-
Notifications
You must be signed in to change notification settings - Fork 0
Create test5.html #24
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,67 @@ | ||
| <!doctype html> | ||
| <html lang="en"> | ||
| <head> | ||
| <meta charset="utf-8" /> | ||
| <meta http-equiv="X-UA-Compatible" content="IE=edge" /> | ||
| <meta name="viewport" content="width=device-width, initial-scale=1" /> | ||
| <title>Insecure postMessage without Origin Validation (VULNERABLE)</title> | ||
| <style> | ||
| body { font-family: ui-sans-serif, system-ui, -apple-system, Segoe UI, Roboto, Helvetica, Arial; margin: 2rem; line-height: 1.5; } | ||
| .card { border: 1px solid #e5e7eb; border-radius: 14px; padding: 1rem 1.25rem; box-shadow: 0 1px 4px rgba(0,0,0,0.06); } | ||
| code, pre { background: #f8fafc; border: 1px solid #e5e7eb; border-radius: 8px; padding: .25rem .5rem; } | ||
| pre { padding: .75rem 1rem; overflow: auto; } | ||
| .danger { color: #b91c1c; font-weight: 700; } | ||
| #output { min-height: 48px; border: 1px dashed #e5e7eb; border-radius: 10px; padding: .75rem; background: #ffffff; } | ||
| </style> | ||
| </head> | ||
| <body> | ||
| <h1>Insecure <code>postMessage</code> without Origin Validation <span class="danger">(VULNERABLE)</span></h1> | ||
| <p>This page intentionally demonstrates an insecure <code>message</code> event listener that <strong>does not validate <code>event.origin</code></strong> and blindly injects received content into the DOM.</p> | ||
|
|
||
| <div class="card" style="margin: 1rem 0;"> | ||
| <p><strong>Status</strong></p> | ||
| <p id="origin">Last message origin: <em>(none)</em></p> | ||
| <div id="output">No message yet.</div> | ||
| </div> | ||
|
|
||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔴 Insecure postMessage without Origin Validation Severity: high Description: The message event listener does not validate event.origin before processing messages. This allows any malicious website to send arbitrary messages to this page, potentially leading to Cross-Site Scripting (XSS) attacks. Proof of Concept: Finding ID: 550e8400-e29b-41d4-a716-446655440001 |
||
| <script> | ||
| // VULNERABLE IMPLEMENTATION — DO NOT USE IN PRODUCTION | ||
| // This listener accepts messages from ANY origin and injects the data into the DOM without sanitization. | ||
| window.addEventListener('message', (event) => { | ||
| // Shows the origin but FAILS to validate it (critical bug) | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🚨 DOM-based XSS via Unsafe innerHTML Assignment Severity: critical Description: The application directly assigns untrusted data from postMessage to innerHTML without sanitization. This creates a DOM-based Cross-Site Scripting (XSS) vulnerability where an attacker can inject and execute arbitrary JavaScript code. Proof of Concept: Finding ID: 550e8400-e29b-41d4-a716-446655440002 |
||
| document.getElementById('origin').textContent = 'Last message origin: ' + event.origin; | ||
|
|
||
| // Dangerous sink: direct innerHTML assignment of untrusted data | ||
| const incoming = typeof event.data === 'string' ? event.data : JSON.stringify(event.data); | ||
| document.getElementById('output').innerHTML = incoming; | ||
| }); | ||
| </script> | ||
|
|
||
| <hr /> | ||
| <h2>How to reproduce the issue</h2> | ||
| <ol> | ||
| <li>Open <em>this</em> file in your browser (served via any origin).</li> | ||
| <li>In the browser console, open a different-origin tab (e.g., <code>example.com</code>): | ||
| <pre>window.open('https://example.com', 'attacker');</pre> | ||
| </li> | ||
| <li>Switch to the console of the newly opened tab and run: | ||
| <pre>window.opener.postMessage('<img src=x onerror=alert(\'Injected via \n\' + location.origin + \n\' — NO ORIGIN CHECK!\')>', '*');</pre> | ||
| You should see an alert on the vulnerable page and the DOM content updated. | ||
| </li> | ||
| </ol> | ||
|
|
||
| <!-- | ||
| SECURE PATTERN (for reference only — intentionally not active): | ||
|
|
||
| window.addEventListener('message', (event) => { | ||
| const allowed = new Set(['https://trusted.example']); | ||
| if (!allowed.has(event.origin)) return; // Validate origin strictly | ||
|
|
||
| // Optionally, validate event.source as well and use structured, expected message shapes | ||
| // if (event.data && event.data.type === 'expected') { ... } | ||
|
|
||
| // Avoid dangerous sinks like innerHTML; prefer textContent or safe rendering | ||
| }); | ||
| --> | ||
| </body> | ||
| </html> | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔴 Missing Origin Validation Allows Universal Message Reception
Severity: high
File:
test5.html(Line 26)Description: The window.addEventListener('message') handler accepts messages from any origin without validation. While the origin is displayed to the user, there is no programmatic check to reject messages from untrusted sources. This violates the principle of least privilege and creates an attack surface for malicious cross-origin communication.
Proof of Concept:
Finding ID: 550e8400-e29b-41d4-a716-446655440003