Attack Walkthroughs
Attack 1: SQL Injection
Vulnerability: CWE-89 - Improper Neutralization of Special Elements in SQL Command
Endpoint: POST /rest/user/login
Payload:
{"email": "' OR 1=1--", "password": "anything"}
Attack Chain:
- Attacker crafts JSON payload with SQL metacharacters
- Payload sent to login endpoint without sanitization
- Single quote breaks out of SQL string literal
OR 1=1creates a tautology (always true condition)- Double dashes comment out password verification
- Backend returns first user in database with valid JWT token
Result: ✅ Authentication bypass - JWT token obtained without credentials
Evidence: HTTP Stream capture showing payload and JWT response in Wireshark
Attack 2: Path Traversal
Vulnerability: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory
Endpoint: GET /ftp/{path}
Filter Mechanism: Application strips ../ sequences (naive regex)
Attack Progression:
- Baseline (Legitimate):