sample(go): intentional vulnerabilities for SquidGate demo

Demo only — hardcoded secret + injection / dangerous API patterns.
See examples/README.md
This commit is contained in:
SquidSec Bot
2026-07-28 16:08:24 -04:00
parent ee7d42ee22
commit 00cdfa483d
+20
View File
@@ -0,0 +1,20 @@
// SquidGate sample — Go (intentional vulnerabilities for demo)
package demo
import (
"database/sql"
"os/exec"
)
const apiKey = "go-demo-secret-key-not-real"
func FindUser(db *sql.DB, id string) error {
// SQL injection
_, err := db.Query("SELECT * FROM users WHERE id = '" + id + "'")
return err
}
func Run(userInput string) error {
// command injection
return exec.Command("sh", "-c", "echo "+userInput).Run()
}