:44:35 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
--- FX Bot ---
Project : FXABAC TEST
Template : ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1
Run Id : 8a808011699a990101699ab3901a2277
Job : Default
Env : Default
Category : Hijack_Level1
Tags : [FX Top 10 - API Vulnerability, Data_Access_Control]
Severity : Major
Region : FXLabs/US_WEST_1
Result : fail
Status Code : 400
Headers : {X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZGU2MzgzODMtYWYxYy00YjI1LThkYzgtYjYwOWIzNjBmZTZh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:00 GMT]}
Endpoint : http://13.56.210.25/api/v1/autocode-generator
Request :
{
"abacResources" : [ {
"createBody" : "YjNNV8in",
"createEndpoint" : "YjNNV8in",
"createUserAuth" : "YjNNV8in",
"createdBy" : "",
"createdDate" : "",
"deleteEndpoint" : "YjNNV8in",
"enumValues" : "YjNNV8in",
"generatorId" : "YjNNV8in",
"id" : "",
"inactive" : false,
"initScriptName" : "YjNNV8in",
"lock" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"resourceName" : "YjNNV8in",
"scripts" : [ {
"body" : "YjNNV8in",
"deleteEndPoint" : "YjNNV8in",
"endpoint" : "YjNNV8in",
"resourceName" : "YjNNV8in",
"scriptName" : "YjNNV8in",
"scriptType" : "YjNNV8in",
"sequence" : "685875669",
"userAuth" : "YjNNV8in",
"validationScript" : false
} ],
"typeThreeCreateEndpoint" : "YjNNV8in",
"validations" : [ {
"body" : "YjNNV8in",
"endpoint" : "YjNNV8in",
"inactive" : false,
"lock" : false,
"path" : "YjNNV8in",
"userAuth" : "YjNNV8in",
"validationType" : "YjNNV8in"
} ],
"version" : ""
} ],
"assertionDescription" : "YjNNV8in",
"assertions" : [ "YjNNV8in" ],
"assertionsText" : "YjNNV8in",
"authors" : "YjNNV8in",
"category" : "SQL_Injection",
"coverageMultiplier" : "685875669",
"currentScripts" : "685875669",
"database" : {
"name" : "YjNNV8in",
"version" : ""
},
"displayHeaderDescription" : "YjNNV8in",
"displayHeaderLabel" : "YjNNV8in",
"expectedScripts" : "685875669",
"fixHours" : "YjNNV8in",
"id" : "",
"inactive" : false,
"matches" : [ {
"allowRoles" : "YjNNV8in",
"bodyProperties" : "YjNNV8in",
"denyRoles" : "YjNNV8in",
"id" : "",
"methods" : "YjNNV8in",
"name" : "YjNNV8in",
"pathPatterns" : "YjNNV8in",
"queryParams" : "YjNNV8in",
"resourceSamples" : "YjNNV8in",
"value" : "YjNNV8in"
} ],
"newlyAdded" : false,
"project" : "",
"sequenceOrder" : "685875669",
"severity" : "Major",
"tags" : [ "YjNNV8in" ],
"type" : "YjNNV8in"
}
Response :
{
"timestamp" : "2019-03-20T10:45:00.972+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 71, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.AutoCodeGenerator[\"project\"])",
"path" : "/api/v1/autocode-generator"
}
Logs :
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/orgs]
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1] : Request [{
"billingEmail" : "X5QbCKwV",
"company" : "Bechtelar, Bechtelar and Bechtelar",
"createdBy" : "",
"createdDate" : "",
"description" : "X5QbCKwV",
"id" : "",
"inactive" : false,
"location" : "X5QbCKwV",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "X5QbCKwV",
"orgPlan" : "TEAM",
"orgType" : "ENTERPRISE",
"version" : ""
}]
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:52.665+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/orgs"
}]
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTYwYzJkYWItYjA2My00MzgyLTk5NjItMmNiNTcxNmM0OWRi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:52 GMT]}]
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1] : StatusCode [403]
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1] : Time [696]
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1] : Size [121]
2019-03-20 10:44:52 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTYwYzJkYWItYjA2My00MzgyLTk5NjItMmNiNTcxNmM0OWRi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:52 GMT]}]
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTYwYzJkYWItYjA2My00MzgyLTk5NjItMmNiNTcxNmM0OWRi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:52 GMT]}]
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTYwYzJkYWItYjA2My00MzgyLTk5NjItMmNiNTcxNmM0OWRi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:52 GMT]}]
2019-03-20 10:44:52 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTYwYzJkYWItYjA2My00MzgyLTk5NjItMmNiNTcxNmM0OWRi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:52 GMT]}]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/accounts]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1] : Request [{
"accessKey" : "K57xRazt",
"accountType" : "GitLab",
"createdBy" : "",
"createdDate" : "",
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "K57xRazt",
"org" : "",
"prop1" : "K57xRazt",
"prop2" : "K57xRazt",
"prop3" : "K57xRazt",
"region" : "K57xRazt",
"secretKey" : "K57xRazt",
"version" : ""
}]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:53.753+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 11, column: 11] (through reference chain: com.fxlabs.fxt.dto.clusters.Account[\"org\"])",
"path" : "/api/v1/accounts"
}]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=M2UyZGU1N2UtMDczNC00OGM2LTgwNWYtODI3YmUwNzFjNDU0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:53 GMT]}]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1] : Time [1087]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1] : Size [722]
2019-03-20 10:44:53 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=M2UyZGU1N2UtMDczNC00OGM2LTgwNWYtODI3YmUwNzFjNDU0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:53 GMT]}]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=M2UyZGU1N2UtMDczNC00OGM2LTgwNWYtODI3YmUwNzFjNDU0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:53 GMT]}]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=M2UyZGU1N2UtMDczNC00OGM2LTgwNWYtODI3YmUwNzFjNDU0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:53 GMT]}]
2019-03-20 10:44:53 DEBUG [AccountCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=M2UyZGU1N2UtMDczNC00OGM2LTgwNWYtODI3YmUwNzFjNDU0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:53 GMT]}]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/skills]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1] : Request [{
"accessKey" : "5hC8fbG1",
"createdBy" : "",
"createdDate" : "",
"description" : "5hC8fbG1",
"host" : "5hC8fbG1",
"id" : "",
"inactive" : false,
"key" : "5hC8fbG1",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "5hC8fbG1",
"org" : "",
"prop1" : "5hC8fbG1",
"prop2" : "5hC8fbG1",
"prop3" : "5hC8fbG1",
"prop4" : "5hC8fbG1",
"prop5" : "5hC8fbG1",
"secretKey" : "5hC8fbG1",
"skillType" : "BOT_DEPLOYMENT",
"version" : ""
}]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:54.950+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 13, column: 11] (through reference chain: com.fxlabs.fxt.dto.skills.Skill[\"org\"])",
"path" : "/api/v1/skills"
}]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZGJlMTA5ZjktYWIwNi00YWYxLWEyYTgtMTk1NzRhZDAxMjU4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:54 GMT]}]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1] : Time [1193]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1] : Size [716]
2019-03-20 10:44:54 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZGJlMTA5ZjktYWIwNi00YWYxLWEyYTgtMTk1NzRhZDAxMjU4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:54 GMT]}]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZGJlMTA5ZjktYWIwNi00YWYxLWEyYTgtMTk1NzRhZDAxMjU4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:54 GMT]}]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZGJlMTA5ZjktYWIwNi00YWYxLWEyYTgtMTk1NzRhZDAxMjU4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:54 GMT]}]
2019-03-20 10:44:54 DEBUG [SkillCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZGJlMTA5ZjktYWIwNi00YWYxLWEyYTgtMTk1NzRhZDAxMjU4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:54 GMT]}]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/issue-trackers/issue-tracker-bot]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1] : Request [{
"account" : "",
"createdBy" : "",
"createdDate" : "",
"description" : "aBwtC5jd",
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "aBwtC5jd",
"org" : "",
"prop1" : "aBwtC5jd",
"prop2" : "aBwtC5jd",
"prop3" : "aBwtC5jd",
"prop4" : "aBwtC5jd",
"prop5" : "aBwtC5jd",
"skill" : "",
"state" : "INACTIVE",
"version" : "",
"visibility" : "ORG_PUBLIC"
}]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:56.351+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 2, column: 15] (through reference chain: com.fxlabs.fxt.dto.it.IssueTracker[\"account\"])",
"path" : "/api/v1/issue-trackers/issue-tracker-bot"
}]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZDgxZDdiOGYtNjFkNi00YWIyLTk0MWMtNmZkNWJjNjZjNTQx; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:55 GMT]}]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1] : Time [1399]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1] : Size [768]
2019-03-20 10:44:56 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZDgxZDdiOGYtNjFkNi00YWIyLTk0MWMtNmZkNWJjNjZjNTQx; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:55 GMT]}]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZDgxZDdiOGYtNjFkNi00YWIyLTk0MWMtNmZkNWJjNjZjNTQx; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:55 GMT]}]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZDgxZDdiOGYtNjFkNi00YWIyLTk0MWMtNmZkNWJjNjZjNTQx; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:55 GMT]}]
2019-03-20 10:44:56 DEBUG [IssueTrackerCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZDgxZDdiOGYtNjFkNi00YWIyLTk0MWMtNmZkNWJjNjZjNTQx; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:55 GMT]}]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/projects]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1] : Request [{
"account" : "",
"autoGenSuites" : "1722188988",
"branch" : "XyUA5sJf",
"bugsOpen" : "1722188988",
"createdBy" : "",
"createdDate" : "",
"description" : "XyUA5sJf",
"genPolicy" : "Create",
"id" : "",
"inactive" : false,
"isFileLoad" : "XyUA5sJf",
"issueTracker" : "",
"lastCommit" : "XyUA5sJf",
"lastSync" : null,
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "XyUA5sJf",
"openAPISpec" : "XyUA5sJf",
"openText" : "XyUA5sJf",
"org" : "",
"props" : null,
"url" : "XyUA5sJf",
"version" : ""
}]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:57.267+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 2, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.Project[\"account\"])",
"path" : "/api/v1/projects"
}]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjRiMjJkNTktYWUzNi00YTdmLWI4YjUtMTMwYmU2OWFhNTEx; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:56 GMT]}]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1] : Time [913]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1] : Size [744]
2019-03-20 10:44:57 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjRiMjJkNTktYWUzNi00YTdmLWI4YjUtMTMwYmU2OWFhNTEx; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:56 GMT]}]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjRiMjJkNTktYWUzNi00YTdmLWI4YjUtMTMwYmU2OWFhNTEx; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:56 GMT]}]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjRiMjJkNTktYWUzNi00YTdmLWI4YjUtMTMwYmU2OWFhNTEx; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:56 GMT]}]
2019-03-20 10:44:57 DEBUG [ProjectCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjRiMjJkNTktYWUzNi00YTdmLWI4YjUtMTMwYmU2OWFhNTEx; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:56 GMT]}]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/autocode-generator]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Request [{
"assertionDescription" : "5wFzQJVr",
"assertionsText" : "5wFzQJVr",
"authors" : "5wFzQJVr",
"category" : "ABAC_Level1_Positive",
"coverageMultiplier" : "1019747797",
"currentScripts" : "1019747797",
"database" : {
"name" : "5wFzQJVr",
"version" : ""
},
"displayHeaderDescription" : "5wFzQJVr",
"displayHeaderLabel" : "5wFzQJVr",
"expectedScripts" : "1019747797",
"fixHours" : "5wFzQJVr",
"id" : "",
"inactive" : false,
"newlyAdded" : false,
"project" : "",
"sequenceOrder" : "1019747797",
"severity" : "Major",
"type" : "5wFzQJVr"
}]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:58.636+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 19, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.AutoCodeGenerator[\"project\"])",
"path" : "/api/v1/autocode-generator"
}]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MDY4NjgzYWUtOGJkYS00OWI1LWE2YTEtZDgzN2ViMmNmNGEy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:57 GMT]}]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Time [1368]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Size [751]
2019-03-20 10:44:58 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MDY4NjgzYWUtOGJkYS00OWI1LWE2YTEtZDgzN2ViMmNmNGEy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:57 GMT]}]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MDY4NjgzYWUtOGJkYS00OWI1LWE2YTEtZDgzN2ViMmNmNGEy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:57 GMT]}]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MDY4NjgzYWUtOGJkYS00OWI1LWE2YTEtZDgzN2ViMmNmNGEy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:57 GMT]}]
2019-03-20 10:44:58 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MDY4NjgzYWUtOGJkYS00OWI1LWE2YTEtZDgzN2ViMmNmNGEy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:57 GMT]}]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1] : URL [http://13.56.210.25/api/v1/projects]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1] : Method [POST]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1] : Request [{
"account" : "",
"autoGenSuites" : "412086470",
"branch" : "JoMESUTz",
"bugsOpen" : "412086470",
"createdBy" : "",
"createdDate" : "",
"description" : "JoMESUTz",
"genPolicy" : "Create",
"id" : "",
"inactive" : false,
"isFileLoad" : "JoMESUTz",
"issueTracker" : "",
"lastCommit" : "JoMESUTz",
"lastSync" : null,
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "JoMESUTz",
"openAPISpec" : "JoMESUTz",
"openText" : "JoMESUTz",
"org" : "",
"props" : null,
"url" : "JoMESUTz",
"version" : ""
}]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:59.716+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 2, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.Project[\"account\"])",
"path" : "/api/v1/projects"
}]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YzFmOWNlYTYtYmUzZS00ZjI0LWEyOTAtYjY4NWEwZTQyZWU4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:58 GMT]}]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1] : StatusCode [400]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1] : Time [1079]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1] : Size [744]
2019-03-20 10:44:59 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YzFmOWNlYTYtYmUzZS00ZjI0LWEyOTAtYjY4NWEwZTQyZWU4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:58 GMT]}]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YzFmOWNlYTYtYmUzZS00ZjI0LWEyOTAtYjY4NWEwZTQyZWU4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:58 GMT]}]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YzFmOWNlYTYtYmUzZS00ZjI0LWEyOTAtYjY4NWEwZTQyZWU4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:58 GMT]}]
2019-03-20 10:44:59 DEBUG [ProjectCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YzFmOWNlYTYtYmUzZS00ZjI0LWEyOTAtYjY4NWEwZTQyZWU4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:58 GMT]}]
2019-03-20 10:45:01 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : URL [http://13.56.210.25/api/v1/autocode-generator]
2019-03-20 10:45:01 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Method [POST]
2019-03-20 10:45:01 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Request [{
"abacResources" : [ {
"createBody" : "YjNNV8in",
"createEndpoint" : "YjNNV8in",
"createUserAuth" : "YjNNV8in",
"createdBy" : "",
"createdDate" : "",
"deleteEndpoint" : "YjNNV8in",
"enumValues" : "YjNNV8in",
"generatorId" : "YjNNV8in",
"id" : "",
"inactive" : false,
"initScriptName" : "YjNNV8in",
"lock" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"resourceName" : "YjNNV8in",
"scripts" : [ {
"body" : "YjNNV8in",
"deleteEndPoint" : "YjNNV8in",
"endpoint" : "YjNNV8in",
"resourceName" : "YjNNV8in",
"scriptName" : "YjNNV8in",
"scriptType" : "YjNNV8in",
"sequence" : "685875669",
"userAuth" : "YjNNV8in",
"validationScript" : false
} ],
"typeThreeCreateEndpoint" : "YjNNV8in",
"validations" : [ {
"body" : "YjNNV8in",
"endpoint" : "YjNNV8in",
"inactive" : false,
"lock" : false,
"path" : "YjNNV8in",
"userAuth" : "YjNNV8in",
"validationType" : "YjNNV8in"
} ],
"version" : ""
} ],
"assertionDescription" : "YjNNV8in",
"assertions" : [ "YjNNV8in" ],
"assertionsText" : "YjNNV8in",
"authors" : "YjNNV8in",
"category" : "SQL_Injection",
"coverageMultiplier" : "685875669",
"currentScripts" : "685875669",
"database" : {
"name" : "YjNNV8in",
"version" : ""
},
"displayHeaderDescription" : "YjNNV8in",
"displayHeaderLabel" : "YjNNV8in",
"expectedScripts" : "685875669",
"fixHours" : "YjNNV8in",
"id" : "",
"inactive" : false,
"matches" : [ {
"allowRoles" : "YjNNV8in",
"bodyProperties" : "YjNNV8in",
"denyRoles" : "YjNNV8in",
"id" : "",
"methods" : "YjNNV8in",
"name" : "YjNNV8in",
"pathPatterns" : "YjNNV8in",
"queryParams" : "YjNNV8in",
"resourceSamples" : "YjNNV8in",
"value" : "YjNNV8in"
} ],
"newlyAdded" : false,
"project" : "",
"sequenceOrder" : "685875669",
"severity" : "Major",
"tags" : [ "YjNNV8in" ],
"type" : "YjNNV8in"
}]
2019-03-20 10:45:01 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:01 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Response [{
"timestamp" : "2019-03-20T10:45:00.972+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 71, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.AutoCodeGenerator[\"project\"])",
"path" : "/api/v1/autocode-generator"
}]
2019-03-20 10:45:01 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZGU2MzgzODMtYWYxYy00YjI1LThkYzgtYjYwOWIzNjBmZTZh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:00 GMT]}]
2019-03-20 10:45:01 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : StatusCode [400]
2019-03-20 10:45:01 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Time [1252]
2019-03-20 10:45:01 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Size [751]
2019-03-20 10:45:01 ERROR [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Assertion [@StatusCode == 401 OR @StatusCode == 403] resolved-to [400 == 401 OR 400 == 403] result [Failed]
2019-03-20 10:45:02 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : URL [http://13.56.210.25/api/v1/autocode-generator/]
2019-03-20 10:45:02 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Method [DELETE]
2019-03-20 10:45:02 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Request [null]
2019-03-20 10:45:02 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:02 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Response [{
"timestamp" : "2019-03-20T10:45:02.438+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/autocode-generator/"
}]
2019-03-20 10:45:02 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Response-Headers [{Allow=[GET, PUT, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ODkyNjY0YjUtY2I3Yi00YTBjLWE4YjctZjBjYjg0OTFkY2U1; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:01 GMT]}]
2019-03-20 10:45:02 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : StatusCode [405]
2019-03-20 10:45:02 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Time [1467]
2019-03-20 10:45:02 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Size [173]
2019-03-20 10:45:02 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
2019-03-20 10:45:04 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : URL [http://13.56.210.25/api/v1/projects/]
2019-03-20 10:45:04 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Method [DELETE]
2019-03-20 10:45:04 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Request [null]
2019-03-20 10:45:04 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:04 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Response [{
"timestamp" : "2019-03-20T10:45:04.004+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/projects/"
}]
2019-03-20 10:45:04 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Response-Headers [{Allow=[GET, POST, PUT], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YTcyNWQyNWUtODg0OC00ODczLWE2OWItMDE1MjI5NTY1ODgw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:04 GMT]}]
2019-03-20 10:45:04 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : StatusCode [405]
2019-03-20 10:45:04 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Time [1562]
2019-03-20 10:45:04 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Size [163]
2019-03-20 10:45:04 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
2019-03-20 10:45:05 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : URL [http://13.56.210.25/api/v1/issue-trackers/issue-tracker-bot/]
2019-03-20 10:45:05 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Method [DELETE]
2019-03-20 10:45:05 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Request [null]
2019-03-20 10:45:05 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:05 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Response [{
"timestamp" : "2019-03-20T10:45:05.342+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/issue-trackers/issue-tracker-bot/"
}]
2019-03-20 10:45:05 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Response-Headers [{Allow=[POST, GET, PUT], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MDRkN2VlYTMtODg1Mi00MTJlLWI2ODAtODc4ZTVmNmM5ZmVl; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:05 GMT]}]
2019-03-20 10:45:05 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : StatusCode [405]
2019-03-20 10:45:05 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Time [1338]
2019-03-20 10:45:05 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Size [187]
2019-03-20 10:45:05 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
2019-03-20 10:45:06 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : URL [http://13.56.210.25/api/v1/skills/]
2019-03-20 10:45:06 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Method [DELETE]
2019-03-20 10:45:06 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Request [null]
2019-03-20 10:45:06 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:06 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Response [{
"timestamp" : "2019-03-20T10:45:06.580+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/skills/"
}]
2019-03-20 10:45:06 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Response-Headers [{Allow=[GET, POST, PUT], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=N2E4MzI2ZDgtN2QyOS00MWZiLTg3YmUtZTdkYThhZWViOTM3; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:06 GMT]}]
2019-03-20 10:45:06 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : StatusCode [405]
2019-03-20 10:45:06 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Time [1241]
2019-03-20 10:45:06 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Size [161]
2019-03-20 10:45:06 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
2019-03-20 10:45:08 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : URL [http://13.56.210.25/api/v1/accounts/]
2019-03-20 10:45:08 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Method [DELETE]
2019-03-20 10:45:08 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Request [null]
2019-03-20 10:45:08 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:08 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Response [{
"timestamp" : "2019-03-20T10:45:08.429+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/accounts/"
}]
2019-03-20 10:45:08 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Response-Headers [{Allow=[GET, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTY2ZTIyZjEtM2U4Yi00ZDdiLWI2M2ItNGRkMWQ2ZjE4MDYw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:08 GMT]}]
2019-03-20 10:45:08 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : StatusCode [405]
2019-03-20 10:45:08 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Time [1843]
2019-03-20 10:45:08 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Size [163]
2019-03-20 10:45:08 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
2019-03-20 10:45:09 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : URL [http://13.56.210.25/api/v1/orgs/]
2019-03-20 10:45:09 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Method [DELETE]
2019-03-20 10:45:09 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request [null]
2019-03-20 10:45:09 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:09 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response [{
"timestamp" : "2019-03-20T10:45:09.839+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/orgs/"
}]
2019-03-20 10:45:09 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response-Headers [{Allow=[GET, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YmFlNjI2NTUtMjFkNi00MmUxLWJlOWMtZWIyZWQyNGUwZGQw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:09 GMT]}]
2019-03-20 10:45:09 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : StatusCode [405]
2019-03-20 10:45:09 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Time [1412]
2019-03-20 10:45:09 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Size [159]
2019-03-20 10:45:09 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
--- FX Bot ---
Project : FXABAC TEST
Template : ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1
Run Id : 8a808011699a990101699ab0f9761b20
Job : Default
Env : Default
Category : Hijack_Level1
Tags : [FX Top 10 - API Vulnerability, Data_Access_Control]
Severity : Major
Region : FXLabs/US_WEST_1
Result : fail
Status Code : 400
Headers : {X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MGQxNjIxY2MtMGM0OS00ZjRjLThjZDYtOGMwZjg1ZWJiN2U4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:39 GMT]}
Endpoint : http://13.56.210.25/api/v1/autocode-generator
Request :
{ "abacResources" : [ { "createBody" : "keSyUCAf", "createEndpoint" : "keSyUCAf", "createUserAuth" : "keSyUCAf", "createdBy" : "", "createdDate" : "", "deleteEndpoint" : "keSyUCAf", "enumValues" : "keSyUCAf", "generatorId" : "keSyUCAf", "id" : "", "inactive" : false, "initScriptName" : "keSyUCAf", "lock" : false, "modifiedBy" : "", "modifiedDate" : "", "resourceName" : "keSyUCAf", "scripts" : [ { "body" : "keSyUCAf", "deleteEndPoint" : "keSyUCAf", "endpoint" : "keSyUCAf", "resourceName" : "keSyUCAf", "scriptName" : "keSyUCAf", "scriptType" : "keSyUCAf", "sequence" : "2096000836", "userAuth" : "keSyUCAf", "validationScript" : false } ], "typeThreeCreateEndpoint" : "keSyUCAf", "validations" : [ { "body" : "keSyUCAf", "endpoint" : "keSyUCAf", "inactive" : false, "lock" : false, "path" : "keSyUCAf", "userAuth" : "keSyUCAf", "validationType" : "keSyUCAf" } ], "version" : "" } ], "assertionDescription" : "keSyUCAf", "assertions" : [ "keSyUCAf" ], "assertionsText" : "keSyUCAf", "authors" : "keSyUCAf", "category" : "SQL_Injection", "coverageMultiplier" : "2096000836", "currentScripts" : "2096000836", "database" : { "name" : "keSyUCAf", "version" : "" }, "displayHeaderDescription" : "keSyUCAf", "displayHeaderLabel" : "keSyUCAf", "expectedScripts" : "2096000836", "fixHours" : "keSyUCAf", "id" : "", "inactive" : false, "matches" : [ { "allowRoles" : "keSyUCAf", "bodyProperties" : "keSyUCAf", "denyRoles" : "keSyUCAf", "id" : "", "methods" : "keSyUCAf", "name" : "keSyUCAf", "pathPatterns" : "keSyUCAf", "queryParams" : "keSyUCAf", "resourceSamples" : "keSyUCAf", "value" : "keSyUCAf" } ], "newlyAdded" : false, "project" : "", "sequenceOrder" : "2096000836", "severity" : "Major", "tags" : [ "keSyUCAf" ], "type" : "keSyUCAf" }
Response :
{ "timestamp" : "2019-03-20T10:41:40.104+0000", "status" : 400, "error" : "Bad Request", "message" : "JSON parse error: Cannot construct instance of
com.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance ofcom.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 71, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.AutoCodeGenerator[\"project\"])", "path" : "/api/v1/autocode-generator" }Logs :
2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/orgs] 2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1] : Method [POST] 2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1] : Request [{ "billingEmail" : "wSmcpAxs", "company" : "Rice-Rice", "createdBy" : "", "createdDate" : "", "description" : "wSmcpAxs", "id" : "", "inactive" : false, "location" : "wSmcpAxs", "modifiedBy" : "", "modifiedDate" : "", "name" : "wSmcpAxs", "orgPlan" : "TEAM", "orgType" : "ENTERPRISE", "version" : "" }] 2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:36.268+0000", "status" : 403, "error" : "Forbidden", "message" : "Forbidden", "path" : "/api/v1/orgs" }] 2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzIyYWQ2MWMtZWMxNi00NGMwLWIzNWYtMmVjNTc5ZDdjYmY0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:36 GMT]}] 2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1] : StatusCode [403] 2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1] : Time [602] 2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1] : Size [121] 2019-03-20 10:41:36 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed] 2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzIyYWQ2MWMtZWMxNi00NGMwLWIzNWYtMmVjNTc5ZDdjYmY0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:36 GMT]}] 2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzIyYWQ2MWMtZWMxNi00NGMwLWIzNWYtMmVjNTc5ZDdjYmY0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:36 GMT]}] 2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzIyYWQ2MWMtZWMxNi00NGMwLWIzNWYtMmVjNTc5ZDdjYmY0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:36 GMT]}] 2019-03-20 10:41:36 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzIyYWQ2MWMtZWMxNi00NGMwLWIzNWYtMmVjNTc5ZDdjYmY0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:36 GMT]}] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/accounts] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1] : Method [POST] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1] : Request [{ "accessKey" : "PVFfdwKO", "accountType" : "GitLab", "createdBy" : "", "createdDate" : "", "id" : "", "inactive" : false, "modifiedBy" : "", "modifiedDate" : "", "name" : "PVFfdwKO", "org" : "", "prop1" : "PVFfdwKO", "prop2" : "PVFfdwKO", "prop3" : "PVFfdwKO", "region" : "PVFfdwKO", "secretKey" : "PVFfdwKO", "version" : "" }] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:36.714+0000", "status" : 400, "error" : "Bad Request", "message" : "JSON parse error: Cannot construct instance of
com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance ofcom.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 11, column: 11] (through reference chain: com.fxlabs.fxt.dto.clusters.Account[\"org\"])", "path" : "/api/v1/accounts" }] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NDdkM2Q3ODMtYzJhNy00MmJiLWFjZmEtYzRiYzk5YzczZjQ2; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:36 GMT]}] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1] : StatusCode [400] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1] : Time [443] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1] : Size [722] 2019-03-20 10:41:36 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NDdkM2Q3ODMtYzJhNy00MmJiLWFjZmEtYzRiYzk5YzczZjQ2; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:36 GMT]}] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NDdkM2Q3ODMtYzJhNy00MmJiLWFjZmEtYzRiYzk5YzczZjQ2; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:36 GMT]}] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NDdkM2Q3ODMtYzJhNy00MmJiLWFjZmEtYzRiYzk5YzczZjQ2; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:36 GMT]}] 2019-03-20 10:41:36 DEBUG [AccountCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NDdkM2Q3ODMtYzJhNy00MmJiLWFjZmEtYzRiYzk5YzczZjQ2; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:36 GMT]}] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/skills] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1] : Method [POST] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1] : Request [{ "accessKey" : "3H9Ur1Ya", "createdBy" : "", "createdDate" : "", "description" : "3H9Ur1Ya", "host" : "3H9Ur1Ya", "id" : "", "inactive" : false, "key" : "3H9Ur1Ya", "modifiedBy" : "", "modifiedDate" : "", "name" : "3H9Ur1Ya", "org" : "", "prop1" : "3H9Ur1Ya", "prop2" : "3H9Ur1Ya", "prop3" : "3H9Ur1Ya", "prop4" : "3H9Ur1Ya", "prop5" : "3H9Ur1Ya", "secretKey" : "3H9Ur1Ya", "skillType" : "BOT_DEPLOYMENT", "version" : "" }] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:37.332+0000", "status" : 400, "error" : "Bad Request", "message" : "JSON parse error: Cannot construct instance ofcom.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance ofcom.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 13, column: 11] (through reference chain: com.fxlabs.fxt.dto.skills.Skill[\"org\"])", "path" : "/api/v1/skills" }] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTlhMDU1ODQtZjk3Zi00NTQ5LWI5MzItZWJhOGE5ZjRhN2Zl; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:37 GMT]}] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1] : StatusCode [400] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1] : Time [618] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1] : Size [716] 2019-03-20 10:41:37 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTlhMDU1ODQtZjk3Zi00NTQ5LWI5MzItZWJhOGE5ZjRhN2Zl; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:37 GMT]}] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTlhMDU1ODQtZjk3Zi00NTQ5LWI5MzItZWJhOGE5ZjRhN2Zl; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:37 GMT]}] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTlhMDU1ODQtZjk3Zi00NTQ5LWI5MzItZWJhOGE5ZjRhN2Zl; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:37 GMT]}] 2019-03-20 10:41:37 DEBUG [SkillCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTlhMDU1ODQtZjk3Zi00NTQ5LWI5MzItZWJhOGE5ZjRhN2Zl; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:37 GMT]}] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/issue-trackers/issue-tracker-bot] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1] : Method [POST] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1] : Request [{ "account" : "", "createdBy" : "", "createdDate" : "", "description" : "YvROW62c", "id" : "", "inactive" : false, "modifiedBy" : "", "modifiedDate" : "", "name" : "YvROW62c", "org" : "", "prop1" : "YvROW62c", "prop2" : "YvROW62c", "prop3" : "YvROW62c", "prop4" : "YvROW62c", "prop5" : "YvROW62c", "skill" : "", "state" : "INACTIVE", "version" : "", "visibility" : "ORG_PUBLIC" }] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:37.871+0000", "status" : 400, "error" : "Bad Request", "message" : "JSON parse error: Cannot construct instance ofcom.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance ofcom.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 2, column: 15] (through reference chain: com.fxlabs.fxt.dto.it.IssueTracker[\"account\"])", "path" : "/api/v1/issue-trackers/issue-tracker-bot" }] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=OTI3NmYxN2QtMTUxOS00NGU3LWJlYmQtOGZmM2Y2ZDE4Nzg1; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:37 GMT]}] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1] : StatusCode [400] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1] : Time [536] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1] : Size [768] 2019-03-20 10:41:37 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=OTI3NmYxN2QtMTUxOS00NGU3LWJlYmQtOGZmM2Y2ZDE4Nzg1; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:37 GMT]}] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=OTI3NmYxN2QtMTUxOS00NGU3LWJlYmQtOGZmM2Y2ZDE4Nzg1; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:37 GMT]}] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=OTI3NmYxN2QtMTUxOS00NGU3LWJlYmQtOGZmM2Y2ZDE4Nzg1; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:37 GMT]}] 2019-03-20 10:41:37 DEBUG [IssueTrackerCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=OTI3NmYxN2QtMTUxOS00NGU3LWJlYmQtOGZmM2Y2ZDE4Nzg1; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:37 GMT]}] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/projects] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1] : Method [POST] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1] : Request [{ "account" : "", "autoGenSuites" : "1133723349", "branch" : "jqyoAeau", "bugsOpen" : "1133723349", "createdBy" : "", "createdDate" : "", "description" : "jqyoAeau", "genPolicy" : "Create", "id" : "", "inactive" : false, "isFileLoad" : "jqyoAeau", "issueTracker" : "", "lastCommit" : "jqyoAeau", "lastSync" : null, "modifiedBy" : "", "modifiedDate" : "", "name" : "jqyoAeau", "openAPISpec" : "jqyoAeau", "openText" : "jqyoAeau", "org" : "", "props" : null, "url" : "jqyoAeau", "version" : "" }] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:38.520+0000", "status" : 400, "error" : "Bad Request", "message" : "JSON parse error: Cannot construct instance ofcom.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance ofcom.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 2, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.Project[\"account\"])", "path" : "/api/v1/projects" }] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NmQ0NDRkN2ItYzI1MC00ODM5LWE5ZWQtZDM3NTA0NmZiZmU5; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:38 GMT]}] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1] : StatusCode [400] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1] : Time [646] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1] : Size [744] 2019-03-20 10:41:38 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NmQ0NDRkN2ItYzI1MC00ODM5LWE5ZWQtZDM3NTA0NmZiZmU5; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:38 GMT]}] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NmQ0NDRkN2ItYzI1MC00ODM5LWE5ZWQtZDM3NTA0NmZiZmU5; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:38 GMT]}] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NmQ0NDRkN2ItYzI1MC00ODM5LWE5ZWQtZDM3NTA0NmZiZmU5; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:38 GMT]}] 2019-03-20 10:41:38 DEBUG [ProjectCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NmQ0NDRkN2ItYzI1MC00ODM5LWE5ZWQtZDM3NTA0NmZiZmU5; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:38 GMT]}] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/autocode-generator] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Method [POST] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Request [{ "assertionDescription" : "Y2Y6OYgH", "assertionsText" : "Y2Y6OYgH", "authors" : "Y2Y6OYgH", "category" : "ABAC_Level1_Positive", "coverageMultiplier" : "1058151187", "currentScripts" : "1058151187", "database" : { "name" : "Y2Y6OYgH", "version" : "" }, "displayHeaderDescription" : "Y2Y6OYgH", "displayHeaderLabel" : "Y2Y6OYgH", "expectedScripts" : "1058151187", "fixHours" : "Y2Y6OYgH", "id" : "", "inactive" : false, "newlyAdded" : false, "project" : "", "sequenceOrder" : "1058151187", "severity" : "Major", "type" : "Y2Y6OYgH" }] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:39.130+0000", "status" : 400, "error" : "Bad Request", "message" : "JSON parse error: Cannot construct instance ofcom.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance ofcom.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 19, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.AutoCodeGenerator[\"project\"])", "path" : "/api/v1/autocode-generator" }] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTk4ZDMzYTctNjk1Mi00NjI4LTlkY2QtZmMyYTI2ZjZlZTUy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:38 GMT]}] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : StatusCode [400] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Time [609] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1] : Size [751] 2019-03-20 10:41:39 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTk4ZDMzYTctNjk1Mi00NjI4LTlkY2QtZmMyYTI2ZjZlZTUy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:38 GMT]}] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTk4ZDMzYTctNjk1Mi00NjI4LTlkY2QtZmMyYTI2ZjZlZTUy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:38 GMT]}] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTk4ZDMzYTctNjk1Mi00NjI4LTlkY2QtZmMyYTI2ZjZlZTUy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:38 GMT]}] 2019-03-20 10:41:39 DEBUG [AutoCodeGeneratorCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTk4ZDMzYTctNjk1Mi00NjI4LTlkY2QtZmMyYTI2ZjZlZTUy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:38 GMT]}] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1] : URL [http://13.56.210.25/api/v1/projects] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1] : Method [POST] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1] : Request [{ "account" : "", "autoGenSuites" : "1018200011", "branch" : "cCjyAB9D", "bugsOpen" : "1018200011", "createdBy" : "", "createdDate" : "", "description" : "cCjyAB9D", "genPolicy" : "Create", "id" : "", "inactive" : false, "isFileLoad" : "cCjyAB9D", "issueTracker" : "", "lastCommit" : "cCjyAB9D", "lastSync" : null, "modifiedBy" : "", "modifiedDate" : "", "name" : "cCjyAB9D", "openAPISpec" : "cCjyAB9D", "openText" : "cCjyAB9D", "org" : "", "props" : null, "url" : "cCjyAB9D", "version" : "" }] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:39.638+0000", "status" : 400, "error" : "Bad Request", "message" : "JSON parse error: Cannot construct instance ofcom.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance ofcom.fxlabs.fxt.dto.base.AccountMinimalDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 2, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.Project[\"account\"])", "path" : "/api/v1/projects" }] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTAyZWMzZWItMTZjZi00NGI5LTk2ZGMtZGI5ZDFkYmUyZjRi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:39 GMT]}] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1] : StatusCode [400] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1] : Time [506] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1] : Size [744] 2019-03-20 10:41:39 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTAyZWMzZWItMTZjZi00NGI5LTk2ZGMtZGI5ZDFkYmUyZjRi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:39 GMT]}] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTAyZWMzZWItMTZjZi00NGI5LTk2ZGMtZGI5ZDFkYmUyZjRi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:39 GMT]}] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTAyZWMzZWItMTZjZi00NGI5LTk2ZGMtZGI5ZDFkYmUyZjRi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:39 GMT]}] 2019-03-20 10:41:39 DEBUG [ProjectCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTAyZWMzZWItMTZjZi00NGI5LTk2ZGMtZGI5ZDFkYmUyZjRi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:39 GMT]}] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : URL [http://13.56.210.25/api/v1/autocode-generator] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Method [POST] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Request [{ "abacResources" : [ { "createBody" : "keSyUCAf", "createEndpoint" : "keSyUCAf", "createUserAuth" : "keSyUCAf", "createdBy" : "", "createdDate" : "", "deleteEndpoint" : "keSyUCAf", "enumValues" : "keSyUCAf", "generatorId" : "keSyUCAf", "id" : "", "inactive" : false, "initScriptName" : "keSyUCAf", "lock" : false, "modifiedBy" : "", "modifiedDate" : "", "resourceName" : "keSyUCAf", "scripts" : [ { "body" : "keSyUCAf", "deleteEndPoint" : "keSyUCAf", "endpoint" : "keSyUCAf", "resourceName" : "keSyUCAf", "scriptName" : "keSyUCAf", "scriptType" : "keSyUCAf", "sequence" : "2096000836", "userAuth" : "keSyUCAf", "validationScript" : false } ], "typeThreeCreateEndpoint" : "keSyUCAf", "validations" : [ { "body" : "keSyUCAf", "endpoint" : "keSyUCAf", "inactive" : false, "lock" : false, "path" : "keSyUCAf", "userAuth" : "keSyUCAf", "validationType" : "keSyUCAf" } ], "version" : "" } ], "assertionDescription" : "keSyUCAf", "assertions" : [ "keSyUCAf" ], "assertionsText" : "keSyUCAf", "authors" : "keSyUCAf", "category" : "SQL_Injection", "coverageMultiplier" : "2096000836", "currentScripts" : "2096000836", "database" : { "name" : "keSyUCAf", "version" : "" }, "displayHeaderDescription" : "keSyUCAf", "displayHeaderLabel" : "keSyUCAf", "expectedScripts" : "2096000836", "fixHours" : "keSyUCAf", "id" : "", "inactive" : false, "matches" : [ { "allowRoles" : "keSyUCAf", "bodyProperties" : "keSyUCAf", "denyRoles" : "keSyUCAf", "id" : "", "methods" : "keSyUCAf", "name" : "keSyUCAf", "pathPatterns" : "keSyUCAf", "queryParams" : "keSyUCAf", "resourceSamples" : "keSyUCAf", "value" : "keSyUCAf" } ], "newlyAdded" : false, "project" : "", "sequenceOrder" : "2096000836", "severity" : "Major", "tags" : [ "keSyUCAf" ], "type" : "keSyUCAf" }] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:40.104+0000", "status" : 400, "error" : "Bad Request", "message" : "JSON parse error: Cannot construct instance ofcom.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance ofcom.fxlabs.fxt.dto.project.Project
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 71, column: 15] (through reference chain: com.fxlabs.fxt.dto.project.AutoCodeGenerator[\"project\"])", "path" : "/api/v1/autocode-generator" }] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MGQxNjIxY2MtMGM0OS00ZjRjLThjZDYtOGMwZjg1ZWJiN2U4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:39 GMT]}] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : StatusCode [400] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Time [465] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Size [751] 2019-03-20 10:41:40 ERROR [ApiV1AutocodeGeneratorPostAutocodegeneratoruserbDisallowHijack1] : Assertion [@StatusCode == 401 OR @StatusCode == 403] resolved-to [400 == 401 OR 400 == 403] result [Failed] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : URL [http://13.56.210.25/api/v1/autocode-generator/] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Method [DELETE] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Request [null] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Response [{ "timestamp" : "2019-03-20T10:41:40.883+0000", "status" : 405, "error" : "Method Not Allowed", "message" : "Request method 'DELETE' not supported", "path" : "/api/v1/autocode-generator/" }] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Response-Headers [{Allow=[GET, PUT, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YjMwOWIwOTMtY2M4MC00NDk1LThmMjctNjhlMmRmNWU1NDBl; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:40 GMT]}] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : StatusCode [405] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Time [776] 2019-03-20 10:41:40 DEBUG [ApiV1AutocodeGeneratorIdDeleteAutocodegeneratorhijack1] : Size [173] 2019-03-20 10:41:40 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed] 2019-03-20 10:41:41 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : URL [http://13.56.210.25/api/v1/projects/] 2019-03-20 10:41:41 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Method [DELETE] 2019-03-20 10:41:41 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Request [null] 2019-03-20 10:41:41 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:41 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Response [{ "timestamp" : "2019-03-20T10:41:41.248+0000", "status" : 405, "error" : "Method Not Allowed", "message" : "Request method 'DELETE' not supported", "path" : "/api/v1/projects/" }] 2019-03-20 10:41:41 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Response-Headers [{Allow=[GET, POST, PUT], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjRmM2Y5NTktNGJhZC00ZDViLWI4YmItNzY2Y2JjZmU2MTI3; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:40 GMT]}] 2019-03-20 10:41:41 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : StatusCode [405] 2019-03-20 10:41:41 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Time [367] 2019-03-20 10:41:41 DEBUG [ApiV1ProjectsIdDeleteProjecthijack1] : Size [163] 2019-03-20 10:41:41 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed] 2019-03-20 10:41:41 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : URL [http://13.56.210.25/api/v1/issue-trackers/issue-tracker-bot/] 2019-03-20 10:41:41 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Method [DELETE] 2019-03-20 10:41:41 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Request [null] 2019-03-20 10:41:41 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:41 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Response [{ "timestamp" : "2019-03-20T10:41:41.809+0000", "status" : 405, "error" : "Method Not Allowed", "message" : "Request method 'DELETE' not supported", "path" : "/api/v1/issue-trackers/issue-tracker-bot/" }] 2019-03-20 10:41:41 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Response-Headers [{Allow=[POST, GET, PUT], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZjEwYzczOWMtZmQxMy00OGEwLTk0ODYtY2U2MGE1ZjBiMGVk; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:41 GMT]}] 2019-03-20 10:41:41 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : StatusCode [405] 2019-03-20 10:41:41 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Time [558] 2019-03-20 10:41:41 DEBUG [ApiV1IssueTrackersIssueTrackerBotIdDeleteIssuetrackerhijack1] : Size [187] 2019-03-20 10:41:41 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed] 2019-03-20 10:41:42 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : URL [http://13.56.210.25/api/v1/skills/] 2019-03-20 10:41:42 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Method [DELETE] 2019-03-20 10:41:42 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Request [null] 2019-03-20 10:41:42 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:42 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Response [{ "timestamp" : "2019-03-20T10:41:42.663+0000", "status" : 405, "error" : "Method Not Allowed", "message" : "Request method 'DELETE' not supported", "path" : "/api/v1/skills/" }] 2019-03-20 10:41:42 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Response-Headers [{Allow=[GET, POST, PUT], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MDU1ZjI2OGEtYmI1Mi00MTcyLTgwZTctMDUxYzMyM2NlZDQz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:42 GMT]}] 2019-03-20 10:41:42 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : StatusCode [405] 2019-03-20 10:41:42 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Time [853] 2019-03-20 10:41:42 DEBUG [ApiV1SkillsIdDeleteSkillhijack1] : Size [161] 2019-03-20 10:41:42 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed] 2019-03-20 10:41:43 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : URL [http://13.56.210.25/api/v1/accounts/] 2019-03-20 10:41:43 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Method [DELETE] 2019-03-20 10:41:43 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Request [null] 2019-03-20 10:41:43 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:43 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Response [{ "timestamp" : "2019-03-20T10:41:43.248+0000", "status" : 405, "error" : "Method Not Allowed", "message" : "Request method 'DELETE' not supported", "path" : "/api/v1/accounts/" }] 2019-03-20 10:41:43 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Response-Headers [{Allow=[GET, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MzY0NTNmNTktNWE5OS00NzQ2LTljZjEtMGU5YjFiZDAyNTcz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:42 GMT]}] 2019-03-20 10:41:43 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : StatusCode [405] 2019-03-20 10:41:43 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Time [583] 2019-03-20 10:41:43 DEBUG [ApiV1AccountsIdDeleteAccounthijack1] : Size [163] 2019-03-20 10:41:43 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed] 2019-03-20 10:41:43 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : URL [http://13.56.210.25/api/v1/orgs/] 2019-03-20 10:41:43 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Method [DELETE] 2019-03-20 10:41:43 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request [null] 2019-03-20 10:41:43 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:43 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response [{ "timestamp" : "2019-03-20T10:41:43.947+0000", "status" : 405, "error" : "Method Not Allowed", "message" : "Request method 'DELETE' not supported", "path" : "/api/v1/orgs/" }] 2019-03-20 10:41:43 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response-Headers [{Allow=[GET, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YWFmOGFiNTItNDcyZS00ZWI1LWIyMzktZDI1YTMzMmUzYzFh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:43 GMT]}] 2019-03-20 10:41:43 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : StatusCode [405] 2019-03-20 10:41:43 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Time [699] 2019-03-20 10:41:43 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Size [159] 2019-03-20 10:41:43 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]--- FX Bot ---