From eb3e32028c5d5a9a9dcffee431373062bff71da3 Mon Sep 17 00:00:00 2001
From: Joshua Ashton
Date: Sat, 8 Feb 2025 20:03:40 -0700
Subject: [PATCH] implemented insecure assignment.
---
insecure/composer.json | 12 ++++
insecure/css/.gitkeep | 0
insecure/css/styles.css | 136 +++++++++++++++++++++++++++++++++++
insecure/hidden.php | 71 +++++++++++++++++++
insecure/img/.gitkeep | 0
insecure/includes/fbi.txt | 1 +
insecure/includes/spies.txt | 1 +
insecure/index.php | 137 ++++++++++++++++++++++++++++++++++++
insecure/js/.gitkeep | 0
insecure/js/index.js | 0
10 files changed, 358 insertions(+)
create mode 100644 insecure/composer.json
create mode 100644 insecure/css/.gitkeep
create mode 100644 insecure/css/styles.css
create mode 100644 insecure/hidden.php
create mode 100644 insecure/img/.gitkeep
create mode 100644 insecure/includes/fbi.txt
create mode 100644 insecure/includes/spies.txt
create mode 100644 insecure/index.php
create mode 100644 insecure/js/.gitkeep
create mode 100644 insecure/js/index.js
diff --git a/insecure/composer.json b/insecure/composer.json
new file mode 100644
index 0000000..b7cf0fe
--- /dev/null
+++ b/insecure/composer.json
@@ -0,0 +1,12 @@
+{
+ "name": "violet/spies",
+ "type": "project",
+ "autoload": {
+ "psr-4": {
+ "Violet\\Spies\\": "src/"
+ }
+ },
+ "require": {
+ "vlucas/phpdotenv": "^5.6"
+ }
+}
diff --git a/insecure/css/.gitkeep b/insecure/css/.gitkeep
new file mode 100644
index 0000000..e69de29
diff --git a/insecure/css/styles.css b/insecure/css/styles.css
new file mode 100644
index 0000000..2d22bb3
--- /dev/null
+++ b/insecure/css/styles.css
@@ -0,0 +1,136 @@
+* {
+ margin: 0;
+ padding: 0;
+}
+
+body {
+ /* Positioning */
+ display: flex;
+ flex-direction: column;
+ justify-content: center;
+ align-items: center;
+
+ /* Styling */
+ background-color: #bbedbe;
+}
+
+h1 {
+ /* Positioning */
+ width: 100%;
+ padding: 2vw;
+
+ /* Font */
+ font-size: 6vw;
+ text-align: center;
+}
+
+h3 {
+ font-size: 4vw;
+}
+
+h5 {
+ font-size: 2vw;
+}
+
+h1,
+h3,
+h5,
+p,
+input {
+ color: #0e3610;
+}
+
+form {
+ /* Form Shape */
+ width: 60%;
+ padding: 2.5vw 5vw 2.5vw 5vw;
+
+ /* Positioning */
+ display: flex;
+ flex-direction: column;
+ justify-content: center;
+ align-items: center;
+}
+
+.row {
+ /* Row Shape */
+ width: 100%;
+ display: flex;
+}
+
+input {
+ /* Input Shape */
+ width: 50%;
+ padding: 1vw;
+ margin: 1vw;
+ border: none;
+ border-radius: 18px;
+
+ /* Styling */
+ background-color: #f1fbf2;
+
+ /* Font */
+ font-size: 1vw;
+ font-weight: 400;
+}
+
+button {
+ /* Button Shape */
+ width: 60%;
+ padding: 1vw;
+ margin: 1vw;
+ border: none;
+ border-radius: 18px;
+
+ /* Font */
+ color: white;
+ font-size: 1vw;
+ font-weight: 600;
+
+ /* Transition for hover */
+ transition-duration: 500ms;
+
+ background-color: #1c6b20;
+}
+
+button:hover {
+ background-color: #26942D;
+}
+
+table {
+ border-spacing: 0;
+ table-layout: fixed;
+ width: 40%;
+ border: 1px solid black;
+}
+
+td {
+ margin: 0;
+ padding: 1vw;
+ border: 1px solid black;
+ text-align: center;
+}
+
+.card {
+ padding: 2vw;
+ background-color: gray;
+ border-radius: 18px;
+}
+
+.error {
+ color: white;
+ background-color: red;
+}
+
+.success {
+ color: white;
+ background-color: #0e3610;
+}
+
+.reset {
+ background-color: #cc0000;
+}
+
+.reset:hover {
+ background-color: #FF0000;
+}
diff --git a/insecure/hidden.php b/insecure/hidden.php
new file mode 100644
index 0000000..ac1eee6
--- /dev/null
+++ b/insecure/hidden.php
@@ -0,0 +1,71 @@
+ 'roast', 'bob' => 'ross');
+$access = false;
+
+if (isset($_POST['username']) && isset($_POST['password'])) {
+ $username = $_POST['username'];
+ $password = $_POST['password'];
+ if (array_key_exists($username, $users) && $users[$username] === $password)
+ $access = true;
+}
+
+$file = 'fbi.txt';
+
+function fileRead($file)
+{
+ if (isset($_GET['fbi']))
+ $file = 'fbi.txt';
+ else
+ $file = 'spies.txt';
+ if ($access) {
+ echo "reading $file";
+ $fs = fopen($file, 'r');
+ $string = fread($fs, filesize($file));
+ $values = explode('||>><<||', $string);
+
+ echo '';
+ foreach ($values as $v) {
+ list($a, $b) = explode(',', $v);
+
+ echo '
+
+ | ' . $a . ' |
+ ' . $b . ' |
+
+ ';
+ }
+ echo '
';
+ } else
+ header('Location: .?access=false');
+}
+?>
+
+
+
+
+ Spies
+
+
+
+
+
+ View Confidential Information
+
+Access Granted
';
+
+ echo '
+
+
+ ';
+
+ fileRead($file);
+}
+?>
+
+
+
+
+
diff --git a/insecure/img/.gitkeep b/insecure/img/.gitkeep
new file mode 100644
index 0000000..e69de29
diff --git a/insecure/includes/fbi.txt b/insecure/includes/fbi.txt
new file mode 100644
index 0000000..06a9203
--- /dev/null
+++ b/insecure/includes/fbi.txt
@@ -0,0 +1 @@
+skinner,gatekeeper||>><<||csm,alien||>><<||dana,skeptic||>><<||fox,believer
\ No newline at end of file
diff --git a/insecure/includes/spies.txt b/insecure/includes/spies.txt
new file mode 100644
index 0000000..d67c36a
--- /dev/null
+++ b/insecure/includes/spies.txt
@@ -0,0 +1 @@
+dale,the government||>><<||bill,the barber||>><<||hank,the texan||>><<||boomhauer,the marshall
\ No newline at end of file
diff --git a/insecure/index.php b/insecure/index.php
new file mode 100644
index 0000000..8f576a1
--- /dev/null
+++ b/insecure/index.php
@@ -0,0 +1,137 @@
+safeLoad();
+
+// Use environment variables for the database password and IP address.
+$db_pass = $_ENV['DATABASE_PASSWORD'];
+$ip_addr = $_ENV['IP_ADDRESS'];
+
+// Make some constants
+if ($_SERVER['HTTP_HOST'] == 'localhost') {
+ define('HOST', 'localhost');
+ define('USER', 'root');
+ define('PASS', $db_pass);
+ define('DB', 'insecure');
+} else {
+ define('HOST', $ip_addr);
+ define('USER', 'root');
+ define('PASS', $db_pass);
+ define('DB', 'insecure');
+}
+
+if (isset($_POST['username']) && isset($_POST['password'])) {
+ $username = $_POST['username'];
+ $password = $_POST['password'];
+
+ // Connect to the DB
+ $conn = mysqli_connect(HOST, USER, PASS, DB);
+
+ // Write a DB query
+ $sql = 'SELECT password FROM users WHERE username = "' . $username . ' ";';
+
+ // Run DB query
+ $results = mysqli_query($conn, $sql);
+
+ if (mysqli_num_rows($results) == 0) {
+ $_GET['error'] = true;
+ } else {
+ $row = mysqli_fetch_assoc($results);
+
+ if ($row['password'] == $password) {
+ $_SESSION['access'] = true;
+ $_GET['file'] = 'includes/fbi.txt';
+ } else {
+ $_GET['error'] = true;
+ }
+ }
+}
+
+if (isset($_GET['logout'])) {
+ $_SESSION['access'] = false;
+ header('Location: .');
+}
+
+?>
+
+
+
+
+
+ Spies
+
+
+
+
+
+View Confidential Information
+
+ Access Denied.
+ Invalid username or password.
+
+ ';
+ }
+ echo '
+
+ ';
+} else if (isset($_GET['file']) && isset($_SESSION['access'])) {
+ echo '
+
+
Access Granted.
+
+
+ ';
+ fileRead($_GET['file']);
+}
+?>
+
+
+
+><<||', $string);
+
+ echo '
+
+
+ | Agent |
+ Codename |
+
+ ';
+ foreach ($values as $v) {
+ list($a, $b) = explode(',', $v);
+
+ echo '
+
+ | ' . ucfirst($a) . ' |
+ ' . ucwords($b) . ' |
+
+ ';
+ }
+ echo '
';
+}
+?>
diff --git a/insecure/js/.gitkeep b/insecure/js/.gitkeep
new file mode 100644
index 0000000..e69de29
diff --git a/insecure/js/index.js b/insecure/js/index.js
new file mode 100644
index 0000000..e69de29