-
Notifications
You must be signed in to change notification settings - Fork 192
/
index.html
executable file
·117 lines (96 loc) · 4.25 KB
/
index.html
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Live demonstrations</title>
<link href="/static/css/bootstrap.min.css" rel="stylesheet">
<link href="/static/css/datepicker3.css" rel="stylesheet">
<link href="/static/css/styles.css" rel="stylesheet">
<script src="/static/js/hints.js"></script>
<!--Icons-->
<script src="/static/js/lumino.glyphs.js"></script>
</head>
<body>
<nav class="navbar navbar-inverse navbar-fixed-top" role="navigation">
<div class="container-fluid">
<div class="navbar-header">
<button type="button" class="navbar-toggle collapsed" data-toggle="collapse" data-target="#sidebar-collapse">
<span class="sr-only">Toggle navigation</span>
<span class="icon-bar"></span>
<span class="icon-bar"></span>
<span class="icon-bar"></span>
</button>
<ul class="user-menu">
<li class="dropdown pull-right">
<ul class="dropdown-menu" role="menu">
</ul>
</li>
</ul>
</div>
</div><!-- /.container-fluid -->
</nav>
<div id="sidebar-collapse" class="col-sm-3 col-lg-2 sidebar">
<br/><br/>
<center>
<img src="/static/img/logo.svg" width="60%" height="60%"/> <br/>
<p style="color:#515594; font-size:1.0em;"><a href="https://github.com/blabla1337/skf-flask" style="color:#515594; font-size:1.7em;">OWASP S.K.F.</a></p> <p><a href="https://gitter.im/Security-Knowledge-Framework/Lobby" rel="nofollow"> <img src="/static/img/badge.svg" alt="Join the chat at https://gitter.im/Security-Knowledge-Framework/Lobby" data-canonical-src="/static/img/badge.svg" style="max-width:100%;"></a> </p>
</center>
<br>
<div>
<h2 align="center">Hint <span id="hint-num">0</span>/3 (<button
class="btn btn-primary btn-lg" type="button" onclick="showHint(); return false">show</button>)
</h2>
<div id="hints">
<ol>
<li style="display: none" data-hidden="true"><b>1.</b>
Find, identify and explore every possible input field that could be object of injection.
<li style="display: none" data-hidden="true"><b>2.</b>
Try to inject and execute javascript code in the field.
</ol>
</div>
</div>
</div><!--/.sidebar-->
<div class="col-sm-9 col-sm-offset-3 col-lg-10 col-lg-offset-2 main">
<div class="row">
</div><!--/.row-->
<div class="row">
<div class="col-lg-12">
<h1 class="page-header">Live demonstration!</h1>
</div>
</div><!--/.row-->
<div class="row">
<div class="col-lg-12">
<div class="panel panel-default">
<div class="panel-heading">XSS attribute!</div>
<div class="panel-body">
<div class="col-md-6">
<form method="post" action="/home">
<input type="text" class="form-control" name="string" placeholder="fill me in plz"/><br/>
<button class="btn btn-primary" type="submit">Submit Button</button>
</div>
</form>
</div>
</div>
</div><!-- /.col-->
</div><!-- /.row -->
<center> <p style="font-size:2em;"> {% autoescape false %}<span style='color:{{xss}};' > Let me be a new color!</span>{% endautoescape %}</p></center>
</div><!--/.main-->
<script src="/static/js/jquery-1.11.1.min.js"></script>
<script src="/static/js/bootstrap.min.js"></script>
<script>
!function ($) {
$(document).on("click","ul.nav li.parent > a > span.icon", function(){
$(this).find('em:first').toggleClass("glyphicon-minus");
});
$(".sidebar span.icon").find('em:first').addClass("glyphicon-plus");
}(window.jQuery);
$(window).on('resize', function () {
if ($(window).width() > 768) $('#sidebar-collapse').collapse('show')
})
$(window).on('resize', function () {
if ($(window).width() <= 767) $('#sidebar-collapse').collapse('hide')
})
</script>
</body>
</html>