
Frammenti vulnerabili di Twitter
<!--
Un 'grazie' da parte nostra / YesWeHack
MC0tPjAvJy8qPiovLTAtLyItMS8tMS0wLS8qPjxpbWcvc3JjLyUwYW9uZXJyb3I9LyoqLy1hbGVydCgxKTtvbmVycm9yLy8+
Provalo:
https://dojo-yeswehack.com/Playground#eyJkZXNjcmlwdGlvbiI6IldvcmtzIGluIG1vc3Qgb3V0YnJlYWsgc2VuYXJpb3MgKyBzdGFuZGFyZCBET00gWFNTLCB5dyIsInNvbHV0aW9uIjpudWxsLCJoaW50cyI6W10sInF1ZXJ5Ijp7ImJhY2tlbmQiOiJYU1MiLCJ0ZW1wbGF0ZSI6IlxuPGRpdiB2YWx1ZT1cIiRwYXlsb2FkXCI+XG48ZGl2IHZhbHVlPSckcGF5bG9hZCc+XG5cbjxwIGlkPVwiZG9tXCI+Li4uPC9wPlxuPHNjcmlwdD5cbi8qJHBheWxvYWQqL1xueCA9IFwiJHBheWxvYWRcIjtcbnkgPSAnJHBheWxvYWQnO1xuXG4vL0RPTSBYU1MgUE9DOlxuZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoJ2RvbScpLmlubmVySFRNTD0gYCRwYXlsb2FkYFxuXG4vLyRwYXlsb2FkXG48L3NjcmlwdD4tLT5cbiIsImZpbHRlcnMiOnsiJHBheWxvYWQiOlt7ImZ1bmMiOiJVUkwgZGVjb2RlIiwiYXJncyI6W119XX19fQ==
-->
<div align="center">
<h1><img src="https://assets.kitploit.com/production/public/readmes/48008/f84ecb608ca8909443d56f62f2cfa2071636dd5f603b0a12740aa24d46b6a3ba.png" alt="Logo YWH" width="24" height="auto"> Snippet di codice vulnerabili</h1>
<img src="https://raw.githubusercontent.com/yeswehack/vulnerable-code-snippets/HEAD/img/VsnippetBanner.gif" alt="Banner dello snippet di codice vulnerabile (Vsnippet) del repository Github di YesWeHack" >
</div>
<p align="center">
<a href="#vulnerabilities">Vulnerabilità</a> |
<a href="#programming-languages">Linguaggi di programmazione</a> |
<a href="#run-a-vulnerable-code-snippet">Esegui uno snippet di codice vulnerabile</a> |
<a href="#installation">Installazione</a> |
<a href="#update">Aggiornamento</a>
</p>
[YesWeHack](https://www.yeswehack.com/) presenta snippet di codice contenenti diverse vulnerabilità per esercitarti nell'analisi del codice in un ambiente dockerizzato sicuro. Gli snippet di codice vulnerabili sono adatti a tutti i livelli di competenza.
~ Nuovo **snippet di codice vulnerabile** su Twitter [@yeswehack](https://twitter.com/yeswehack) **ogni venerdì**! 🗒
> Se vuoi vedere qualcosa di speciale o hai semplicemente un'idea per uno snippet di codice vulnerabile, sentiti libero di creare una "[Nuova issue](https://github.com/yeswehack/vulnerable-code-snippets/issues)" in cui spieghi la tua idea, **nessuna idea è stupida**.
---
⚠️ **Attenzione**
> Assicurati di eseguire questo in un ambiente sicuro, poiché il codice è vulnerabile ed è pensato per essere usato per imparare l'analisi del codice!
Di default, tutti gli snippet di codice vulnerabili includono una configurazione docker che isola il codice dal sistema host e lo rende sicuro da eseguire (*leggi di più nella sezione: "Esegui uno snippet di codice vulnerabile"*).
## Post su Twitter (X)
Una raccolta di tutti gli snippet di codice vulnerabili pubblicati sul nostro Twitter 📂
| ID | Vulnerabilità | Descrizione |
|---|---|---|
📜[#1](https://twitter.com/yeswehack/status/1570757831468679169) | **SQLi e XSS** | Collisione del filtro backslash
📜[#2](https://twitter.com/yeswehack/status/1573303741310271490) | **Accesso improprio ai file e XSS** | Carattere non valido e verifica tramite regex
📜[#3](https://twitter.com/yeswehack/status/1575839882269818881) | **Iniezione di Log Forging, Path traversal e Code injection** | Filtro debole e gestione impropria di `include()`
📜[#4](https://twitter.com/yeswehack/status/1578370258230194177) | **XSS** | Filtro non valido per l'input utente
📜[#5](https://twitter.com/yeswehack/status/1580911299382296576) | **SSRF e autorizzazione non corretta** | Input utente considerato attendibile e IP del client dall'header
📜[#6](https://twitter.com/yeswehack/status/1583445497687130114) | **SSTI** | Formato di input misto
📜[#7](https://twitter.com/yeswehack/status/1585979707522134017) | **SQLi** | Uso di una variabile non valida all'interno di un'istruzione
📜[#8](https://twitter.com/yeswehack/status/1588531516665171969) | **CSRF** | Nessun token CSRF incluso
📜[#9](https://twitter.com/yeswehack/status/1591068243439009798) | **Open Redirect** | Handler regex non valido
📜[#10](https://twitter.com/yeswehack/status/1593604941897236485) | **DOM XSS** | Il filtro backend collide con il JavaScript lato client
📜[#11](https://twitter.com/yeswehack/status/1596141663075926017) | **CORS** | Header `Access-Control-Allow` configurato in modo errato
📜[#12](https://twitter.com/yeswehack/status/1598678380072902660) | **CSRF/ClickJacking** | Richiesta GET CSRF con processo di eliminazione non sicuro / ClickJacking - `X-Frame-Options` impostato nel meta tag HTML
📜[#13](https://twitter.com/yeswehack/status/1601230194035105797) | **Path Traversal/Upload di file senza restrizioni** | Scarsa protezione da Path Traversal e upload di file che porta a un code injection
📜[#14](https://twitter.com/yeswehack/status/1603751408678969347) | **DOS** | Gestione errata dell'operatore nel "for loop"
📜[#15](https://twitter.com/yeswehack/status/1606288516744347648) | **Meccanismo debole di recupero della password dimenticata** | Hash debole per il recupero della password
📜[#16](https://twitter.com/yeswehack/status/1608822361419321350) | **IDOR** | Un'istruzione if non sicura porta a un controllo degli accessi improprio
📜[#17](https://twitter.com/yeswehack/status/1611361951644368898) | **Deserializzazione non sicura** | Esegue input utente considerato attendibile all'interno della funzione pickle `loads()`
📜[#18](https://twitter.com/yeswehack/status/1614985966178996225) | **Path Traversal** | Validazione impropria del nome del file da parte dell'utente
📜[#19](https://twitter.com/yeswehack/status/1616435388507201536) | **Open Redirect** | Gestione non valida dell'input controllato dall'utente "*location.hash*"
📜[#20](https://twitter.com/yeswehack/status/1618972101943107584) | **SQL injection** | Uso non valido della funzione `replace()`, il carattere viene sostituito una sola volta
📜[#21](https://twitter.com/yeswehack/status/1621508813177212930) | **PostMessage DOM XSS** | Nessuna validazione dell'origine, che porta a PostMessage DOM XSS
📜[#22](https://twitter.com/yeswehack/status/1626582253215318016) | **XSS/OpenRedirect** | La protezione tramite filtro non filtra tutti i caratteri speciali che possono essere usati per sfruttare le vulnerabilità
📜[#23](https://twitter.com/yeswehack/status/1631655669244784640) | **Buffer overflow** | Prende l'input STDIN dell'utente con la funzione `gets()` senza controllare la dimensione del buffer
📜[#24](https://twitter.com/yeswehack/status/1636725322447220739) | **SQL injection** | Uso errato della funzione PHP `addslashes()`
📜[#25](https://twitter.com/yeswehack/status/1639253229203599361) | **XSS - bypass CSP** | Nessuna validazione dell'input utente e gestione non sicura del nonce
📜[#26](https://twitter.com/yeswehack/status/1641776354315190272) | **Path Traversal** | Il filtro fornito dalla funzione PHP "preg_replace()" è limitato a filtrare solo i primi 10 caratteri
📜[#27](https://twitter.com/yeswehack/status/1646854408196456448) | **Web Cache Poisoning** | L'header HTTP `Referer` viene riflesso nel corpo della risposta in cache senza essere filtrato
📜[#28](https://twitter.com/yeswehack/status/1649394393374248963) | **Vulnerabilità di logica di business** | Un attaccante può prelevare importi negativi per aumentare il saldo complessivo del proprio account
📜[#29](https://twitter.com/yeswehack/status/1651933932198285314) | **IDOR** | Un attaccante può ottenere l'accesso a dati sensibili di altri utenti effettuando un attacco di *Forced browsing*
📜[#30](https://twitter.com/yeswehack/status/1654465424560365568) | **Deserializzazione non sicura** | Uso di una funzione pericolosa (`exec`) che può essere controllata dall'utente, risultando in un RCE
📜[#31](https://twitter.com/yeswehack/status/1659568814609117185) | **LFI** | Nessun corretto escaping dei caratteri o verifica del filtro. La funzione `include()` esegue tutto il codice PHP nel file indicato, indipendentemente dall'estensione del file, risultando in un code injection
📜[#32](https://twitter.com/yeswehack/status/1669693673846591488) | **Format injection!** | Formatta una stringa contenente valori forniti dal client, risultando in una format injection
📜[#33](https://twitter.com/yeswehack/status/1678378536015372288) | **SQL injection (second order)** | Tutte le query SQL usano prepared statement tranne l'ultima. Questa istruzione estrae dal database un valore che era stato controllato dall'utente e lo aggiunge alla query SQL, portando a un SQL injection (second order)
📜[#34](https://twitter.com/yeswehack/status/1680877622685843456) | **Regular expression Denial of Service (ReDoS)** | Pattern regex configurato male usato per filtrare l'input controllato dall'utente
📜[#35](https://twitter.com/yeswehack/status/1691057079996350464) | **XSS** | Input utente considerato attendibile nel parametro GET
📜[#36](https://twitter.com/yeswehack/status/1696130513038418312) | **Upload di file senza restrizioni** | Validazione insufficiente dell'estensione del file caricato e mancata validazione del contenuto del file
📜[#37](https://twitter.com/yeswehack/status/1705190707768479828) | **SSRF** | Gestione non sicura dell'header proxy `X-Forwarded-Host` e di cURL che portano a una SSRF completa
📜[#38](https://twitter.com/yeswehack/status/1709124683377885530) | **Code injection** | L'utente può scrivere contenuti personalizzati in un file selezionato che viene poi eseguito sul sistema vulnerabile
📜[#39](https://twitter.com/yeswehack/status/1717202895701954626) | **LFI** | Lo sfruttamento di una LFI rende possibile eseguire lo strumento *pearcmd*, risultando in una remote code execution
📜[#40](https://twitter.com/yeswehack/status/1745074482522243552) | **Upload di file senza restrizioni** | L'estensione `php3` può essere usata per eseguire codice PHP a causa della configurazione nel proxy Apache.
📜[#41](https://twitter.com/yeswehack) | **Command injection** | L'uso non valido di escapeshellcmd porta a una vulnerabilità di command injection
📜[#42](https://x.com/yeswehack/status/1801619463097274624) | **Command injection** | Non viene eseguita alcuna validazione dell'input utente, portando a una vulnerabilità di command injection
📜[#43](https://x.com/yeswehack/status/1775179767412593021) | **SSTI** | Uso improprio del template engine che porta a una SSTI e di conseguenza a un RCE
## Vulnerabilità
- [Controllo degli accessi non corretto](https://owasp.org/www-community/Broken_Access_Control) - CWE-284
- [Code injection](https://owasp.org/www-community/attacks/Code_Injection) - CWE-94
- [Cross Site Request Forgery (CSRF)](https://owasp.org/www-community/attacks/csrf) - CWE-352
- [SQL injection (SQLi)](https://owasp.org/www-community/attacks/SQL_Injection) - CWE-89
- [Cross Site Scripting (XSS)](https://owasp.org/www-community/attacks/xss/) - CWE-79
- [Open Redirect](https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html) - CWE-601
- [Server-side template injection (SSTI)](https://owasp.org/www-project-web-security-testing-guide/v41/4-Web_Application_Security_Testing/07-Input_Validation_Testing/18-Testing_for_Server_Side_Template_Injection) - CWE-1336
- [Server Side Request Forgery (SSRF)](https://owasp.org/www-community/attacks/Server_Side_Request_Forgery) - CWE-918
- [Cross Origin Resource Sharing (CORS)](https://owasp.org/www-community/attacks/CORS_OriginHeaderScrutiny) - CWE-942
- [Clickjacking](https://owasp.org/www-community/attacks/Clickjacking) - CWE-1021
- [Upload di file senza restrizioni](https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload) - CWE-434
- [Path Traversal](https://owasp.org/www-community/attacks/Path_Traversal) - CWE-35
- [Denial Of Service](https://owasp.org/www-community/attacks/Denial_of_Service) - CWE-400
- [Meccanismo debole di recupero per la password dimenticata](https://cwe.mitre.org/data/definitions/640.html) - CWE-640
- [Insecure Direct Object Reference (IDOR)](https://cwe.mitre.org/data/definitions/639.html) - CWE-639
- [Deserializzazione di dati non attendibili](https://owasp.org/www-community/vulnerabilities/Deserialization_of_untrusted_data) - CWE-502
- [Local File Inclusion](https://cwe.mitre.org/data/definitions/98.html) - CWE-98
- [Buffer Overflow](https://cwe.mitre.org/data/definitions/120.html) - CWE-120
- [Accettazione di dati esterni non attendibili con dati attendibili ("Cache Poisoning")](https://cwe.mitre.org/data/definitions/349.html) - CWE-349
- [Errori di logica di business](https://cwe.mitre.org/data/definitions/840.html) - CWE-840
- [Format injection](https://cwe.mitre.org/data/definitions/134.html) - CWE-134
- [Command injection](https://cwe.mitre.org/data/definitions/77) - CWE-77
## Linguaggi di programmazione
- [PHP](https://www.php.net/)
- [Python](https://www.python.org/)
- [Golang](https://go.dev/)
- [Java](https://www.java.com/)
- [JavaScript](https://www.javascript.com/)
- [C](https://en.wikipedia.org/wiki/C_(programming_language))
__Sono inclusi anche__
- SQL ([MySQL](https://www.mysql.com/))
- HTML
- CSS
---
## Esegui uno snippet di codice vulnerabile
In ogni cartella dello snippet di codice vulnerabile (Vsnippet) c'è un file `docker-compose.yml`. Per avviare un Vsnippet in un ambiente docker isolato, esegui semplicemente il seguente comando:
```
docker compose up --build
```
oppure
```
docker-compose up --build
```
## Installazione
```bash
git clone https://github.com/yeswehack/vulnerable-code-snippets.git
```
## Aggiornamento
Per ottenere gli ultimi snippet di codice vulnerabili, esegui:
```bash
git pull
```
~ **H4i già tr0v4t0 l'u0v0 di P4squ4?** 🐇🪺
Per domande, assistenza o se hai scoperto un problema con il codice. Contattaci su Twitter: [@yeswehack](https://twitter.com/yeswehack) 📬