|
| 1 | +package aspnet_test |
| 2 | + |
| 3 | +import ( |
| 4 | + "testing" |
| 5 | + |
| 6 | + "github.com/vulncheck-oss/go-exploit/aspnet" |
| 7 | +) |
| 8 | + |
| 9 | +var pageState1 = `<!DOCTYPE html> |
| 10 | +<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> |
| 11 | +<head><meta http-equiv="X-UA-Compatible" content="IE=9" /><meta http-equiv="Page-Enter" content="Alpha(opacity=100)" /><title> |
| 12 | + Gladinet Cloud Cluster |
| 13 | +</title> |
| 14 | +<body style="overflow:hidden;"> |
| 15 | + <form name="aspnetForm" method="post" action="./admindatabase.aspx" id="aspnetForm"> |
| 16 | +<div> |
| 17 | +<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" /> |
| 18 | +<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" /> |
| 19 | +<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" /> |
| 20 | +<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTE4OTcxMDA5NzIPZBYCZg9kFgQCAw8WAh4EVGV4dGVkAgUPZBYIAgYPZBYCAjsPEGQPFgRmAgECAgIDFgQQBRREZWZhdWx0IC0gYWxsIGluIG9uZQUHZGVmYXVsdGcQBQZNeSBTcWwFBW15c3FsZxAFClNRTCBTZXJ2ZXIFA3NxbGcQBQpQb3N0Z3JlU1FMBQRwc3FsZxYBZmQCCA8PFgIeC05hdmlnYXRlVXJsBSVodHRwOi8vd3d3LmdsYWRpbmV0LmNvbS9wL2NvbnRhY3QuaHRtZGQCCQ8PFgIfAQUjaHR0cDovL3d3dy5nbGFkaW5ldC5jb20vcC90ZXJtcy5odG1kZAIKDw8WAh8BBSVodHRwOi8vd3d3LmdsYWRpbmV0LmNvbS9wL3ByaXZhY3kuaHRtZGRkhIVOv1laSf4FVfKCihTCvPyajtM=" /> |
| 21 | +</div> |
| 22 | +<div> |
| 23 | + <input type="hidden" name="__VIEWSTATEGENERATOR" id="__VIEWSTATEGENERATOR" value="C73717A7" /> |
| 24 | + <input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="/wEdAAdexv6/qKqWdd7V9UzkVbKnzivrZbTfl5HxflMl0WEimkj+n3ntyqDMPWej+FjsRo61P6Uqwq7GZ15buFg7WHqF4VZwC+5O3u0TMTTYeToUrXDySQQEwxvyin+PIQ6Xt1JpqJ+bt/0dmbPhJrKioUwF82Mylv8B1bqOz6F0llEnG94eilk=" /> |
| 25 | +</div> |
| 26 | +</body> |
| 27 | +</html>` |
| 28 | + |
| 29 | +var pageState2 = `<!DOCTYPE html> |
| 30 | +<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> |
| 31 | +<head><meta http-equiv="X-UA-Compatible" content="IE=9" /><meta http-equiv="Page-Enter" content="Alpha(opacity=100)" /><title> |
| 32 | + Gladinet Cloud Cluster |
| 33 | +</title> |
| 34 | +<body style="overflow:hidden;"> |
| 35 | + <form name="aspnetForm" method="post" action="./admindatabase.aspx" id="aspnetForm"> |
| 36 | +<div> |
| 37 | +<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" /> |
| 38 | +<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" /> |
| 39 | +<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" /> |
| 40 | +<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTE4OTcxMDA5NzIPZBYCZg9kFgQCAw8WAh4EVGV4dGVkAgUPZBYIAgYPZBYGAjsPEGQPFgRmAgECAgIDFgQQBRREZWZhdWx0IC0gYWxsIGluIG9uZQUHZGVmYXVsdGcQBQZNeSBTcWwFBW15c3FsZxAFClNRTCBTZXJ2ZXIFA3NxbGcQBQpQb3N0Z3JlU1FMBQRwc3FsZxYBAgNkAj0PDxYCHgdWaXNpYmxlaGRkAkUPDxYCHwFnZGQCCA8PFgIeC05hdmlnYXRlVXJsBSVodHRwOi8vd3d3LmdsYWRpbmV0LmNvbS9wL2NvbnRhY3QuaHRtZGQCCQ8PFgIfAgUjaHR0cDovL3d3dy5nbGFkaW5ldC5jb20vcC90ZXJtcy5odG1kZAIKDw8WAh8CBSVodHRwOi8vd3d3LmdsYWRpbmV0LmNvbS9wL3ByaXZhY3kuaHRtZGQYAQUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFgEFIGN0bDAwJE1haW5Db250ZW50JFBTUUxDaGtTU0xNb2Rlt1OAugQHTFQSO9InFhq1a4zTB6w=" /> |
| 41 | +</div> |
| 42 | +<div> |
| 43 | + <!-- contrived example removes <input type="hidden" name="__VIEWSTATEGENERATOR" id="__VIEWSTATEGENERATOR" value="C73717A7" /> --> |
| 44 | + <input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="/wEdAA1uUUuJru4fqcEgJkMrkl/VzivrZbTfl5HxflMl0WEimkj+n3ntyqDMPWej+FjsRo61P6Uqwq7GZ15buFg7WHqF4VZwC+5O3u0TMTTYeToUrXDySQQEwxvyin+PIQ6Xt1J+6SNjww5M+V+WUpWYV8cEoUTnLwGbguM3r6r03Xnunl50DFJPWsXTExtP5yQn7eqIN4VNCPK0IRBU8qYLZ2Qrlo7dTb8AdCT3V/XWpLNKSntkbVfk8X4Pe7mGcdZvwtNpqJ+bt/0dmbPhJrKioUwF+aS81hLoX5JwP8HKC0ur6/9jlQ8=" /> |
| 45 | +</div> |
| 46 | +</body> |
| 47 | +</html> |
| 48 | +` |
| 49 | + |
| 50 | +func TestState_Full(t *testing.T) { |
| 51 | + state := aspnet.State{} |
| 52 | + p := state.AsParams() |
| 53 | + if len(p) != 0 { |
| 54 | + t.Error("Parameters should not have state currently") |
| 55 | + } |
| 56 | + |
| 57 | + state.Update(pageState1) |
| 58 | + p = state.AsParams() |
| 59 | + if len(p) == 0 { |
| 60 | + t.Error("Parameters should have state currently") |
| 61 | + } |
| 62 | + if len(p) != 6 { |
| 63 | + t.Errorf("First state should only have 6 values: %d - %#v", len(p), p) |
| 64 | + } |
| 65 | + |
| 66 | + value, exists := p["__VIEWSTATE"] |
| 67 | + if !exists { |
| 68 | + t.Error("ViewState should be set on first request state update") |
| 69 | + } |
| 70 | + if value != `/wEPDwULLTE4OTcxMDA5NzIPZBYCZg9kFgQCAw8WAh4EVGV4dGVkAgUPZBYIAgYPZBYCAjsPEGQPFgRmAgECAgIDFgQQBRREZWZhdWx0IC0gYWxsIGluIG9uZQUHZGVmYXVsdGcQBQZNeSBTcWwFBW15c3FsZxAFClNRTCBTZXJ2ZXIFA3NxbGcQBQpQb3N0Z3JlU1FMBQRwc3FsZxYBZmQCCA8PFgIeC05hdmlnYXRlVXJsBSVodHRwOi8vd3d3LmdsYWRpbmV0LmNvbS9wL2NvbnRhY3QuaHRtZGQCCQ8PFgIfAQUjaHR0cDovL3d3dy5nbGFkaW5ldC5jb20vcC90ZXJtcy5odG1kZAIKDw8WAh8BBSVodHRwOi8vd3d3LmdsYWRpbmV0LmNvbS9wL3ByaXZhY3kuaHRtZGRkhIVOv1laSf4FVfKCihTCvPyajtM=` { |
| 71 | + t.Error("ViewState on first update is unexpected") |
| 72 | + } |
| 73 | + |
| 74 | + value, exists = p["__LASTFOCUS"] |
| 75 | + if !exists { |
| 76 | + t.Error("LastFocus should not be nil") |
| 77 | + } |
| 78 | + if value != `` { |
| 79 | + t.Error("LastFocus should be set but is an empty string") |
| 80 | + } |
| 81 | + if state.ViewStateGenerator == nil { |
| 82 | + t.Errorf("ViewStateGenerator should not be nil on first request: %#v", state.ViewStateGenerator) |
| 83 | + } |
| 84 | + |
| 85 | + state.Update(pageState2) |
| 86 | + p = state.AsParams() |
| 87 | + if len(p) == 0 { |
| 88 | + t.Error("Parameters should have state currently at state 2") |
| 89 | + } |
| 90 | + if len(p) != 5 { |
| 91 | + t.Errorf("Second state should only have 5 values: %d - %#v", len(p), p) |
| 92 | + } |
| 93 | + if state.ViewStateGenerator != nil { |
| 94 | + t.Errorf("ViewStateGenerator should be nil on second request: %#v", state.ViewStateGenerator) |
| 95 | + } |
| 96 | + if state.ViewState == nil { |
| 97 | + t.Errorf("ViewState should be not be nil on second request: %#v", state.ViewStateGenerator) |
| 98 | + } |
| 99 | + if *state.ViewState != `/wEPDwULLTE4OTcxMDA5NzIPZBYCZg9kFgQCAw8WAh4EVGV4dGVkAgUPZBYIAgYPZBYGAjsPEGQPFgRmAgECAgIDFgQQBRREZWZhdWx0IC0gYWxsIGluIG9uZQUHZGVmYXVsdGcQBQZNeSBTcWwFBW15c3FsZxAFClNRTCBTZXJ2ZXIFA3NxbGcQBQpQb3N0Z3JlU1FMBQRwc3FsZxYBAgNkAj0PDxYCHgdWaXNpYmxlaGRkAkUPDxYCHwFnZGQCCA8PFgIeC05hdmlnYXRlVXJsBSVodHRwOi8vd3d3LmdsYWRpbmV0LmNvbS9wL2NvbnRhY3QuaHRtZGQCCQ8PFgIfAgUjaHR0cDovL3d3dy5nbGFkaW5ldC5jb20vcC90ZXJtcy5odG1kZAIKDw8WAh8CBSVodHRwOi8vd3d3LmdsYWRpbmV0LmNvbS9wL3ByaXZhY3kuaHRtZGQYAQUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFgEFIGN0bDAwJE1haW5Db250ZW50JFBTUUxDaGtTU0xNb2Rlt1OAugQHTFQSO9InFhq1a4zTB6w=` { |
| 100 | + t.Error("ViewState on second update is unexpected") |
| 101 | + } |
| 102 | +} |
| 103 | + |
| 104 | +func TestState_Each(t *testing.T) { |
| 105 | + state := aspnet.State{} |
| 106 | + p := state.AsParams() |
| 107 | + if len(p) != 0 { |
| 108 | + t.Error("Parameters should not have state currently") |
| 109 | + } |
| 110 | + |
| 111 | + state.Update(pageState1) |
| 112 | + p = state.AsParams() |
| 113 | + if len(p) == 0 { |
| 114 | + t.Error("Parameters should have state currently") |
| 115 | + } |
| 116 | + if len(p) != 6 { |
| 117 | + t.Errorf("First state should only have 6 values: %d - %#v", len(p), p) |
| 118 | + } |
| 119 | + |
| 120 | + value, exists := p["__VIEWSTATE"] |
| 121 | + if !exists { |
| 122 | + t.Error("ViewState should be set on first request state update") |
| 123 | + } |
| 124 | + if value != `/wEPDwULLTE4OTcxMDA5NzIPZBYCZg9kFgQCAw8WAh4EVGV4dGVkAgUPZBYIAgYPZBYCAjsPEGQPFgRmAgECAgIDFgQQBRREZWZhdWx0IC0gYWxsIGluIG9uZQUHZGVmYXVsdGcQBQZNeSBTcWwFBW15c3FsZxAFClNRTCBTZXJ2ZXIFA3NxbGcQBQpQb3N0Z3JlU1FMBQRwc3FsZxYBZmQCCA8PFgIeC05hdmlnYXRlVXJsBSVodHRwOi8vd3d3LmdsYWRpbmV0LmNvbS9wL2NvbnRhY3QuaHRtZGQCCQ8PFgIfAQUjaHR0cDovL3d3dy5nbGFkaW5ldC5jb20vcC90ZXJtcy5odG1kZAIKDw8WAh8BBSVodHRwOi8vd3d3LmdsYWRpbmV0LmNvbS9wL3ByaXZhY3kuaHRtZGRkhIVOv1laSf4FVfKCihTCvPyajtM=` { |
| 125 | + t.Error("ViewState on first update is unexpected") |
| 126 | + } |
| 127 | + |
| 128 | + value, exists = p["__LASTFOCUS"] |
| 129 | + if !exists { |
| 130 | + t.Error("LastFocus should not be nil") |
| 131 | + } |
| 132 | + if value != `` { |
| 133 | + t.Error("LastFocus should be set but is an empty string") |
| 134 | + } |
| 135 | + value, exists = p["__VIEWSTATEGENERATOR"] |
| 136 | + if !exists { |
| 137 | + t.Error("ViewStateGenerator should not be nil") |
| 138 | + } |
| 139 | + if value != `C73717A7` { |
| 140 | + t.Error("ViewStateGenerator on first update is unexpected") |
| 141 | + } |
| 142 | + value, exists = p["__EVENTVALIDATION"] |
| 143 | + if !exists { |
| 144 | + t.Error("EventValidation should not be nil") |
| 145 | + } |
| 146 | + if value != `/wEdAAdexv6/qKqWdd7V9UzkVbKnzivrZbTfl5HxflMl0WEimkj+n3ntyqDMPWej+FjsRo61P6Uqwq7GZ15buFg7WHqF4VZwC+5O3u0TMTTYeToUrXDySQQEwxvyin+PIQ6Xt1JpqJ+bt/0dmbPhJrKioUwF82Mylv8B1bqOz6F0llEnG94eilk=` { |
| 147 | + t.Error("EventValidation on first update is unexpected") |
| 148 | + } |
| 149 | + if state.EventArgument == nil { |
| 150 | + t.Errorf("EventArgument should not be nil on second request: %#v", state.EventArgument) |
| 151 | + } |
| 152 | + if *state.EventArgument != "" { |
| 153 | + t.Errorf("EventArgument should be empty string on second request: %#v", state.EventArgument) |
| 154 | + } |
| 155 | + if state.EventTarget == nil { |
| 156 | + t.Errorf("EventTarget should not be nil on second request: %#v", state.EventTarget) |
| 157 | + } |
| 158 | + if *state.EventTarget != "" { |
| 159 | + t.Errorf("EventTarget should be empty string on second request: %#v", state.EventTarget) |
| 160 | + } |
| 161 | +} |
| 162 | + |
| 163 | +func TestState_Merge(t *testing.T) { |
| 164 | + state := aspnet.State{} |
| 165 | + p := state.AsParams() |
| 166 | + if len(p) != 0 { |
| 167 | + t.Error("Parameters should not have state currently") |
| 168 | + } |
| 169 | + |
| 170 | + state.Update(pageState1) |
| 171 | + p = state.AsParams() |
| 172 | + if len(p) == 0 { |
| 173 | + t.Error("Parameters should have state currently") |
| 174 | + } |
| 175 | + if len(p) != 6 { |
| 176 | + t.Errorf("State should only have 6 values: %d - %#v", len(p), p) |
| 177 | + } |
| 178 | + v := map[string]string{ |
| 179 | + "STUFF": "THINGS", |
| 180 | + } |
| 181 | + merged := state.MergeParams(v) |
| 182 | + if len(merged) != 7 { |
| 183 | + t.Errorf("State should have 7 values: %d - %#v", len(p), p) |
| 184 | + } |
| 185 | +} |
0 commit comments