sohail1024 / testing1

0 stars 0 forks source link

testing github bug management : ExampleV1HotelsIdDeleteRolePmDisallowedRbac #36

Open sohail1024 opened 5 years ago

sohail1024 commented 5 years ago

Project : testing github bug management

Job : Default

Env : Default

Category : RBAC

Tags : [OWASP - OTG-IDENT-001 , FX Top 10 - API Vulnerability, Endpoint_Access_Control]

Severity : Major

Region : FXLabs/US_WEST_1

Result : fail

Status Code : 406

Headers : {X-Application-Context=[application:8090], Content-Length=[0], Date=[Mon, 04 Mar 2019 05:15:35 GMT]}

Endpoint : http://18.144.38.115:8090/example/v1/hotels/NLP16Wue

Request :

Response :

Logs :
2019-03-04 05:15:35 DEBUG [ExampleV1HotelsIdDeleteRolePmDisallowedRbac] : URL [http://18.144.38.115:8090/example/v1/hotels/NLP16Wue] 2019-03-04 05:15:35 DEBUG [ExampleV1HotelsIdDeleteRolePmDisallowedRbac] : Method [DELETE] 2019-03-04 05:15:35 DEBUG [ExampleV1HotelsIdDeleteRolePmDisallowedRbac] : Request [] 2019-03-04 05:15:35 DEBUG [ExampleV1HotelsIdDeleteRolePmDisallowedRbac] : Request-Headers [{Content-Type=[application/json], Accept=[application/xml, application/json]}] 2019-03-04 05:15:35 DEBUG [ExampleV1HotelsIdDeleteRolePmDisallowedRbac] : Response [] 2019-03-04 05:15:35 DEBUG [ExampleV1HotelsIdDeleteRolePmDisallowedRbac] : Response-Headers [{X-Application-Context=[application:8090], Content-Length=[0], Date=[Mon, 04 Mar 2019 05:15:35 GMT]}] 2019-03-04 05:15:35 DEBUG [ExampleV1HotelsIdDeleteRolePmDisallowedRbac] : StatusCode [406] 2019-03-04 05:15:35 DEBUG [ExampleV1HotelsIdDeleteRolePmDisallowedRbac] : Time [69] 2019-03-04 05:15:35 DEBUG [ExampleV1HotelsIdDeleteRolePmDisallowedRbac] : Size [0] 2019-03-04 05:15:35 ERROR [ExampleV1HotelsIdDeleteRolePmDisallowedRbac] : Assertion [@StatusCode == 401 OR @StatusCode == 403] resolved-to [406 == 401 OR 406 == 403] result [Failed]

--- FX Bot ---

sohail1024 commented 5 years ago

Project : testing github bug management

Job : Default

Env : Default

Region : FXLabs/US_WEST_1

Result : fail

Status Code : 406

Headers : {X-Application-Context=[application:8090], Content-Length=[0], Date=[Mon, 04 Mar 2019 05:39:43 GMT]}

Endpoint : http://18.144.38.115:8090/example/v1/hotels/WPCJh21F

Request :

Response :

Logs :
Assertion [@StatusCode == 401 OR @StatusCode == 403] resolved-to [406 == 401 OR 406 == 403] result [Failed] --- FX Bot ---