jaleelsyed / fxt_local

0 stars 0 forks source link

demo3 : ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber #274

Open jaleelsyed opened 5 years ago

jaleelsyed commented 5 years ago

Project : demo3

Job : Default

Env : Default

Category : Negative_Number

Tags : [OWASP - OTG-BUSLOGIC-001, Fuzz]

Severity : Major

Region : local

Result : fail

Status Code : 401

Headers : {WWW-Authenticate=[Basic realm="Realm", Basic realm="Realm"], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Content-Length=[0], Date=[Tue, 22 Jan 2019 10:57:30 GMT]}

Endpoint : http://localhost:8080/api/v1/issues/job-id/PPkZtFtg?pageSize=-1&status=PPkZtFtg

Request :

Response :

Logs :
2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : URL [http://localhost:8080/api/v1/issues/job-id/gessYObd?pageSize=-1&status=gessYObd] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Method [GET] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Request [] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic YWRtaW5AZnhsYWJzLmlvOmZ4YWRtaW4xMjM=]}] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Response [] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Response-Headers [{WWW-Authenticate=[Basic realm="Realm", Basic realm="Realm"], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Content-Length=[0], Date=[Tue, 22 Jan 2019 10:57:15 GMT]}] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : StatusCode [401] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Time [1014] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Size [0] 2019-01-22 10:57:15 ERROR [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Assertion [@StatusCode == 404] resolved-to [401 == 404] result [Failed] 2019-01-22 10:57:15 ERROR [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Invalid assertion [@StatusCode ==401] errors [{}]. e.g. valid [ ] i.e. @Request.name == @Response.name

--- FX Bot ---

jaleelsyed commented 5 years ago

Project : demo3

Job : Default

Env : Default

Region : local

Result : fail

Status Code : 401

Headers : {WWW-Authenticate=[Basic realm="Realm", Basic realm="Realm"], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Content-Length=[0], Date=[Tue, 22 Jan 2019 11:00:30 GMT]}

Endpoint : http://localhost:8080/api/v1/issues/job-id/fVImHsIx?pageSize=-1&status=fVImHsIx

Request :

Response :

Logs :
2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : URL [http://localhost:8080/api/v1/issues/job-id/gessYObd?pageSize=-1&status=gessYObd] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Method [GET] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Request [] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic YWRtaW5AZnhsYWJzLmlvOmZ4YWRtaW4xMjM=]}] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Response [] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Response-Headers [{WWW-Authenticate=[Basic realm="Realm", Basic realm="Realm"], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Content-Length=[0], Date=[Tue, 22 Jan 2019 10:57:15 GMT]}] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : StatusCode [401] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Time [1014] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Size [0] 2019-01-22 10:57:15 ERROR [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Assertion [@StatusCode == 404] resolved-to [401 == 404] result [Failed] 2019-01-22 10:57:15 ERROR [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Invalid assertion [@StatusCode ==401] errors [{}]. e.g. valid [ ] i.e. @Request.name == @Response.name

--- FX Bot ---

jaleelsyed commented 5 years ago

Project : demo3

Job : Default

Env : Default

Region : local

Result : fail

Status Code : 401

Headers : {WWW-Authenticate=[Basic realm="Realm", Basic realm="Realm"], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Content-Length=[0], Date=[Tue, 22 Jan 2019 11:00:12 GMT]}

Endpoint : http://localhost:8080/api/v1/issues/job-id/FzbFiAiK?pageSize=-1&status=FzbFiAiK

Request :

Response :

Logs :
2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : URL [http://localhost:8080/api/v1/issues/job-id/gessYObd?pageSize=-1&status=gessYObd] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Method [GET] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Request [] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Request-Headers [{Content-Type=[application/json], Accept=[application/json], Authorization=[Basic YWRtaW5AZnhsYWJzLmlvOmZ4YWRtaW4xMjM=]}] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Response [] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Response-Headers [{WWW-Authenticate=[Basic realm="Realm", Basic realm="Realm"], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Content-Length=[0], Date=[Tue, 22 Jan 2019 10:57:15 GMT]}] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : StatusCode [401] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Time [1014] 2019-01-22 10:57:15 DEBUG [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Size [0] 2019-01-22 10:57:15 ERROR [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Assertion [@StatusCode == 404] resolved-to [401 == 404] result [Failed] 2019-01-22 10:57:15 ERROR [ApiV1IssuesJobIdIdGetQueryParamPagesizeNegativeNumber] : Invalid assertion [@StatusCode ==401] errors [{}]. e.g. valid [ ] i.e. @Request.name == @Response.name

--- FX Bot ---