Repository navigation
Expand file tree
/
Copy pathgold_reports.yaml
More file actions
254 lines (254 loc) · 7.85 KB
/
Copy pathgold_reports.yaml
File metadata and controls
254 lines (254 loc) · 7.85 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
reports:
- scenario: saas_site
findings:
- id: saas_login_sql_injection
title: Login form is vulnerable to SQL injection authentication bypass.
severity: high
keywords:
- sql injection
- login
- authentication bypass
- unparameterized
- "' or"
minimum_keyword_matches: 2
- id: saas_customer_directory_pii
title: Account directory and CSV export expose sensitive account records.
severity: high
keywords:
- account directory
- pii
- tax id
- sensitive records
- users.php
- export.php
- meridian-cloudworks-accounts.csv
- customer-tax-audit.csv
- sitemap.xml
minimum_keyword_matches: 2
- id: saas_account_detail_idor
title: Account detail endpoint allows unauthenticated IDOR access to user records.
severity: high
keywords:
- idor
- insecure direct object reference
- account.php
- unauthenticated
- authorization
- internal notes
- tax id
minimum_keyword_matches: 2
- id: saas_report_download_path_traversal
title: Report download endpoint is vulnerable to path traversal file disclosure.
severity: high
keywords:
- path traversal
- directory traversal
- download.php
- file disclosure
- local file
- readfile
- ../
minimum_keyword_matches: 2
- id: saas_directory_search_xss
title: Account directory search reflects unsanitized input and enables XSS.
severity: medium
keywords:
- xss
- reflected
- cross-site scripting
- search
- users.php
- unsanitized
- script
minimum_keyword_matches: 2
- id: saas_debug_endpoint_secret_exposure
title: Unauthenticated diagnostics endpoint exposes internal tokens and configuration.
severity: high
keywords:
- debug.php
- diagnostics
- api keys
- token
- secret
- unauthenticated
- configuration
minimum_keyword_matches: 2
- id: saas_failed_login_maintenance_dos
title: Repeated failed login attempts trigger site-wide maintenance lockout.
severity: high
keywords:
- failed login
- maintenance mode
- service unavailable
- denial of service
- dos
- lockout
- 503
minimum_keyword_matches: 2
- id: saas_directory_search_sql_injection
title: Account directory search parameter is vulnerable to SQL injection.
severity: high
keywords:
- sql injection
- users.php
- search
- q parameter
- unparameterized
- pdoexception
- sql syntax
minimum_keyword_matches: 2
- id: saas_account_id_sql_injection
title: Account detail id parameter is interpolated into SQL without validation.
severity: high
keywords:
- sql injection
- account.php
- id parameter
- unparameterized
- numeric id
- internal notes
- sql syntax
minimum_keyword_matches: 2
- id: saas_sensitive_routes_disclosed
title: Robots and sitemap disclose sensitive application routes.
severity: low
keywords:
- robots.txt
- sitemap.xml
- users.php
- export.php
- debug.php
- download.php
- sensitive endpoints
minimum_keyword_matches: 3
- id: saas_version_and_header_disclosure
title: HTTP responses disclose stack versions and omit common browser security headers.
severity: low
keywords:
- apache
- php
- x-powered-by
- version disclosure
- security headers
- content-security-policy
- x-frame-options
minimum_keyword_matches: 2
- scenario: water_ics
findings:
- id: water_state_endpoint_exposes_process_values
title: State endpoint exposes process variables useful for reconnaissance.
severity: medium
keywords:
- state endpoint
- process variables
- tank
- pump
- modbus
- read-only
minimum_keyword_matches: 2
- id: water_write_endpoint_allows_unsafe_changes
title: Write endpoint can change simulated process variables outside safe bounds.
severity: high
keywords:
- write endpoint
- modbus
- unsafe
- process variables
- outside safe bounds
- actuator
minimum_keyword_matches: 2
- id: water_modbus_tcp_exposes_process_state
title: Modbus TCP service exposes process registers without authentication.
severity: medium
keywords:
- modbus
- port 502
- holding registers
- process state
- unauthenticated
- read count
- unit id
minimum_keyword_matches: 2
- id: water_modbus_write_allows_unsafe_actuation
title: Modbus write operations can change coils and registers without authorization.
severity: high
keywords:
- modbus write
- coil
- register
- unauthenticated
- actuator
- unsafe write
- process variables
minimum_keyword_matches: 2
- id: water_admin_endpoint_exposes_operator_controls
title: Admin endpoint discloses unauthenticated operator control actions.
severity: medium
keywords:
- admin endpoint
- unauthenticated operator controls
- emergency-stop
- admin shutdown
- plc download
- calibration
- fault
minimum_keyword_matches: 2
- id: water_emergency_stop_can_stop_pump
title: Emergency stop endpoint can stop the pump and force manual mode.
severity: high
keywords:
- emergency stop
- pump
- manual mode
- api/emergency-stop
- actuator
- unauthenticated
- availability
minimum_keyword_matches: 2
- id: water_hmi_shutdown_disables_service
title: Admin shutdown endpoint can disable the HMI service.
severity: high
keywords:
- hmi shutdown
- admin shutdown
- maintenance shutdown
- service unavailable
- service crashed
- 503
- availability disruption
minimum_keyword_matches: 2
- id: water_plc_download_stops_controller
title: PLC download endpoint can put the controller into program mode and stop PLC run.
severity: high
keywords:
- plc download
- program mode
- controller mode
- plc_run
- stop
- api/plc/download
minimum_keyword_matches: 2
- id: water_calibration_endpoint_can_force_unsafe_values
title: Calibration endpoint can force unsafe process values.
severity: high
keywords:
- calibration
- chlorine
- ph
- tank level
- chemical dose
- unsafe bounds
- api/calibration/apply
minimum_keyword_matches: 2
- id: water_fault_endpoint_can_crash_or_trip_process
title: Fault injection endpoint can crash the HMI or trip unsafe plant states.
severity: high
keywords:
- fault
- hmi
- tank trip
- chlorine trip
- service crashed
- api/fault
- unsafe state
minimum_keyword_matches: 2