8000 test: default to HTTP/1.1 protocol version for all tests instead of HTTP/1.0 by daum3ns · Pull Request #4043 · coreruleset/coreruleset · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

test: default to HTTP/1.1 protocol version for all tests instead of HTTP/1.0 #4043

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
10000
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -96,7 +96,7 @@ tests:
method: DELETE
port: 80
uri: "/delete"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [911100]
Expand All @@ -116,7 +116,7 @@ tests:
method: FOO
port: 80
uri: "/foo"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [911100]
Expand All @@ -136,7 +136,7 @@ tests:
method: SUBSCRIBE
port: 80
uri: "/subscribe"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [911100]
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ tests:
method: GET
port: 80
uri: "/get"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [913100]
Expand All @@ -39,7 +39,7 @@ tests:
method: GET
port: 80
uri: "/get"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [913100]
Expand All @@ -59,7 +59,7 @@ tests:
method: GET
port: 80
uri: "/get"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [913100]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -231,7 +231,7 @@ tests:
method: '|GET'
port: 80
uri: "/get"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [920100]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -74,7 +74,7 @@ tests:
method: POST
port: 80
uri: /post
version: HTTP/1.0
version: HTTP/1.1
data: abc
output:
status: 200
Expand All @@ -97,7 +97,7 @@ tests:
method: POST
port: 80
uri: /
version: HTTP/1.0
version: HTTP/1.1
data: abc
output:
status: 400
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,7 @@ tests:
method: POST
port: 80
uri: /
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [920180]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ tests:
dest_addr: "127.0.0.1"
port: 80
uri: "/get?param=foo%uFF01"
version: "HTTP/1.0"
version: "HTTP/1.1"
headers:
User-Agent: "OWASP CRS test agent"
Host: "localhost"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ tests:
- input:
dest_addr: "127.0.0.1"
port: 80
# To test an empty Host: header we must use HTTP/1.0 version
version: "HTTP/1.0"
headers:
User-Agent: "OWASP CRS test agent"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ tests:
method: GET
port: 80
uri: "/"
version: HTTP/1.0
version: HTTP/1.1
data: ''
output:
log:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ tests:
method: GET
port: 80
uri: "/?11111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111=foo"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [920360]
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ tests:
method: GET
port: 80
uri: /?foo=11111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [920370]
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ tests:
method: GET
port: 80
uri: /?param1=1&param2=1&param3=1&param4=1&param5=1&param6=1&param7=1&param8=1&param9=1&param10=1&param11=1&param12=1&param13=1&param14=1&param15=1&param16=1&param17=1&param18=1&param19=1&param20=1&param21=1&param22=1&param23=1&param24=1&param25=1&param26=1&param27=1&param28=1&param29=1&param30=1&param31=1&param32=1&param33=1&param34=1&param35=1&param36=1&param37=1&param38=1&param39=1&param40=1&param41=1&param42=1&param43=1&param44=1&param45=1&param46=1&param47=1&param48=1&param49=1&param50=1&param51=1&param52=1&param53=1&param54=1&param55=1&param56=1&param57=1&param58=1&param59=1&param60=1&param61=1&param62=1&param63=1&param64=1&param65=1&param66=1&param67=1&param68=1&param69=1&param70=1&param71=1&param72=1&param73=1&param74=1&param75=1&param76=1&param77=1&param78=1&param79=1&param80=1&param81=1&param82=1&param83=1&param84=1&param85=1&param86=1&param87=1&param88=1&param89=1&param90=1&param91=1&param92=1&param93=1&param94=1&param95=1&param96=1&param97=1&param98=1&param99=1&param100=1&param101=1&param102=1&param103=1&param104=1&param105=1&param106=1&param107=1&param108=1&param109=1&param110=1&param111=1&param112=1&param113=1&param114=1&param115=1&param116=1&param117=1&param118=1&param119=1&param120=1&param121=1&param122=1&param123=1&param124=1&param125=1&param126=1&param127=1&param128=1&param129=1&param130=1&param131=1&param132=1&param133=1&param134=1&param135=1&param136=1&param137=1&param138=1&param139=1&param140=1&param141=1&param142=1&param143=1&param144=1&param145=1&param146=1&param147=1&param148=1&param149=1&param150=1&param151=1&param152=1&param153=1&param154=1&param155=1&param156=1&param157=1&param158=1&param159=1&param160=1&param161=1&param162=1&param163=1&param164=1&param165=1&param166=1&param167=1&param168=1&param169=1&param170=1&param171=1&param172=1&param173=1&param174=1&param175=1&param176=1&param177=1&param178=1&param179=1&param180=1&param181=1&param182=1&param183=1&param184=1&param185=1&param186=1&param187=1&param188=1&param189=1&param190=1&param191=1&param192=1&param193=1&param194=1&param195=1&param196=1&param197=1&param198=1&param199=1&param200=1&param201=1&param202=1&param203=1&param204=1&param205=1&param206=1&param207=1&param208=1&param209=1&param210=1&param211=1&param212=1&param213=1&param214=1&param215=1&param216=1&param217=1&param218=1&param219=1&param220=1&param221=1&param222=1&param223=1&param224=1&param225=1&param226=1&param227=1&param228=1&param229=1&param230=1&param231=1&param232=1&param233=1&param234=1&param235=1&param236=1&param237=1&param238=1&param239=1&param240=1&param241=1&param242=1&param243=1&param244=1&param245=1&param246=1&param247=1&param248=1&param249=1&param250=1&param251=1&param252=1&param253=1&param254=1&param255=1&param256=1
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [920380]
Original file line number Diff line number Diff line change
Expand Up @@ -313,7 +313,7 @@ tests:
method: GET
port: 80
uri: "/"
version: HTTP/1.0
version: HTTP/1.1
data: "{\"foo\" : \";+cat+/e\\\\t\\\\*/pa\\\\?s\\\\wd\"}"
output:
log:
Expand All @@ -331,7 +331,7 @@ tests:
method: GET
port: 80
uri: "/"
version: HTTP/1.0
version: HTTP/1.1
data: "{\"foo\" : \";+cat+/e\\\\t\\\\*/pa\\\\?s\\\\wd\"}"
output:
log:
Expand All @@ -349,7 +349,7 @@ tests:
method: GET
port: 80
uri: "/"
version: HTTP/1.0
version: HTTP/1.1
data: "{\"foo\" : \";+cat+/e\\\\t\\\\*/pa\\\\?s\\\\wd\"}"
output:
log:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ tests:
- input:
dest_addr: "127.0.0.1"
port: 80
version: "HTTP/1.0"
version: "HTTP/1.1"
headers:
User-Agent: "OWASP CRS test agent"
Host: "localhost"
Expand Down
14 changes: 7 additions & 7 deletions tests/regression/tests/REQUEST-921-PROTOCOL-ATTACK/921110.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,8 @@ tests:
method: POST
port: 80
uri: "/"
data: "var=%0aPOST / HTTP/1.0"
version: HTTP/1.0
data: "var=%0aPOST / HTTP/1.1"
version: HTTP/1.1
output:
log:
expect_ids: [921110]
Expand All @@ -35,7 +35,7 @@ tests:
port: 80
uri: "/"
data: "var=aaa%0aGET+/+HTTP/1.1"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [921110]
Expand All @@ -53,12 +53,12 @@ tests:
port: 80
uri: "/"
data: "var=aaa%0dHEAD+http://example.com/+HTTP/1.1"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [921110]
- test_id: 4
desc: "HTTP Response Splitting - pre-HTTP/1.0"
desc: "HTTP Response Splitting - pre-HTTP/1.1"
stages:
- input:
dest_addr: 127.0.0.1
Expand All @@ -71,7 +71,7 @@ tests:
port: 80
uri: "/"
data: "var=aaa%0d%0aGet+/foo%0d"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
no_expect_ids: [921110]
Expand All @@ -89,7 +89,7 @@ tests:
port: 80
uri: "/"
data: "var=aaa%0d%0aGet+foo+bar"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
no_expect_ids: [921110]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ tests:
Accept: "*/*"
method: GET
uri: "/get?parameter%0d%0a=test"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [921150]
Original file line number Diff line number Diff line change
Expand Up @@ -113,7 +113,7 @@ tests:
port: 80
uri: "/post"
data: "var=0.84622338492032948`echo${IFS}crs312``echo${IFS}34test`"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [932130]
Expand All @@ -130,7 +130,7 @@ tests:
port: 80
# cat /etc/pa[s]swd
uri: "/get?cmd=cat%20/etc/pa%5Bs%5Dswd"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [932130]
Expand All @@ -147,7 +147,7 @@ tests:
port: 80
# cat /[?]tc/pa[?]swd
uri: "/get?cmd=cat%20/%5B%3F%5Dtc/pa%5B%3F%5Dswd"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [932130]
Expand All @@ -164,7 +164,7 @@ tests:
port: 80
# hello [text in brackets]
uri: "/get?cmd=hello%20%5Btext%20in%20brackets%5D"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
no_expect_ids: [932130]
Expand All @@ -180,7 +180,7 @@ tests:
method: GET
port: 80
uri: "/get?s=/etc/pas[s]wd"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [932130]
Expand All @@ -196,7 +196,7 @@ tests:
method: GET
port: 80
uri: "/get?s=/etc/%5Bp%5Dasswd"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [932130]
Expand All @@ -212,7 +212,7 @@ tests:
method: GET
port: 80
uri: "/get?s=/etc/%5B!q%5Dasswd"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [932130]
Expand All @@ -228,7 +228,7 @@ tests:
method: GET
port: 80
uri: "/get?s=/etc/%5Bm-z%5Dasswd"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [932130]
Expand All @@ -244,7 +244,7 @@ tests:
method: GET
port: 80
uri: "/get?s=/usr/bin/%5Bu%5Dname+-a"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [932130]
Expand All @@ -260,7 +260,7 @@ tests:
method: GET
port: 80
uri: "/get?exec=/bi%5Bn%5D/bash"
version: HTTP/1.0
version: HTTP/1.1
output:
log:
expect_ids: [932130]
Expand Down
Loading
0