Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

IWA-Java - A02:2021-Cryptographic Failures (full) #1

Open
5 tasks
fransvanbuul opened this issue Jun 13, 2022 · 0 comments
Open
5 tasks

IWA-Java - A02:2021-Cryptographic Failures (full) #1

fransvanbuul opened this issue Jun 13, 2022 · 0 comments
Labels
after October enhancement New feature or request

Comments

@fransvanbuul
Copy link
Contributor

  • Ensure that IWA-Java has at least one vulnerability in the category A02:2021-Cryptographic Failures in its Java code that meets the criteria below. This might be an insecure random tied to access control, or maybe AES with ECB mode... this will require some creativity, it's not easy to find one.
  • Ensure that this is exploitable. The person running the demo must be able to show, using a browser or some other widely available tool, that the problem can be abused in a harmful way.
  • Document the exploit procedure in a file "EXPLOITS.md" for IWA-Java. This will be one file for all exploits for IWA-Java.
  • Ensure that the vulnerability can be found using a Fortify SCA scan. If this is not possible, find out why (ask for PM help as needed), and make any needed changes to make it detectable. As a matter of last resort, we can try to fix things in SCA and/or the rules, but the general idea is making a demo for Fortify SCA as-is.
  • Ensure that the vulnerability can be found using a WebInspect scan. If this is not possible, find out why (ask for PM help as needed), and make any needed changes to make it detectable. As a matter of last resort, we can try to fix things in SCA and/or the rules, but the general idea is making a demo for WebInspect as-is.
This issue is being transferred. Timeline may not be complete until it finishes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
after October enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant