Faith Olajide

Cybersecurity & IT Support Specialist

View on GitHub

Attack Walkthroughs

Attack 1: SQL Injection

Vulnerability: CWE-89 - Improper Neutralization of Special Elements in SQL Command

Endpoint: POST /rest/user/login

Payload:

{"email": "' OR 1=1--", "password": "anything"}

Attack Chain:

  1. Attacker crafts JSON payload with SQL metacharacters
  2. Payload sent to login endpoint without sanitization
  3. Single quote breaks out of SQL string literal
  4. OR 1=1 creates a tautology (always true condition)
  5. Double dashes comment out password verification
  6. Backend returns first user in database with valid JWT token

Result: ✅ Authentication bypass - JWT token obtained without credentials

Evidence: HTTP Stream capture showing payload and JWT response in Wireshark


Attack 2: Path Traversal

Vulnerability: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory

Endpoint: GET /ftp/{path}

Filter Mechanism: Application strips ../ sequences (naive regex)

Attack Progression:

  1. Baseline (Legitimate):