microsoft/restler-fuzzer

URL Parameters Missing Space Encodings

Ouverte

#495 ouverte le 22 mars 2022

 (1 commentaire) (0 réaction) (0 personne assignée)Python (329 forks)auto 404
bughelp wanted

Métriques du dépôt

Stars
 (2 929 étoiles)
Métriques de merge PR
 (Métriques PR en attente)

Description

URL parameters which contain a space in the value do not get the usual URL encoding (ex. " " becomes "+" or "%20"). This results in malformed HTTP/1.1 requests. For example, if my yaml specification has a type like:

    network:
      name: network
      in: query
      required: true
      schema:
        type: string
        enum:
          - "Internal"
          - "External Users"
          - "External Networks"

then the following GET requests will be created:

GET /config?network=Internal HTTP/1.1
GET /config?network=External Users HTTP/1.1
GET /config?network=External Networks HTTP/1.1

This doesn't get recognized properly and leads to erroneous fuzzing cases for parameters which are supposed to contain a space in them.

Guide contributeur