CodePath Week 8 Assignment
Time spent: 5 hours spent in total
Objective: Identify vulnerabilities in three different versions of the Globitek website: blue, green, and red.
The six possible exploits are:
- Username Enumeration
- Insecure Direct Object Reference (IDOR)
- SQL Injection (SQLi)
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Session Hijacking/Fixation
Each version of the site has been given two of the six vulnerabilities. (In other words, all six of the exploits should be assignable to one of the sites.)
Vulnerability #1:SQL Injection
- Blind SQL injection can be run by inserting ' OR SLEEP(5)=0--' at the end of the URL within the salesperson page, after clicking on a person. For example: https://35.226.11.110/blue/public/salesperson.php?id=%27%20OR%20SLEEP(5)=0--%27 makes the page load for 5 seconds.

Vulnerability #2: Session Hijacking
- The blue website can be logged into simultaneously on two browsers. I logged in on chrome then accessed the session ID through inspecting the page. Then on Firefox, I opened the website as well, not logged in. I was able to change the session ID to the session ID of the logged in chrome page using the hacking tool provided, then click the log in page and be automatically logged in.

Vulnerability #1: Username Enumeration
- If an existing username is entered with the incorrect password, the failure message appears in bold. If a username that does not exist is used, the error message is in non-bold text. Upon checking the source code, this is because these errors were stored as different classes, one called "failed" and one called "failure", which shows the attacker whether or not an account under a username exists.

Vulnerability #2: Cross-Site Scripting
- The Contact page has a cross-site scripting vulnerability. Script like <script>alert('Elie found the XSS!');</script> can be added in the contact form while not logged in, then upon logging in as admin and clicking the feedback tab, the alert popped up.

Vulnerability #1: Insecure Direct Object Reference
- On the red pag under the "Find a Salesperson" tab, clicking through the salespeople reveals the vulnerability because at the end of each URL is salesperson.php?id=N, where N is a number. By using https://35.226.11.110/red/public/salesperson.php?id=10, I was able to find a salesperson whose page is not supposed to be public.

Vulnerability #2: CSRF
