microsoft/restler-fuzzer

URL Parameters Missing Space Encodings

Open

#495 opened on Mar 22, 2022

 (1 comment) (0 reactions) (0 assignees)Python (329 forks)auto 404
bughelp wanted

Repository metrics

Stars
 (2,929 stars)
PR merge metrics
 (PR metrics pending)

Description

URL parameters which contain a space in the value do not get the usual URL encoding (ex. " " becomes "+" or "%20"). This results in malformed HTTP/1.1 requests. For example, if my yaml specification has a type like:

    network:
      name: network
      in: query
      required: true
      schema:
        type: string
        enum:
          - "Internal"
          - "External Users"
          - "External Networks"

then the following GET requests will be created:

GET /config?network=Internal HTTP/1.1
GET /config?network=External Users HTTP/1.1
GET /config?network=External Networks HTTP/1.1

This doesn't get recognized properly and leads to erroneous fuzzing cases for parameters which are supposed to contain a space in them.

Contributor guide