mirror of
https://github.com/SquidSec/SquidGate
synced 2026-08-09 12:22:48 +00:00
sample(go): intentional vulnerabilities for SquidGate demo
Demo only — hardcoded secret + injection / dangerous API patterns. See examples/README.md
This commit is contained in:
@@ -0,0 +1,20 @@
|
||||
// SquidGate sample — Go (intentional vulnerabilities for demo)
|
||||
package demo
|
||||
|
||||
import (
|
||||
"database/sql"
|
||||
"os/exec"
|
||||
)
|
||||
|
||||
const apiKey = "go-demo-secret-key-not-real"
|
||||
|
||||
func FindUser(db *sql.DB, id string) error {
|
||||
// SQL injection
|
||||
_, err := db.Query("SELECT * FROM users WHERE id = '" + id + "'")
|
||||
return err
|
||||
}
|
||||
|
||||
func Run(userInput string) error {
|
||||
// command injection
|
||||
return exec.Command("sh", "-c", "echo "+userInput).Run()
|
||||
}
|
||||
Reference in New Issue
Block a user