Sha256: 004ab524b644bbd87b2f14fb28beeb0f476271cf09e62014b58b58e95f41e1bc

Contents?: true

Size: 1.27 KB

Versions: 10

Compression:

Stored size: 1.27 KB

Contents

require 'sinatra'
require 'sinatra/contrib'

def logged_in?
    cookies[:success] == 'true'
end

get '/' do
    cookies[:success] ||= false

    if logged_in?
        <<-HTML
            <a href='/congrats'>Hi there logged-in user!</a>
        HTML
    else
        redirect '/login'
    end
end

get '/fail_4_times' do
    @@tries ||= 0
    @@tries += 1

    if @@tries <= 5
        # Return a 0 error code.
        0
    else
        'Stuff'
    end
end

get '/fail' do
    # Return a 0 error code.
    0
end

get '/login' do
    <<-HTML
        <form method='post' name='login_form' action="/login">
            <input name='username' value='' />
            <input name='password' type='password' value='' />
            <input name='token' type='hidden' value='secret!' />
        </form>
    HTML
end

post '/login' do
    if params['username'] == 'john' && params['password'] == 'doe' &&
        params['token'] == 'secret!'
        cookies[:success] = true
        redirect '/'
    else
        'Boohoo...'
    end
end

get '/congrats' do
    <<-EOHTML
        Congrats, get to the audit!
        <a href='/link'></a>
    EOHTML
end

get '/link' do
    if logged_in?
        <<-EOHTML
            <a href='/link?input=blah'>Inject here</a>
            #{params[:input]}
        EOHTML
    end
end

Version data entries

10 entries across 10 versions & 1 rubygems

Version Path
arachni-0.4.7 spec/support/servers/arachni/framework.rb
arachni-0.4.6 spec/support/servers/arachni/framework.rb
arachni-0.4.5.2 spec/support/servers/arachni/framework.rb
arachni-0.4.5.1 spec/support/servers/arachni/framework.rb
arachni-0.4.5 spec/support/servers/arachni/framework.rb
arachni-0.4.4 spec/support/servers/arachni/framework.rb
arachni-0.4.3.2 spec/support/servers/arachni/framework.rb
arachni-0.4.3.1 spec/support/servers/arachni/framework.rb
arachni-0.4.3 spec/support/servers/arachni/framework.rb
arachni-0.4.2 spec/servers/arachni/framework.rb