
शोधकर्ताओं के लिए मार्कडाउन टेम्पलेट्स रखने हेतु रिपॉजिटरी
निर्देशिका संरचना नोट्स:
स्क्रिप्ट generate-directories.py GitHub से VRT संरचना के वर्तमान नवीनतम संस्करण को लेती है और किसी भी लापता निर्देशिका को बनाती है। यह VRT से हटाए गए आइटमों के आधार पर निर्देशिकाओं को नहीं हटाती या उनका नाम नहीं बदलती है।
स्क्रिप्ट मानक प्रविष्टि नामों का पालन करती है और VRT id फ़ील्ड द्वारा प्रदान किए गए अनुसार अंडरस्कोर / केस को बनाए रखती है।
इस रिपो में 'प्रोटेक्टेड मास्टर' सक्षम है; जिसका अर्थ है कि केवल प्रोजेक्ट एडमिन ही पुल रिक्वेस्ट के माध्यम से मास्टर ब्रांच में कमिट कर सकते हैं। अखंडता सुनिश्चित करने के लिए सभी अपडेट पुल रिक्वेस्ट के माध्यम से आने चाहिए।
निम्नलिखित SSH एक्सेस के सही ढंग से कॉन्फ़िगर होने की धारणा के साथ लिखा गया है।
सबसे पहले, मास्टर ब्रांच चेक आउट करें:
git clone [email protected]:bugcrowd/templates.git ## n.b. using SSH aliases can make this much simpler
एक बार जब आपके सिस्टम पर मास्टर आ जाए, तो आपको उस कार्य के लिए एक ब्रांच बनाने की आवश्यकता होगी जो आप करने वाले हैं:
git checkout -b <branch-name>
उदाहरण ब्रांच नाम XXE-templates XSS-templates हो सकते हैं, कुछ ऐसा जो इंगित करता है कि कार्य का हिस्सा क्या है। इन्हें छोटा रखा जाना चाहिए, अधिमानतः टेम्पलेट्स का एक समूह और इससे अधिक कुछ नहीं। बार-बार कमिट और पुश करें!
git commit -am "Comments about what you changed go here" आपके परिवर्तनों को स्थानीय git रिपो में सहेजता है। हमेशा एक वर्णनात्मक कमिट संदेश छोड़ें।
जब आप अपने टेम्पलेट्स पूरे कर लें, तो आप उन्हें रिपो में पुश कर सकते हैं। ये अभी भी अपनी स्वयं की ब्रांच होंगे, लेकिन जब आप पुश करते हैं तो लिंटर चलेगा और नियमों के एक सेट के विरुद्ध मार्कडाउन को मान्य करेगा। यदि आपने उदाहरण टेम्पलेट का पालन किया और अधिक विचलित नहीं हुए, तो टेम्पलेट्स पास हो जाने चाहिए।
git push --set-upstream origin <branch-name> यह ओरिजिन सर्वर (github) पर ब्रांच बनाएगा और आपके परिवर्तनों को पुश करेगा। यह ब्रांच के लिए केवल एक बार करने की आवश्यकता है, और ब्रांच के लिए बाद के पुश git push के साथ किए जा सकते हैं।
लिंटर सफलतापूर्वक चल जाने के बाद, आप एक पुल रिक्वेस्ट (PR) बना सकते हैं।
GitHub इंटरफ़ेस में ब्रांच चुनें। आपको कोड के ऊपर एक 'पुल रिक्वेस्ट' बटन दिखना चाहिए।
उस बटन का चयन करें, फिर प्रोजेक्ट एडमिन द्वारा समीक्षा के लिए क्या बदला गया है इसके बारे में कुछ विवरण भरें, फिर 'क्रिएट पुल रिक्वेस्ट' पर क्लिक करें।
उस बिंदु पर, आपका काम हो गया! हम PR की समीक्षा करेंगे और उचित रूप से मर्ज या अस्वीकार करेंगे।
PR स्वीकार हो जाने के बाद, आप ब्रांच को हटाने के लिए स्वतंत्र हैं
git branch -d <branch-name>
नीचे एक उदाहरण टेम्पलेट है। सभी अनुभागों को सही जानकारी शामिल करने के लिए अद्यतन किया जाना चाहिए।
## Overview of the Vulnerability
Provide a 1-2 sentence description of the vulnerability.
This format is a good guide:
[VULNTYPE] in [COMPONENT] in [APPLICATION] allows [ATTACKER] to [IMPACT] via [VECTOR]
## Business Impact
Provide an example of the impact to the business. This could be reputational damage, financial loss, a loss in customer trust, etc.
## Steps to Reproduce
Provide a step-by-step walkthrough on how to access the vulnerable injection point, and how to exploit the vulnerability.
Example:
1. Login to in-scope asset at <www.bugcrowd.com/login>
1. Browse to account page
1. Modify ID token to add single quote
1. View error which states 'SQL Syntax Error'
1. Replace ID value with `1' waitfor delay '00:00:10'; `
## Proof of Concept (PoC)
Your submission must include evidence of the vulnerability and not be theoretical in nature.
You may present your evidence as output from a tool, such as SQLMap, unless the program forbids the use of these tools. Evidence may also be in the format of terminal output, screenshots, or video.
Use this section to demonstrate clearly the effect of the vulnerability. However, do not access Personally Identifiable Information (PII).
यह एक उदाहरण टेम्पलेट है:
# Reflected Cross-Site Scripting (Non-self)
## Overview of the Vulnerability
Reflected Cross-Site Scripting (XSS) is a type of injection attack where malicious JavaScript code is injected into a website. When a user visits the affected web page, the JavaScript code executes and its input is reflected in the user’s browser. Reflected XSS can be found on this domain which allows an attacker to create a crafted URL. When opened by a user, this URL will execute arbitrary Javascript within that user’s browser in the context of this domain.
When an attacker can control code that is executed within a user’s browser, they are able to carry out any actions that the user is able to perform, including accessing any of the user's data and modifying information within the user’s permissions. This can result in modification, deletion, or theft of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user’s session.
## Business Impact
Reflected XSS could lead to data theft through the attacker’s ability to manipulate data through their access to the application, and their ability to interact with other users, including performing other malicious attacks, which would appear to originate from a legitimate user. These malicious actions could also result in reputational damage for the business through the impact to customers’ trust.
## Steps to Reproduce
1. Enable a HTTP interception proxy, such as Burp Suite or OWASP ZAP
1. Use a browser to navigate to: {{URL}}
1. Forward the following request to the endpoint:
```HTTP Request
{{request}}
```
1. Observe the JavaScript payload being executed
## Proof of Concept (PoC)
Below is a screenshot demonstrating the injected JavaScript executing at the vulnerable endpoint:
{{screenshot}}
जहां संभव हो, कर्मवाच्य (passive voice) का उपयोग करें। उदाहरण के लिए:
सही:
वेब एप्लिकेशन में एक SQL इंजेक्शन भेद्यता की खोज की गई थी।
गलत:
मैंने वेब एप्लिकेशन में एक SQL इंजेक्शन भेद्यता की खोज की।
गलत:
Bugcrowd ने वेब एप्लिकेशन में एक SQL इंजेक्शन भेद्यता की खोज की।
गलत:
हमने वेब एप्लिकेशन में एक SQL इंजेक्शन की खोज की।
गलत:
पूरे आकलन (engagement) के दौरान, वेब एप्लिकेशन (<www.example.com>) में एक क्रिटिकल गंभीरता वाला SQL इंजेक्शन खोजा गया, जिसका उपयोग कोई हमलावर बैकएंड डेटाबेस से व्यक्तिगत रूप से पहचान योग्य जानकारी निकालने के लिए कर सकता था।
सही:
<www.example.com> में एक SQL इंजेक्शन खोजा गया जो एक दुर्भावनापूर्ण हमलावर को व्यक्तिगत रूप से पहचान योग्य जानकारी निकालने की अनुमति देता है।
गलत:
<www.example.com> में एक SQL इंजेक्शन खोजा गया जो एक दुर्भावनापूर्ण हमलावर को ईमेल पते सहित व्यक्तिगत रूप से पहचान योग्य जानकारी निकालने की अनुमति देता है, जिसे GDPR उल्लंघन माना जाएगा और यह काफी व्यावसायिक जोखिम पैदा करता है।
सही:
<www.example.com> में एक SQL इंजेक्शन खोजा गया जो एक दुर्भावनापूर्ण हमलावर को व्यक्तिगत रूप से पहचान योग्य जानकारी निकालने की अनुमति देता है। प्राप्त करने योग्य डेटा में पासवर्ड, ईमेल पते और पूरे नाम शामिल हैं। यह GDPR उल्लंघन और काफी व्यावसायिक जोखिम पैदा करता है।
किसी परिवर्णी शब्द का उपयोग करते समय, पहले पूर्ण संस्करण को कोष्ठक में परिवर्णी शब्द के साथ लिखें। एक बार पूर्ण रूप से लिखे जाने के बाद, बाद के उपयोगों में केवल परिवर्णी शब्द का उपयोग किया जा सकता है।
उदाहरण के लिए:
क्रॉस-साइट स्क्रिप्टिंग (XSS) एक क्लाइंट-साइड हमला है जो एक दुर्भावनापूर्ण हमलावर को पीड़ित के ब्राउज़र में JavaScript निष्पादित करने की अनुमति देता है। XSS तब होता है जब उपयोगकर्ता इनपुट बिना एन्कोडिंग के ब्राउज़र में वापस परिलक्षित होता है।
example.com में क्रॉस-साइट रिक्वेस्ट फोर्जरी (CSRF) की खोज की गई थी। यह CSRF आपको पीड़ित उपयोगकर्ता के पते को उनकी जानकारी के बिना अपडेट करने की अनुमति देता है।
सही: Bugcrowd गलत: BugCrowd, bugcrowd, Bug Crowd, Bug crowd और bug crowd।
सही: pentest (या Pentest यदि व्याकरणिक रूप से आवश्यक हो) गलत: pen test, PenTest, Pen Test