Sploitus

Exploit for notevault-vapt-assessment

githubexploit Β· 2026-08-23

Exploit Code

README67 lines
## https://sploitus.com/exploit?id=7E538382-17FC-5032-B925-532B1C727550
# Black-Box VAPT Assessment β€” NoteVault

A self-contained, reproducible black-box penetration test: a deliberately vulnerable web app, a real assessment performed against it with Burp Suite / Postman / manual testing, a professional VAPT report with PoCs and CVSS scoring for 5 critical/high findings, and a remediated build with retest evidence proving each fix.

**Read the full report: [`report/VAPT_Report.md`](report/VAPT_Report.md)**

> ⚠️ **Disclaimer:** `app/` is an *intentionally vulnerable* application built for this repository. It contains real, exploitable bugs on purpose (SQL injection, stored XSS, IDOR, plaintext password storage, a hardcoded secret, an unauthenticated debug endpoint). Never deploy `app/` anywhere reachable from the internet. It exists solely so this assessment could be performed and documented end-to-end, legally and safely, against a target the author owns.

## What's in this repo

| Path | Purpose |
|---|---|
| [`app/`](app) | The vulnerable NoteVault build β€” the assessment target |
| [`fixed/`](fixed) | The remediated build, with every fix from the report applied |
| [`report/VAPT_Report.md`](report/VAPT_Report.md) | The full assessment: methodology, 5 detailed findings with real PoCs and CVSS scores, retest evidence, and metrics |
| [`testing/postman_collection.json`](testing/postman_collection.json) | Importable Postman collection of every request used, grouped by finding |
| [`testing/manual_test_notes.md`](testing/manual_test_notes.md) | Burp Suite workflow (Proxy/Repeater/Intruder/Decoder) and manual testing checklist |
| [`scripts/`](scripts) | Convenience scripts to run either build |

## Findings summary

| ID | Finding | Severity | CVSS 3.1 | Status |
|---|---|---|---|---|
| VULN-01 | SQL Injection (`/api/search`) | Critical | 9.1 | Fixed & retested |
| VULN-02 | Stored XSS (note comments) | High | 8.7 | Fixed & retested |
| VULN-03 | IDOR / broken object-level authorization | Critical | 8.1 | Fixed & retested |
| VULN-04 | Broken auth β€” plaintext passwords + hardcoded JWT secret | Critical | 9.1 | Fixed & retested |
| VULN-05 | Security misconfiguration β€” unauthenticated debug endpoint | High | 7.5 | Fixed & retested |
| VULN-06 | Missing security headers / no login rate limiting | Medium | 5.3 | Fixed & retested |
| VULN-07–10 | CSRF, audit logging, dependency scanning, MFA | Medium/Low | β€” | Open β€” see report Β§5 |

**60% of all identified findings** were remediated and independently retested within this engagement; **100% of critical/high findings** were closed. Full methodology for these numbers is in [report Β§6](report/VAPT_Report.md#6-metrics-methodology).

## Running it yourself

Requires Node.js 22+ (uses the built-in `node:sqlite` module, no native build step).

```bash
# vulnerable build β€” http://localhost:4001
./scripts/run_vuln_app.sh

# remediated build β€” http://localhost:4002
./scripts/run_fixed_app.sh
```

Seeded accounts on both builds: `alice` / `alice123`, `bob` / `bobpassword`, `admin` / `admin123`.

Reproduce any finding from the report, e.g. the IDOR:

```bash
curl -s -c /tmp/cookies.txt -X POST http://localhost:4001/api/login \
  -H "Content-Type: application/json" -d '{"username":"alice","password":"alice123"}'

curl -s -b /tmp/cookies.txt http://localhost:4001/api/notes/3   # returns admin's note
curl -s -b /tmp/cookies.txt http://localhost:4002/api/notes/3   # 403 forbidden on the fixed build
```

## Tools

- **Burp Suite** β€” proxying, Repeater for payload iteration, Intruder for ID enumeration, Decoder for JWT inspection
- **Postman** β€” the request collection in `testing/postman_collection.json`
- **Manual testing** β€” `curl` / Node.js for scripted, exactly-reproducible PoCs (used to generate every response quoted in the report)

## License

MIT β€” see [`LICENSE`](LICENSE).