Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
67 changes: 67 additions & 0 deletions test2.html
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8" />
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<title>Insecure postMessage without Origin Validation (VULNERABLE)</title>
<style>
body { font-family: ui-sans-serif, system-ui, -apple-system, Segoe UI, Roboto, Helvetica, Arial; margin: 2rem; line-height: 1.5; }
.card { border: 1px solid #e5e7eb; border-radius: 14px; padding: 1rem 1.25rem; box-shadow: 0 1px 4px rgba(0,0,0,0.06); }
code, pre { background: #f8fafc; border: 1px solid #e5e7eb; border-radius: 8px; padding: .25rem .5rem; }
pre { padding: .75rem 1rem; overflow: auto; }
.danger { color: #b91c1c; font-weight: 700; }
#output { min-height: 48px; border: 1px dashed #e5e7eb; border-radius: 10px; padding: .75rem; background: #ffffff; }
</style>

Check failure on line 15 in test2.html

View check run for this annotation

Hacktron App (DEV) / Hacktron Security Check

Test Finding 1 - Line Range 10-15

This is a test finding to verify line range support in GitHub annotations. Affected Code: ``` Test code block spanning lines 10-15 ```
Raw output
**Category:** vulnerability
**Severity:** CRITICAL
**File:** test2.html:10-15

**Proof of Concept:**
Test PoC for finding 1

**Finding ID:** a50e8400-e29b-41d4-a716-446655440001
</head>
<body>
<h1>Insecure <code>postMessage</code> without Origin Validation <span class="danger">(VULNERABLE)</span></h1>
<p>This page intentionally demonstrates an insecure <code>message</code> event listener that <strong>does not validate <code>event.origin</code></strong> and blindly injects received content into the DOM.</p>

<div class="card" style="margin: 1rem 0;">
<p><strong>Status</strong></p>
<p id="origin">Last message origin: <em>(none)</em></p>
<div id="output">No message yet.</div>
</div>

Check failure on line 25 in test2.html

View check run for this annotation

Hacktron App (DEV) / Hacktron Security Check

Test Finding 2 - Line Range 20-25

This is test finding 2 to verify line range support. Affected Code: ``` Test code block spanning lines 20-25 ```
Raw output
**Category:** vulnerability
**Severity:** HIGH
**File:** test2.html:20-25

**Proof of Concept:**
Test PoC for finding 2

**Finding ID:** a50e8400-e29b-41d4-a716-446655440002

<script>
// VULNERABLE IMPLEMENTATION — DO NOT USE IN PRODUCTION
// This listener accepts messages from ANY origin and injects the data into the DOM without sanitization.
window.addEventListener('message', (event) => {

Check warning on line 30 in test2.html

View check run for this annotation

Hacktron App (DEV) / Hacktron Security Check

Test Finding 3 - Single Line 30

This is test finding 3 with a single line number. Affected Code: ``` Test code at line 30 ```
Raw output
**Category:** vulnerability
**Severity:** MEDIUM
**File:** test2.html:30

**Proof of Concept:**
Test PoC for finding 3

**Finding ID:** a50e8400-e29b-41d4-a716-446655440003
// Shows the origin but FAILS to validate it (critical bug)
document.getElementById('origin').textContent = 'Last message origin: ' + event.origin;

// Dangerous sink: direct innerHTML assignment of untrusted data
const incoming = typeof event.data === 'string' ? event.data : JSON.stringify(event.data);
document.getElementById('output').innerHTML = incoming;
});
</script>

<hr />
<h2>How to reproduce the issue</h2>
<ol>

Check notice on line 42 in test2.html

View check run for this annotation

Hacktron App (DEV) / Hacktron Security Check

Test Finding 4 - Line Range 35-42

This is test finding 4 with a larger line range. Affected Code: ``` Test code block spanning lines 35-42 ```
Raw output
**Category:** vulnerability
**Severity:** LOW
**File:** test2.html:35-42

**Proof of Concept:**
Test PoC for finding 4

**Finding ID:** a50e8400-e29b-41d4-a716-446655440004
<li>Open <em>this</em> file in your browser (served via any origin).</li>
<li>In the browser console, open a different-origin tab (e.g., <code>example.com</code>):
<pre>window.open('https://example.com', 'attacker');</pre>
</li>
<li>Switch to the console of the newly opened tab and run:
<pre>window.opener.postMessage('&lt;img src=x onerror=alert(\'Injected via \n\' + location.origin + \n\' — NO ORIGIN CHECK!\')&gt;', '*');</pre>
You should see an alert on the vulnerable page and the DOM content updated.
</li>
</ol>

Check notice on line 52 in test2.html

View check run for this annotation

Hacktron App (DEV) / Hacktron Security Check

Test Finding 5 - Line Range 50-52

This is test finding 5 with a small line range. Affected Code: ``` Test code block spanning lines 50-52 ```
Raw output
**Category:** vulnerability
**Severity:** INFO
**File:** test2.html:50-52

**Proof of Concept:**
Test PoC for finding 5

**Finding ID:** a50e8400-e29b-41d4-a716-446655440005
<!--
SECURE PATTERN (for reference only — intentionally not active):

window.addEventListener('message', (event) => {
const allowed = new Set(['https://trusted.example']);
if (!allowed.has(event.origin)) return; // Validate origin strictly

// Optionally, validate event.source as well and use structured, expected message shapes
// if (event.data && event.data.type === 'expected') { ... }

// Avoid dangerous sinks like innerHTML; prefer textContent or safe rendering
});
-->
</body>
</html>