From 1f59d2b2a8320327814b33b635eca21e2545dc1e Mon Sep 17 00:00:00 2001 From: dune73 Date: Tue, 7 Nov 2023 10:21:24 +0100 Subject: [PATCH 1/2] feat: new isolated test 934170-3 (934170 PL1) (Christian Folini) --- .../934170.yaml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/tests/regression/tests/REQUEST-934-APPLICATION-ATTACK-GENERIC/934170.yaml b/tests/regression/tests/REQUEST-934-APPLICATION-ATTACK-GENERIC/934170.yaml index 6bfb8accb..ab0cd607b 100644 --- a/tests/regression/tests/REQUEST-934-APPLICATION-ATTACK-GENERIC/934170.yaml +++ b/tests/regression/tests/REQUEST-934-APPLICATION-ATTACK-GENERIC/934170.yaml @@ -39,3 +39,20 @@ tests: uri: "/get?ssrf=data://text/plain;base64,SSBsb3ZlIFBIUAo=" output: no_log_contains: id "934170" + - test_title: 934170-3 + desc: "SSRF - data: scheme test - simple trigger, isolated test" + stages: + - stage: + input: + dest_addr: "127.0.0.1" + port: 80 + headers: + Host: "localhost" + User-Agent: "ModSecurity CRS 3 Tests" + Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 + Accept-Encoding: gzip,deflate + Accept-Language: en-us,en;q=0.5 + method: GET + uri: "/get?ssrf=data:text/plain" + output: + log_contains: id "934170" From ac53ad2a22a064de4c1991a70ddce7e42fecfde2 Mon Sep 17 00:00:00 2001 From: dune73 Date: Tue, 7 Nov 2023 10:55:50 +0100 Subject: [PATCH 2/2] Adding prefix for test description --- .../tests/REQUEST-934-APPLICATION-ATTACK-GENERIC/934170.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/regression/tests/REQUEST-934-APPLICATION-ATTACK-GENERIC/934170.yaml b/tests/regression/tests/REQUEST-934-APPLICATION-ATTACK-GENERIC/934170.yaml index ab0cd607b..35a1941e6 100644 --- a/tests/regression/tests/REQUEST-934-APPLICATION-ATTACK-GENERIC/934170.yaml +++ b/tests/regression/tests/REQUEST-934-APPLICATION-ATTACK-GENERIC/934170.yaml @@ -40,7 +40,7 @@ tests: output: no_log_contains: id "934170" - test_title: 934170-3 - desc: "SSRF - data: scheme test - simple trigger, isolated test" + desc: "Status Page Test - SSRF - data: scheme test - simple trigger, isolated test" stages: - stage: input: