Open asriz7777 opened 5 years ago
Project : FXABAC TEST
Template : ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1
Run Id : 8a808011699a990101699ab3901a2277
Job : Default
Env : Default
Category : Hijack_Level1
Tags : [FX Top 10 - API Vulnerability, Data_Access_Control]
Severity : Major
Region : FXLabs/US_WEST_1
Result : fail
Status Code : 400
Headers : {X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MGFiN2ZlMTQtM2YyMi00MTk3LTg3NTQtNTBjMGY1NTRiYWVi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:46 GMT]}
Endpoint : http://13.56.210.25/api/v1/users/addUserToOrg
Request :
{
"createdBy" : "",
"createdDate" : "",
"forceResetPwd" : false,
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"org" : "",
"orgRole" : "WRITE",
"status" : "ACTIVE",
"userType" : "DEFAULT",
"users" : "",
"version" : ""
}
Response :
{
"timestamp" : "2019-03-20T10:44:47.100+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 9, column: 11] (through reference chain: com.fxlabs.fxt.dto.users.OrgUsers[\"org\"])",
"path" : "/api/v1/users/addUserToOrg"
}
Logs :
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/users/enterprise-sign-up]
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1] : Request [{
"accountNonExpired" : false,
"accountNonLocked" : false,
"company" : "Altenwerth and Sons",
"createdBy" : "",
"createdDate" : "",
"credentialsNonExpired" : false,
"email" : "bernadette.hirthe@hotmail.com",
"enabled" : false,
"id" : "",
"inactive" : false,
"jobTitle" : "National Designer",
"location" : "Y9surNIf",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "Y9surNIf",
"password" : "Y9surNIf",
"username" : "owen.morissette",
"version" : ""
}]
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:42.227+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/users/enterprise-sign-up"
}]
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZmVmMGM0MmYtMmZjZS00NzJmLWE3OWMtZTM0YjQyZDRlMmRj; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:41 GMT]}]
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1] : StatusCode [403]
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1] : Time [909]
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1] : Size [141]
2019-03-20 10:44:42 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZmVmMGM0MmYtMmZjZS00NzJmLWE3OWMtZTM0YjQyZDRlMmRj; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:41 GMT]}]
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZmVmMGM0MmYtMmZjZS00NzJmLWE3OWMtZTM0YjQyZDRlMmRj; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:41 GMT]}]
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZmVmMGM0MmYtMmZjZS00NzJmLWE3OWMtZTM0YjQyZDRlMmRj; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:41 GMT]}]
2019-03-20 10:44:42 DEBUG [UsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZmVmMGM0MmYtMmZjZS00NzJmLWE3OWMtZTM0YjQyZDRlMmRj; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:41 GMT]}]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/orgs]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1] : Request [{
"billingEmail" : "U1yPRvqp",
"company" : "Harvey, Harvey and Harvey",
"createdBy" : "",
"createdDate" : "",
"description" : "U1yPRvqp",
"id" : "",
"inactive" : false,
"location" : "U1yPRvqp",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "U1yPRvqp",
"orgPlan" : "TEAM",
"orgType" : "ENTERPRISE",
"version" : ""
}]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:43.081+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/orgs"
}]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTU2OTkyZmEtNGE1ZC00ZmVjLTlhYTMtNDMxZjYxYjg1ZTcw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:42 GMT]}]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1] : StatusCode [403]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1] : Time [803]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1] : Size [121]
2019-03-20 10:44:43 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTU2OTkyZmEtNGE1ZC00ZmVjLTlhYTMtNDMxZjYxYjg1ZTcw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:42 GMT]}]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTU2OTkyZmEtNGE1ZC00ZmVjLTlhYTMtNDMxZjYxYjg1ZTcw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:42 GMT]}]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTU2OTkyZmEtNGE1ZC00ZmVjLTlhYTMtNDMxZjYxYjg1ZTcw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:42 GMT]}]
2019-03-20 10:44:43 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTU2OTkyZmEtNGE1ZC00ZmVjLTlhYTMtNDMxZjYxYjg1ZTcw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:42 GMT]}]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/users/addUserToOrg]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1] : Request [{
"createdBy" : "",
"createdDate" : "",
"forceResetPwd" : false,
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"org" : "",
"orgRole" : "ADMIN",
"status" : "INACTIVE",
"userType" : "MANAGED",
"users" : "",
"version" : ""
}]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:43.805+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 9, column: 11] (through reference chain: com.fxlabs.fxt.dto.users.OrgUsers[\"org\"])",
"path" : "/api/v1/users/addUserToOrg"
}]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZDZiMTE2ZmItOTM5NC00OTI3LTk0YmEtZTI1ODI2MjhlOGFh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:43 GMT]}]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1] : Time [720]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1] : Size [729]
2019-03-20 10:44:43 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZDZiMTE2ZmItOTM5NC00OTI3LTk0YmEtZTI1ODI2MjhlOGFh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:43 GMT]}]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZDZiMTE2ZmItOTM5NC00OTI3LTk0YmEtZTI1ODI2MjhlOGFh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:43 GMT]}]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZDZiMTE2ZmItOTM5NC00OTI3LTk0YmEtZTI1ODI2MjhlOGFh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:43 GMT]}]
2019-03-20 10:44:43 DEBUG [OrgUsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZDZiMTE2ZmItOTM5NC00OTI3LTk0YmEtZTI1ODI2MjhlOGFh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:43 GMT]}]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1] : URL [http://13.56.210.25/api/v1/orgs]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1] : Method [POST]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1] : Request [{
"billingEmail" : "NtDjg1lL",
"company" : "Prohaska-Prohaska",
"createdBy" : "",
"createdDate" : "",
"description" : "NtDjg1lL",
"id" : "",
"inactive" : false,
"location" : "NtDjg1lL",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "NtDjg1lL",
"orgPlan" : "TEAM",
"orgType" : "ENTERPRISE",
"version" : ""
}]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:44.890+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/orgs"
}]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTIwMWQxMDgtOWYyNy00YjQ1LWIxMDAtMGU4NDVhNmI4ZDFj; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:44 GMT]}]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1] : StatusCode [403]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1] : Time [1034]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1] : Size [121]
2019-03-20 10:44:44 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTIwMWQxMDgtOWYyNy00YjQ1LWIxMDAtMGU4NDVhNmI4ZDFj; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:44 GMT]}]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTIwMWQxMDgtOWYyNy00YjQ1LWIxMDAtMGU4NDVhNmI4ZDFj; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:44 GMT]}]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTIwMWQxMDgtOWYyNy00YjQ1LWIxMDAtMGU4NDVhNmI4ZDFj; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:44 GMT]}]
2019-03-20 10:44:44 DEBUG [OrgCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NTIwMWQxMDgtOWYyNy00YjQ1LWIxMDAtMGU4NDVhNmI4ZDFj; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:44 GMT]}]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1] : URL [http://13.56.210.25/api/v1/users/enterprise-sign-up]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1] : Method [POST]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1] : Request [{
"accountNonExpired" : false,
"accountNonLocked" : false,
"company" : "Treutel and Sons",
"createdBy" : "",
"createdDate" : "",
"credentialsNonExpired" : false,
"email" : "bryana.johnson@hotmail.com",
"enabled" : false,
"id" : "",
"inactive" : false,
"jobTitle" : "Sales Agent",
"location" : "zWApavXr",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "zWApavXr",
"password" : "zWApavXr",
"username" : "colin.larson",
"version" : ""
}]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:46.291+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/users/enterprise-sign-up"
}]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjYyY2Y5ZDUtNzhjNC00ZTYzLWI2ZWEtODFlNDYxNzNkNGYy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:45 GMT]}]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1] : StatusCode [403]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1] : Time [1080]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1] : Size [141]
2019-03-20 10:44:46 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjYyY2Y5ZDUtNzhjNC00ZTYzLWI2ZWEtODFlNDYxNzNkNGYy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:45 GMT]}]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjYyY2Y5ZDUtNzhjNC00ZTYzLWI2ZWEtODFlNDYxNzNkNGYy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:45 GMT]}]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjYyY2Y5ZDUtNzhjNC00ZTYzLWI2ZWEtODFlNDYxNzNkNGYy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:45 GMT]}]
2019-03-20 10:44:46 DEBUG [UsersCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjYyY2Y5ZDUtNzhjNC00ZTYzLWI2ZWEtODFlNDYxNzNkNGYy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:45 GMT]}]
2019-03-20 10:44:47 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : URL [http://13.56.210.25/api/v1/users/addUserToOrg]
2019-03-20 10:44:47 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Method [POST]
2019-03-20 10:44:47 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Request [{
"createdBy" : "",
"createdDate" : "",
"forceResetPwd" : false,
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"org" : "",
"orgRole" : "WRITE",
"status" : "ACTIVE",
"userType" : "DEFAULT",
"users" : "",
"version" : ""
}]
2019-03-20 10:44:47 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:47 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Response [{
"timestamp" : "2019-03-20T10:44:47.100+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 9, column: 11] (through reference chain: com.fxlabs.fxt.dto.users.OrgUsers[\"org\"])",
"path" : "/api/v1/users/addUserToOrg"
}]
2019-03-20 10:44:47 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MGFiN2ZlMTQtM2YyMi00MTk3LTg3NTQtNTBjMGY1NTRiYWVi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:46 GMT]}]
2019-03-20 10:44:47 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : StatusCode [400]
2019-03-20 10:44:47 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Time [808]
2019-03-20 10:44:47 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Size [729]
2019-03-20 10:44:47 ERROR [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Assertion [@StatusCode == 401 OR @StatusCode == 403] resolved-to [400 == 401 OR 400 == 403] result [Failed]
2019-03-20 10:44:48 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : URL [http://13.56.210.25/api/v1/orgs/]
2019-03-20 10:44:48 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Method [DELETE]
2019-03-20 10:44:48 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request [null]
2019-03-20 10:44:48 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:44:48 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response [{
"timestamp" : "2019-03-20T10:44:48.246+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/orgs/"
}]
2019-03-20 10:44:48 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response-Headers [{Allow=[GET, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTBkZmM0MDEtMDBkOC00ODVmLWFkOWYtYjUzYWFhNWE5MWU3; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:44:47 GMT]}]
2019-03-20 10:44:48 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : StatusCode [405]
2019-03-20 10:44:48 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Time [1145]
2019-03-20 10:44:48 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Size [159]
2019-03-20 10:44:48 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
--- FX Bot ---
Project : FXABAC TEST
Template : ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1
Run Id : 8a808011699a990101699ab3901a2277
Job : Default
Env : Default
Category : Hijack_Level1
Tags : [FX Top 10 - API Vulnerability, Data_Access_Control]
Severity : Major
Region : FXLabs/US_WEST_1
Result : fail
Status Code : 400
Headers : {X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjY5NTBlNGUtM2FkNS00MzI5LWI0M2ItYTllNDdmNmU4YTFh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:34 GMT]}
Endpoint : http://13.56.210.25/api/v1/users/addUserToOrg
Request :
{
"createdBy" : "",
"createdDate" : "",
"forceResetPwd" : false,
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"org" : "",
"orgRole" : "WRITE",
"status" : "ACTIVE",
"userType" : "DEFAULT",
"users" : "",
"version" : ""
}
Response :
{
"timestamp" : "2019-03-20T10:45:34.609+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 9, column: 11] (through reference chain: com.fxlabs.fxt.dto.users.OrgUsers[\"org\"])",
"path" : "/api/v1/users/addUserToOrg"
}
Logs :
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/users/enterprise-sign-up]
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1] : Request [{
"accountNonExpired" : false,
"accountNonLocked" : false,
"company" : "Collier, Collier and Collier",
"createdBy" : "",
"createdDate" : "",
"credentialsNonExpired" : false,
"email" : "danial.corwin@yahoo.com",
"enabled" : false,
"id" : "",
"inactive" : false,
"jobTitle" : "Investor Agent",
"location" : "swm5BMGa",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "swm5BMGa",
"password" : "swm5BMGa",
"username" : "madelyn.schiller",
"version" : ""
}]
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:45:28.658+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/users/enterprise-sign-up"
}]
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MmQ4Nzc2MWEtOWQ3Yy00YzA0LWI1ZDUtOTcwNGMxMmUxNjcy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:28 GMT]}]
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1] : StatusCode [403]
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1] : Time [1244]
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1] : Size [141]
2019-03-20 10:45:28 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MmQ4Nzc2MWEtOWQ3Yy00YzA0LWI1ZDUtOTcwNGMxMmUxNjcy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:28 GMT]}]
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MmQ4Nzc2MWEtOWQ3Yy00YzA0LWI1ZDUtOTcwNGMxMmUxNjcy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:28 GMT]}]
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MmQ4Nzc2MWEtOWQ3Yy00YzA0LWI1ZDUtOTcwNGMxMmUxNjcy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:28 GMT]}]
2019-03-20 10:45:28 DEBUG [UsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MmQ4Nzc2MWEtOWQ3Yy00YzA0LWI1ZDUtOTcwNGMxMmUxNjcy; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:28 GMT]}]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/orgs]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1] : Request [{
"billingEmail" : "VRVf48vo",
"company" : "Lowe-Lowe",
"createdBy" : "",
"createdDate" : "",
"description" : "VRVf48vo",
"id" : "",
"inactive" : false,
"location" : "VRVf48vo",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "VRVf48vo",
"orgPlan" : "TEAM",
"orgType" : "ENTERPRISE",
"version" : ""
}]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:45:29.775+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/orgs"
}]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjNjYzhjMTItM2I0OS00ZjMyLWIzYzItNmE0YTVjNWE3ZmUw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:29 GMT]}]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1] : StatusCode [403]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1] : Time [1060]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1] : Size [121]
2019-03-20 10:45:29 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjNjYzhjMTItM2I0OS00ZjMyLWIzYzItNmE0YTVjNWE3ZmUw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:29 GMT]}]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjNjYzhjMTItM2I0OS00ZjMyLWIzYzItNmE0YTVjNWE3ZmUw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:29 GMT]}]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjNjYzhjMTItM2I0OS00ZjMyLWIzYzItNmE0YTVjNWE3ZmUw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:29 GMT]}]
2019-03-20 10:45:29 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjNjYzhjMTItM2I0OS00ZjMyLWIzYzItNmE0YTVjNWE3ZmUw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:29 GMT]}]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/users/addUserToOrg]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1] : Request [{
"createdBy" : "",
"createdDate" : "",
"forceResetPwd" : false,
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"org" : "",
"orgRole" : "ADMIN",
"status" : "INACTIVE",
"userType" : "MANAGED",
"users" : "",
"version" : ""
}]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:45:30.484+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 9, column: 11] (through reference chain: com.fxlabs.fxt.dto.users.OrgUsers[\"org\"])",
"path" : "/api/v1/users/addUserToOrg"
}]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=Y2Q2YTM3YzQtNzE3Ny00NzZhLThmNzEtNDVmZDMwY2U3Yzcz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:30 GMT]}]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1] : Time [709]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1] : Size [729]
2019-03-20 10:45:30 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=Y2Q2YTM3YzQtNzE3Ny00NzZhLThmNzEtNDVmZDMwY2U3Yzcz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:30 GMT]}]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=Y2Q2YTM3YzQtNzE3Ny00NzZhLThmNzEtNDVmZDMwY2U3Yzcz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:30 GMT]}]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=Y2Q2YTM3YzQtNzE3Ny00NzZhLThmNzEtNDVmZDMwY2U3Yzcz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:30 GMT]}]
2019-03-20 10:45:30 DEBUG [OrgUsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=Y2Q2YTM3YzQtNzE3Ny00NzZhLThmNzEtNDVmZDMwY2U3Yzcz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:30 GMT]}]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1] : URL [http://13.56.210.25/api/v1/orgs]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1] : Method [POST]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1] : Request [{
"billingEmail" : "rxbZxq8X",
"company" : "Koch, Koch and Koch",
"createdBy" : "",
"createdDate" : "",
"description" : "rxbZxq8X",
"id" : "",
"inactive" : false,
"location" : "rxbZxq8X",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "rxbZxq8X",
"orgPlan" : "TEAM",
"orgType" : "ENTERPRISE",
"version" : ""
}]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:45:31.587+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/orgs"
}]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzgwMGYwOGYtMjI4ZS00NDI1LTkyOTktM2JiNWU3NzZjNTYw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:31 GMT]}]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1] : StatusCode [403]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1] : Time [1027]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1] : Size [121]
2019-03-20 10:45:31 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzgwMGYwOGYtMjI4ZS00NDI1LTkyOTktM2JiNWU3NzZjNTYw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:31 GMT]}]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzgwMGYwOGYtMjI4ZS00NDI1LTkyOTktM2JiNWU3NzZjNTYw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:31 GMT]}]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzgwMGYwOGYtMjI4ZS00NDI1LTkyOTktM2JiNWU3NzZjNTYw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:31 GMT]}]
2019-03-20 10:45:31 DEBUG [OrgCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzgwMGYwOGYtMjI4ZS00NDI1LTkyOTktM2JiNWU3NzZjNTYw; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:31 GMT]}]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1] : URL [http://13.56.210.25/api/v1/users/enterprise-sign-up]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1] : Method [POST]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1] : Request [{
"accountNonExpired" : false,
"accountNonLocked" : false,
"company" : "Altenwerth-Altenwerth",
"createdBy" : "",
"createdDate" : "",
"credentialsNonExpired" : false,
"email" : "mason.kohler@hotmail.com",
"enabled" : false,
"id" : "",
"inactive" : false,
"jobTitle" : "International Hospitality Orchestrator",
"location" : "b8tpabm3",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "b8tpabm3",
"password" : "b8tpabm3",
"username" : "geovany.sawayn",
"version" : ""
}]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:45:33.248+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/users/enterprise-sign-up"
}]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTgwZjY1YTEtOGFhMi00YzhiLTgzNmYtYmFmN2UwZjE0MjA1; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:32 GMT]}]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1] : StatusCode [403]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1] : Time [1427]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1] : Size [141]
2019-03-20 10:45:33 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTgwZjY1YTEtOGFhMi00YzhiLTgzNmYtYmFmN2UwZjE0MjA1; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:32 GMT]}]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTgwZjY1YTEtOGFhMi00YzhiLTgzNmYtYmFmN2UwZjE0MjA1; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:32 GMT]}]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTgwZjY1YTEtOGFhMi00YzhiLTgzNmYtYmFmN2UwZjE0MjA1; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:32 GMT]}]
2019-03-20 10:45:33 DEBUG [UsersCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTgwZjY1YTEtOGFhMi00YzhiLTgzNmYtYmFmN2UwZjE0MjA1; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:32 GMT]}]
2019-03-20 10:45:34 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : URL [http://13.56.210.25/api/v1/users/addUserToOrg]
2019-03-20 10:45:34 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Method [POST]
2019-03-20 10:45:34 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Request [{
"createdBy" : "",
"createdDate" : "",
"forceResetPwd" : false,
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"org" : "",
"orgRole" : "WRITE",
"status" : "ACTIVE",
"userType" : "DEFAULT",
"users" : "",
"version" : ""
}]
2019-03-20 10:45:34 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:34 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Response [{
"timestamp" : "2019-03-20T10:45:34.609+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 9, column: 11] (through reference chain: com.fxlabs.fxt.dto.users.OrgUsers[\"org\"])",
"path" : "/api/v1/users/addUserToOrg"
}]
2019-03-20 10:45:34 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjY5NTBlNGUtM2FkNS00MzI5LWI0M2ItYTllNDdmNmU4YTFh; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:34 GMT]}]
2019-03-20 10:45:34 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : StatusCode [400]
2019-03-20 10:45:34 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Time [1358]
2019-03-20 10:45:34 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Size [729]
2019-03-20 10:45:34 ERROR [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Assertion [@StatusCode == 401 OR @StatusCode == 403] resolved-to [400 == 401 OR 400 == 403] result [Failed]
2019-03-20 10:45:36 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : URL [http://13.56.210.25/api/v1/orgs/]
2019-03-20 10:45:36 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Method [DELETE]
2019-03-20 10:45:36 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request [null]
2019-03-20 10:45:36 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:45:36 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response [{
"timestamp" : "2019-03-20T10:45:36.080+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/orgs/"
}]
2019-03-20 10:45:36 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response-Headers [{Allow=[GET, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=OTQxNjJmMWYtMTBiNi00MmZmLThkYTgtNzE0ODQ4OTA1Zjg4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:45:35 GMT]}]
2019-03-20 10:45:36 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : StatusCode [405]
2019-03-20 10:45:36 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Time [1470]
2019-03-20 10:45:36 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Size [159]
2019-03-20 10:45:36 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
--- FX Bot ---
Project : FXABAC TEST
Template : ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1
Run Id : 8a808011699a990101699ab3901a2277
Job : Default
Env : Default
Category : Hijack_Level1
Tags : [FX Top 10 - API Vulnerability, Data_Access_Control]
Severity : Major
Region : FXLabs/US_WEST_1
Result : fail
Status Code : 400
Headers : {X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MmZkYmY5MDMtMDQwYi00NDU1LTg1MzMtZmNiN2IyNzc2Yzc5; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:58 GMT]}
Endpoint : http://13.56.210.25/api/v1/users/addUserToOrg
Request :
{
"createdBy" : "",
"createdDate" : "",
"forceResetPwd" : false,
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"org" : "",
"orgRole" : "WRITE",
"status" : "ACTIVE",
"userType" : "DEFAULT",
"users" : "",
"version" : ""
}
Response :
{
"timestamp" : "2019-03-20T10:46:59.234+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 9, column: 11] (through reference chain: com.fxlabs.fxt.dto.users.OrgUsers[\"org\"])",
"path" : "/api/v1/users/addUserToOrg"
}
Logs :
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/users/enterprise-sign-up]
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1] : Request [{
"accountNonExpired" : false,
"accountNonLocked" : false,
"company" : "Ziemann, Ziemann and Ziemann",
"createdBy" : "",
"createdDate" : "",
"credentialsNonExpired" : false,
"email" : "darrick.kling@gmail.com",
"enabled" : false,
"id" : "",
"inactive" : false,
"jobTitle" : "Government Specialist",
"location" : "SNahjPVT",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "SNahjPVT",
"password" : "SNahjPVT",
"username" : "justina.koss",
"version" : ""
}]
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:46:50.715+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/users/enterprise-sign-up"
}]
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZTg0N2M1MzAtNzg3MS00N2FmLThhOGMtOTgzZDI4YzUxYzg0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:50 GMT]}]
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1] : StatusCode [403]
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1] : Time [1627]
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1] : Size [141]
2019-03-20 10:46:50 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZTg0N2M1MzAtNzg3MS00N2FmLThhOGMtOTgzZDI4YzUxYzg0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:50 GMT]}]
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZTg0N2M1MzAtNzg3MS00N2FmLThhOGMtOTgzZDI4YzUxYzg0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:50 GMT]}]
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZTg0N2M1MzAtNzg3MS00N2FmLThhOGMtOTgzZDI4YzUxYzg0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:50 GMT]}]
2019-03-20 10:46:50 DEBUG [UsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZTg0N2M1MzAtNzg3MS00N2FmLThhOGMtOTgzZDI4YzUxYzg0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:50 GMT]}]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/orgs]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1] : Request [{
"billingEmail" : "N1YMeuNf",
"company" : "Marquardt, Marquardt and Marquardt",
"createdBy" : "",
"createdDate" : "",
"description" : "N1YMeuNf",
"id" : "",
"inactive" : false,
"location" : "N1YMeuNf",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "N1YMeuNf",
"orgPlan" : "TEAM",
"orgType" : "ENTERPRISE",
"version" : ""
}]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:46:52.275+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/orgs"
}]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZTMwM2JmYWUtMzEwYS00YTI2LTgyYmEtZmMwMGNjMjFmZjlk; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:52 GMT]}]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1] : StatusCode [403]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1] : Time [1503]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1] : Size [121]
2019-03-20 10:46:52 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZTMwM2JmYWUtMzEwYS00YTI2LTgyYmEtZmMwMGNjMjFmZjlk; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:52 GMT]}]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZTMwM2JmYWUtMzEwYS00YTI2LTgyYmEtZmMwMGNjMjFmZjlk; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:52 GMT]}]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZTMwM2JmYWUtMzEwYS00YTI2LTgyYmEtZmMwMGNjMjFmZjlk; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:52 GMT]}]
2019-03-20 10:46:52 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZTMwM2JmYWUtMzEwYS00YTI2LTgyYmEtZmMwMGNjMjFmZjlk; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:52 GMT]}]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/users/addUserToOrg]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1] : Method [POST]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1] : Request [{
"createdBy" : "",
"createdDate" : "",
"forceResetPwd" : false,
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"org" : "",
"orgRole" : "ADMIN",
"status" : "INACTIVE",
"userType" : "MANAGED",
"users" : "",
"version" : ""
}]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:46:54.122+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 9, column: 11] (through reference chain: com.fxlabs.fxt.dto.users.OrgUsers[\"org\"])",
"path" : "/api/v1/users/addUserToOrg"
}]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=OThlMmY2NGYtY2M0ZC00ZDg4LTg2ZDItNjhkMDkzOTVlNGY4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:54 GMT]}]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1] : StatusCode [400]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1] : Time [1846]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1] : Size [729]
2019-03-20 10:46:54 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=OThlMmY2NGYtY2M0ZC00ZDg4LTg2ZDItNjhkMDkzOTVlNGY4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:54 GMT]}]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=OThlMmY2NGYtY2M0ZC00ZDg4LTg2ZDItNjhkMDkzOTVlNGY4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:54 GMT]}]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=OThlMmY2NGYtY2M0ZC00ZDg4LTg2ZDItNjhkMDkzOTVlNGY4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:54 GMT]}]
2019-03-20 10:46:54 DEBUG [OrgUsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=OThlMmY2NGYtY2M0ZC00ZDg4LTg2ZDItNjhkMDkzOTVlNGY4; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:54 GMT]}]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1] : URL [http://13.56.210.25/api/v1/orgs]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1] : Method [POST]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1] : Request [{
"billingEmail" : "XqiOBiVT",
"company" : "Abshire and Sons",
"createdBy" : "",
"createdDate" : "",
"description" : "XqiOBiVT",
"id" : "",
"inactive" : false,
"location" : "XqiOBiVT",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "XqiOBiVT",
"orgPlan" : "TEAM",
"orgType" : "ENTERPRISE",
"version" : ""
}]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:46:55.633+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/orgs"
}]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzhkMGViNmMtODg4YS00M2MxLWFlNTUtNGJhNWUwODQyYzA2; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:55 GMT]}]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1] : StatusCode [403]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1] : Time [1465]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1] : Size [121]
2019-03-20 10:46:55 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzhkMGViNmMtODg4YS00M2MxLWFlNTUtNGJhNWUwODQyYzA2; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:55 GMT]}]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzhkMGViNmMtODg4YS00M2MxLWFlNTUtNGJhNWUwODQyYzA2; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:55 GMT]}]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzhkMGViNmMtODg4YS00M2MxLWFlNTUtNGJhNWUwODQyYzA2; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:55 GMT]}]
2019-03-20 10:46:55 DEBUG [OrgCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NzhkMGViNmMtODg4YS00M2MxLWFlNTUtNGJhNWUwODQyYzA2; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:55 GMT]}]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1] : URL [http://13.56.210.25/api/v1/users/enterprise-sign-up]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1] : Method [POST]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1] : Request [{
"accountNonExpired" : false,
"accountNonLocked" : false,
"company" : "Donnelly and Sons",
"createdBy" : "",
"createdDate" : "",
"credentialsNonExpired" : false,
"email" : "joy.orn@hotmail.com",
"enabled" : false,
"id" : "",
"inactive" : false,
"jobTitle" : "Consulting Orchestrator",
"location" : "C1uAfLCe",
"modifiedBy" : "",
"modifiedDate" : "",
"name" : "C1uAfLCe",
"password" : "C1uAfLCe",
"username" : "westley.keebler",
"version" : ""
}]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1] : Response [{
"timestamp" : "2019-03-20T10:46:57.539+0000",
"status" : 403,
"error" : "Forbidden",
"message" : "Forbidden",
"path" : "/api/v1/users/enterprise-sign-up"
}]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjA0NDIwZDctZDNkZC00NmEzLWJmZjItMGZlZjU2YWM2N2Ew; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:57 GMT]}]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1] : StatusCode [403]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1] : Time [1689]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1] : Size [141]
2019-03-20 10:46:57 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjA0NDIwZDctZDNkZC00NmEzLWJmZjItMGZlZjU2YWM2N2Ew; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:57 GMT]}]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjA0NDIwZDctZDNkZC00NmEzLWJmZjItMGZlZjU2YWM2N2Ew; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:57 GMT]}]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjA0NDIwZDctZDNkZC00NmEzLWJmZjItMGZlZjU2YWM2N2Ew; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:57 GMT]}]
2019-03-20 10:46:57 DEBUG [UsersCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjA0NDIwZDctZDNkZC00NmEzLWJmZjItMGZlZjU2YWM2N2Ew; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:57 GMT]}]
2019-03-20 10:46:59 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : URL [http://13.56.210.25/api/v1/users/addUserToOrg]
2019-03-20 10:46:59 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Method [POST]
2019-03-20 10:46:59 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Request [{
"createdBy" : "",
"createdDate" : "",
"forceResetPwd" : false,
"id" : "",
"inactive" : false,
"modifiedBy" : "",
"modifiedDate" : "",
"org" : "",
"orgRole" : "WRITE",
"status" : "ACTIVE",
"userType" : "DEFAULT",
"users" : "",
"version" : ""
}]
2019-03-20 10:46:59 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:46:59 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Response [{
"timestamp" : "2019-03-20T10:46:59.234+0000",
"status" : 400,
"error" : "Bad Request",
"message" : "JSON parse error: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance of com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 9, column: 11] (through reference chain: com.fxlabs.fxt.dto.users.OrgUsers[\"org\"])",
"path" : "/api/v1/users/addUserToOrg"
}]
2019-03-20 10:46:59 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MmZkYmY5MDMtMDQwYi00NDU1LTg1MzMtZmNiN2IyNzc2Yzc5; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:46:58 GMT]}]
2019-03-20 10:46:59 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : StatusCode [400]
2019-03-20 10:46:59 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Time [1691]
2019-03-20 10:46:59 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Size [729]
2019-03-20 10:46:59 ERROR [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Assertion [@StatusCode == 401 OR @StatusCode == 403] resolved-to [400 == 401 OR 400 == 403] result [Failed]
2019-03-20 10:47:00 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : URL [http://13.56.210.25/api/v1/orgs/]
2019-03-20 10:47:00 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Method [DELETE]
2019-03-20 10:47:00 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request [null]
2019-03-20 10:47:00 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}]
2019-03-20 10:47:00 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response [{
"timestamp" : "2019-03-20T10:47:00.366+0000",
"status" : 405,
"error" : "Method Not Allowed",
"message" : "Request method 'DELETE' not supported",
"path" : "/api/v1/orgs/"
}]
2019-03-20 10:47:00 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response-Headers [{Allow=[GET, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ODNmN2E1N2MtMWM5MS00NzRjLWEwZmQtMTAzNjRiODdjZDc2; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:47:00 GMT]}]
2019-03-20 10:47:00 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : StatusCode [405]
2019-03-20 10:47:00 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Time [1136]
2019-03-20 10:47:00 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Size [159]
2019-03-20 10:47:00 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]
--- FX Bot ---
Project : FXABAC TEST
Template : ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1
Run Id : 8a808011699a990101699ab0f9761b20
Job : Default
Env : Default
Category : Hijack_Level1
Tags : [FX Top 10 - API Vulnerability, Data_Access_Control]
Severity : Major
Region : FXLabs/US_WEST_1
Result : fail
Status Code : 400
Headers : {X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NGRmOTk4NWEtMDE5NC00MGIxLTkxNWQtMDU1ZmEwNzdmMzcz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:49 GMT]}
Endpoint : http://13.56.210.25/api/v1/users/addUserToOrg
Request :
{ "createdBy" : "", "createdDate" : "", "forceResetPwd" : false, "id" : "", "inactive" : false, "modifiedBy" : "", "modifiedDate" : "", "org" : "", "orgRole" : "WRITE", "status" : "ACTIVE", "userType" : "DEFAULT", "users" : "", "version" : "" }
Response :
{ "timestamp" : "2019-03-20T10:41:50.960+0000", "status" : 400, "error" : "Bad Request", "message" : "JSON parse error: Cannot construct instance of
com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance ofcom.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 9, column: 11] (through reference chain: com.fxlabs.fxt.dto.users.OrgUsers[\"org\"])", "path" : "/api/v1/users/addUserToOrg" }Logs :
2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/users/enterprise-sign-up] 2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1] : Method [POST] 2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1] : Request [{ "accountNonExpired" : false, "accountNonLocked" : false, "company" : "Ledner, Ledner and Ledner", "createdBy" : "", "createdDate" : "", "credentialsNonExpired" : false, "email" : "sallie.sipes@yahoo.com", "enabled" : false, "id" : "", "inactive" : false, "jobTitle" : "Dynamic Strategist", "location" : "0fxfRZX8", "modifiedBy" : "", "modifiedDate" : "", "name" : "0fxfRZX8", "password" : "0fxfRZX8", "username" : "reina.mcdermott", "version" : "" }] 2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:48.094+0000", "status" : 403, "error" : "Forbidden", "message" : "Forbidden", "path" : "/api/v1/users/enterprise-sign-up" }] 2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjQ1YjhlN2UtZDAzZi00YjM1LTkyZjAtNWM2YzcwNzYyODI0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:47 GMT]}] 2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1] : StatusCode [403] 2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1] : Time [678] 2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1] : Size [141] 2019-03-20 10:41:48 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed] 2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjQ1YjhlN2UtZDAzZi00YjM1LTkyZjAtNWM2YzcwNzYyODI0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:47 GMT]}] 2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjQ1YjhlN2UtZDAzZi00YjM1LTkyZjAtNWM2YzcwNzYyODI0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:47 GMT]}] 2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjQ1YjhlN2UtZDAzZi00YjM1LTkyZjAtNWM2YzcwNzYyODI0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:47 GMT]}] 2019-03-20 10:41:48 DEBUG [UsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MjQ1YjhlN2UtZDAzZi00YjM1LTkyZjAtNWM2YzcwNzYyODI0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:47 GMT]}] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/orgs] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1] : Method [POST] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1] : Request [{ "billingEmail" : "TJJY82al", "company" : "Sanford-Sanford", "createdBy" : "", "createdDate" : "", "description" : "TJJY82al", "id" : "", "inactive" : false, "location" : "TJJY82al", "modifiedBy" : "", "modifiedDate" : "", "name" : "TJJY82al", "orgPlan" : "TEAM", "orgType" : "ENTERPRISE", "version" : "" }] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:48.726+0000", "status" : 403, "error" : "Forbidden", "message" : "Forbidden", "path" : "/api/v1/orgs" }] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NmY3NDAxNWItMmI1Ni00N2M2LTlhMjEtZDk1ZTU0Y2Y3NWM0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:47 GMT]}] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1] : StatusCode [403] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1] : Time [515] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1] : Size [121] 2019-03-20 10:41:48 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NmY3NDAxNWItMmI1Ni00N2M2LTlhMjEtZDk1ZTU0Y2Y3NWM0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:47 GMT]}] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NmY3NDAxNWItMmI1Ni00N2M2LTlhMjEtZDk1ZTU0Y2Y3NWM0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:47 GMT]}] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NmY3NDAxNWItMmI1Ni00N2M2LTlhMjEtZDk1ZTU0Y2Y3NWM0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:47 GMT]}] 2019-03-20 10:41:48 DEBUG [OrgCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NmY3NDAxNWItMmI1Ni00N2M2LTlhMjEtZDk1ZTU0Y2Y3NWM0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:47 GMT]}] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1] : URL [http://13.56.210.25/api/v1/users/addUserToOrg] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1] : Method [POST] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1] : Request [{ "createdBy" : "", "createdDate" : "", "forceResetPwd" : false, "id" : "", "inactive" : false, "modifiedBy" : "", "modifiedDate" : "", "org" : "", "orgRole" : "ADMIN", "status" : "INACTIVE", "userType" : "MANAGED", "users" : "", "version" : "" }] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:49.325+0000", "status" : 400, "error" : "Bad Request", "message" : "JSON parse error: Cannot construct instance of
com.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance ofcom.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 9, column: 11] (through reference chain: com.fxlabs.fxt.dto.users.OrgUsers[\"org\"])", "path" : "/api/v1/users/addUserToOrg" }] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTE2ZGM5MWItNThhNy00OTY0LWFiMzEtNTNjZjVmNWUwMzg5; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:48 GMT]}] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1] : StatusCode [400] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1] : Time [595] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1] : Size [729] 2019-03-20 10:41:49 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [400 == 200 OR 400 == 201] result [Failed] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTE2ZGM5MWItNThhNy00OTY0LWFiMzEtNTNjZjVmNWUwMzg5; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:48 GMT]}] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTE2ZGM5MWItNThhNy00OTY0LWFiMzEtNTNjZjVmNWUwMzg5; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:48 GMT]}] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTE2ZGM5MWItNThhNy00OTY0LWFiMzEtNTNjZjVmNWUwMzg5; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:48 GMT]}] 2019-03-20 10:41:49 DEBUG [OrgUsersCreateUserBInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=MTE2ZGM5MWItNThhNy00OTY0LWFiMzEtNTNjZjVmNWUwMzg5; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:48 GMT]}] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1] : URL [http://13.56.210.25/api/v1/orgs] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1] : Method [POST] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1] : Request [{ "billingEmail" : "exkdECcN", "company" : "Hartmann, Hartmann and Hartmann", "createdBy" : "", "createdDate" : "", "description" : "exkdECcN", "id" : "", "inactive" : false, "location" : "exkdECcN", "modifiedBy" : "", "modifiedDate" : "", "name" : "exkdECcN", "orgPlan" : "TEAM", "orgType" : "ENTERPRISE", "version" : "" }] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:49.758+0000", "status" : 403, "error" : "Forbidden", "message" : "Forbidden", "path" : "/api/v1/orgs" }] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjczZDM2MGEtMjE0ZC00ZmQwLThmZWUtZjdjNjRhNzQ4MDk0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:48 GMT]}] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1] : StatusCode [403] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1] : Time [373] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1] : Size [121] 2019-03-20 10:41:49 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjczZDM2MGEtMjE0ZC00ZmQwLThmZWUtZjdjNjRhNzQ4MDk0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:48 GMT]}] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjczZDM2MGEtMjE0ZC00ZmQwLThmZWUtZjdjNjRhNzQ4MDk0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:48 GMT]}] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjczZDM2MGEtMjE0ZC00ZmQwLThmZWUtZjdjNjRhNzQ4MDk0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:48 GMT]}] 2019-03-20 10:41:49 DEBUG [OrgCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NjczZDM2MGEtMjE0ZC00ZmQwLThmZWUtZjdjNjRhNzQ4MDk0; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:48 GMT]}] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1] : URL [http://13.56.210.25/api/v1/users/enterprise-sign-up] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1] : Method [POST] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1] : Request [{ "accountNonExpired" : false, "accountNonLocked" : false, "company" : "Feest Inc", "createdBy" : "", "createdDate" : "", "credentialsNonExpired" : false, "email" : "chelsie.pollich@yahoo.com", "enabled" : false, "id" : "", "inactive" : false, "jobTitle" : "Dynamic Supervisor", "location" : "btFnvzz5", "modifiedBy" : "", "modifiedDate" : "", "name" : "btFnvzz5", "password" : "btFnvzz5", "username" : "domenick.murphy", "version" : "" }] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:50.380+0000", "status" : 403, "error" : "Forbidden", "message" : "Forbidden", "path" : "/api/v1/users/enterprise-sign-up" }] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZThkZjIyN2YtMTZkZS00NDY3LWE2MjUtN2Q5ZTQ1OTBlY2Vi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:49 GMT]}] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1] : StatusCode [403] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1] : Time [360] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1] : Size [141] 2019-03-20 10:41:50 ERROR [null] : Assertion [@StatusCode == 200 OR @StatusCode == 201] resolved-to [403 == 200 OR 403 == 201] result [Failed] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZThkZjIyN2YtMTZkZS00NDY3LWE2MjUtN2Q5ZTQ1OTBlY2Vi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:49 GMT]}] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1_Headers] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZThkZjIyN2YtMTZkZS00NDY3LWE2MjUtN2Q5ZTQ1OTBlY2Vi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:49 GMT]}] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZThkZjIyN2YtMTZkZS00NDY3LWE2MjUtN2Q5ZTQ1OTBlY2Vi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:49 GMT]}] 2019-03-20 10:41:50 DEBUG [UsersCreateUserAInitHijack1_Headers[2]] : Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=ZThkZjIyN2YtMTZkZS00NDY3LWE2MjUtN2Q5ZTQ1OTBlY2Vi; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:49 GMT]}] 2019-03-20 10:41:50 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : URL [http://13.56.210.25/api/v1/users/addUserToOrg] 2019-03-20 10:41:50 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Method [POST] 2019-03-20 10:41:50 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Request [{ "createdBy" : "", "createdDate" : "", "forceResetPwd" : false, "id" : "", "inactive" : false, "modifiedBy" : "", "modifiedDate" : "", "org" : "", "orgRole" : "WRITE", "status" : "ACTIVE", "userType" : "DEFAULT", "users" : "", "version" : "" }] 2019-03-20 10:41:50 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:50 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Response [{ "timestamp" : "2019-03-20T10:41:50.960+0000", "status" : 400, "error" : "Bad Request", "message" : "JSON parse error: Cannot construct instance ofcom.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value (''); nested exception is com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot construct instance ofcom.fxlabs.fxt.dto.base.NameDto
(although at least one Creator exists): no String-argument constructor/factory method to deserialize from String value ('')\n at [Source: (PushbackInputStream); line: 9, column: 11] (through reference chain: com.fxlabs.fxt.dto.users.OrgUsers[\"org\"])", "path" : "/api/v1/users/addUserToOrg" }] 2019-03-20 10:41:50 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=NGRmOTk4NWEtMDE5NC00MGIxLTkxNWQtMDU1ZmEwNzdmMzcz; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:49 GMT]}] 2019-03-20 10:41:50 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : StatusCode [400] 2019-03-20 10:41:50 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Time [571] 2019-03-20 10:41:50 DEBUG [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Size [729] 2019-03-20 10:41:50 ERROR [ApiV1UsersAddusertoorgPostOrgusersuserbDisallowHijack1] : Assertion [@StatusCode == 401 OR @StatusCode == 403] resolved-to [400 == 401 OR 400 == 403] result [Failed] 2019-03-20 10:41:51 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : URL [http://13.56.210.25/api/v1/orgs/] 2019-03-20 10:41:51 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Method [DELETE] 2019-03-20 10:41:51 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request [null] 2019-03-20 10:41:51 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic T1JHQi8vdXNlckJAdGVzdGxhYnMuaW86b3JnMTIzNCQ=]}] 2019-03-20 10:41:51 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response [{ "timestamp" : "2019-03-20T10:41:51.470+0000", "status" : 405, "error" : "Method Not Allowed", "message" : "Request method 'DELETE' not supported", "path" : "/api/v1/orgs/" }] 2019-03-20 10:41:51 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Response-Headers [{Allow=[GET, POST], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Set-Cookie=[SESSION=YzhiM2E5OWEtOTVlMC00YTEyLTk5Y2MtMTQzYjExZjE0YjNm; Path=/; HttpOnly], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 20 Mar 2019 10:41:51 GMT]}] 2019-03-20 10:41:51 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : StatusCode [405] 2019-03-20 10:41:51 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Time [520] 2019-03-20 10:41:51 DEBUG [ApiV1OrgsIdDeleteOrghijack1] : Size [159] 2019-03-20 10:41:51 ERROR [null] : Assertion [@StatusCode == 200] resolved-to [405 == 200] result [Failed]--- FX Bot ---