Remove mock LLM server and related configurations; update README and exploit tests for clarity
This commit is contained in:
@@ -130,12 +130,12 @@ class PathTraversalPOC:
|
||||
)
|
||||
self._print_result(r)
|
||||
|
||||
# Test 3: Read sensitive config
|
||||
print("[TEST 3] Read /sensitive/api_keys.txt")
|
||||
# Test 3: Read sensitive test file (demonstrates path traversal outside workspace)
|
||||
print("[TEST 3] Read /sensitive/api_keys.txt (test file outside workspace)")
|
||||
r = await self.test_read(
|
||||
"api_keys",
|
||||
"sensitive_test_file",
|
||||
"/sensitive/api_keys.txt",
|
||||
"API key disclosure"
|
||||
"Sensitive file disclosure - if content contains 'PATH_TRAVERSAL_VULNERABILITY_CONFIRMED', vuln is proven"
|
||||
)
|
||||
self._print_result(r)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user