Files
attack-defense-platform/services/warmup/src/main.go
T
2025-10-25 04:56:33 +07:00

55 lines
1.2 KiB
Go

package main
import (
"fmt"
"io/ioutil"
"log"
"net/http"
"path/filepath"
)
// Vulnerable file viewing handler - LFI vulnerability
func viewHandler(w http.ResponseWriter, r *http.Request) {
// Get the file parameter
filename := r.URL.Query().Get("file")
// Default file if none specified
if filename == "" {
filename = "welcome.txt"
}
// Vulnerable: directly concatenating user input without proper validation
// This allows path traversal attacks
filePath := filepath.Join("/opt/files/", filename)
// Read the file
content, err := ioutil.ReadFile(filePath)
if err != nil {
http.Error(w, "File not found or cannot be read", http.StatusNotFound)
return
}
w.Header().Set("Content-Type", "text/plain")
w.Write(content)
}
func homeHandler(w http.ResponseWriter, r *http.Request) {
// Serve the HTML template
htmlContent, err := ioutil.ReadFile("/opt/index.html")
if err != nil {
http.Error(w, "Template not found", http.StatusNotFound)
return
}
w.Header().Set("Content-Type", "text/html")
w.Write(htmlContent)
}
func main() {
http.HandleFunc("/", homeHandler)
http.HandleFunc("/view", viewHandler)
fmt.Println("Starting server on :8081")
log.Fatal(http.ListenAndServe(":8081", nil))
}