microsoft/restler-fuzzer

URL Parameters Missing Space Encodings

Aperta

#495 aperta il 22 mar 2022

 (1 commento) (0 reazioni) (0 assegnatari)Python (329 fork)auto 404
bughelp wanted

Metriche repository

Star
 (2929 stelle)
Metriche merge PR
 (Metriche PR in attesa)

Descrizione

URL parameters which contain a space in the value do not get the usual URL encoding (ex. " " becomes "+" or "%20"). This results in malformed HTTP/1.1 requests. For example, if my yaml specification has a type like:

    network:
      name: network
      in: query
      required: true
      schema:
        type: string
        enum:
          - "Internal"
          - "External Users"
          - "External Networks"

then the following GET requests will be created:

GET /config?network=Internal HTTP/1.1
GET /config?network=External Users HTTP/1.1
GET /config?network=External Networks HTTP/1.1

This doesn't get recognized properly and leads to erroneous fuzzing cases for parameters which are supposed to contain a space in them.

Guida contributor