report.html

Report generated on 17-Jun-2020 at 14:35:36 by pytest-html v2.1.1

Environment

Packages {"pluggy": "0.13.1", "py": "1.8.2", "pytest": "5.4.3"}
Platform macOS-10.15.1-x86_64-i386-64bit
Plugins {"cases": "1.16.0", "html": "2.1.1", "metadata": "1.9.0"}
Python 3.8.1

Summary

75 tests ran in 39.10 seconds.

74 passed, 0 skipped, 1 failed, 0 errors, 0 expected failures, 0 unexpected passes

Results

Result Test Duration Links
Failed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_for_anomalies 0.01
def test_for_anomalies():
pattern_observed = {"status_code": [], "resp_size": [], "request":[], "fuzz_type": "vulns"}
for resp in responses_recieved:
pattern_observed["status_code"].append(resp.status_code)
pattern_observed["resp_size"].append(len(resp.content))
#pattern_observed["request"].append(_create_curl_request(resp.request.url,resp.request.method,resp.request.headers,resp.request.body))
pattern_observed["request"].append(curlify.to_curl(resp.request))
> assertions.assert_for_anomalies(pattern_observed)

tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py:575:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _

pattern_observed = {'fuzz_type': 'vulns', 'request': ['curl -X POST -H \'Accept: application/vnd.demoapp.com; version=1\' -H \'Accept-Enc.../v1/transfers', ...], 'resp_size': [52, 57, 491, 496, 49, 49, ...], 'status_code': [404, 404, 201, 201, 404, 404, ...]}

def assert_for_anomalies(pattern_observed):
status_codes = list(set(pattern_observed["status_code"]))
print(status_codes)
print(pattern_observed["status_code"])
if len(status_codes) == 1:
print("No anomalies observed in status codes")
assert 1
else:
counter = 0
num = status_codes[0]

for i in status_codes:
curr_frequency = status_codes.count(i)
if curr_frequency > counter:
counter = curr_frequency
num = i

indexes = [i for i, x in enumerate(pattern_observed["status_code"]) if x == num]
for _ in indexes:
print("\n ------------ To regenerate the request for "+str(pattern_observed["fuzz_type"])+":\n\n"+
str(pattern_observed["request"][_]))
print("--------" * 20)
print("anomalies observed in status codes")
> assert 0
E AssertionError

tests/assertions.py:58: AssertionError
------------------------------Captured stdout call------------------------------
[201, 404] [404, 404, 201, 201, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404, 404] ------------ To regenerate the request for vulns: curl -X POST -H 'Accept: application/vnd.demoapp.com; version=1' -H 'Accept-Encoding: gzip, deflate' -H 'Accept-Language: en-US,en;q=0.9' -H 'Access-Control-Allow-Methods: GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD' -H 'Access-Control-Allow-Origin: *' -H 'Access-Control-Expose-Headers: ' -H 'Access-Control-Max-Age: 1728000' -H 'Authorization: Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ' -H 'Cache-Control: max-age=0, private, must-revalidate' -H 'Connection: keep-alive' -H 'Content-Length: 119' -H 'Content-Type: application/json; charset=utf-8' -H 'Date: Wed, 17 Jun 2020 00:27:12 GMT' -H 'Etag: W/"f21d0acb657593909d7dc1dad0f31408"' -H 'Origin: http://34.238.148.157:31380' -H 'Referer: http://34.238.148.157:31380/profile' -H 'Referrer-Policy: strict-origin-when-cross-origin' -H 'Server: nginx/1.17.10' -H 'User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36' -H 'Vary: Origin' -H 'X-Content-Type-Options: nosniff' -H 'X-Download-Options: noopen' -H 'X-Frame-Options: SAMEORIGIN' -H 'X-Permitted-Cross-Domain-Policies: none' -H 'X-Request-Id: 5cb20a88-dbbf-46c5-8a9f-87e0538f5895' -H 'X-Runtime: 0.188602' -H 'X-Xss-Protection: 1; mode=block' -H 'cv-fuzzed-event: 1' -d '{"user_id1": "1,,,00", "beneficiary_id": "1,,,00", "description": "1,,,00", "amount": "1,,,00", "account_id": "1,,,00"}' http://54.236.47.36:31236/app-demo/api/v1/transfers ---------------------------------------------------------------------------------------------------------------------------------------------------------------- ------------ To regenerate the request for vulns: curl -X POST -H 'Accept: application/vnd.demoapp.com; version=1' -H 'Accept-Encoding: gzip, deflate' -H 'Accept-Language: en-US,en;q=0.9' -H 'Access-Control-Allow-Methods: GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD' -H 'Access-Control-Allow-Origin: *' -H 'Access-Control-Expose-Headers: ' -H 'Access-Control-Max-Age: 1728000' -H 'Authorization: Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ' -H 'Cache-Control: max-age=0, private, must-revalidate' -H 'Connection: keep-alive' -H 'Content-Length: 144' -H 'Content-Type: application/json; charset=utf-8' -H 'Date: Wed, 17 Jun 2020 00:27:12 GMT' -H 'Etag: W/"f21d0acb657593909d7dc1dad0f31408"' -H 'Origin: http://34.238.148.157:31380' -H 'Referer: http://34.238.148.157:31380/profile' -H 'Referrer-Policy: strict-origin-when-cross-origin' -H 'Server: nginx/1.17.10' -H 'User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36' -H 'Vary: Origin' -H 'X-Content-Type-Options: nosniff' -H 'X-Download-Options: noopen' -H 'X-Frame-Options: SAMEORIGIN' -H 'X-Permitted-Cross-Domain-Policies: none' -H 'X-Request-Id: 5cb20a88-dbbf-46c5-8a9f-87e0538f5895' -H 'X-Runtime: 0.188602' -H 'X-Xss-Protection: 1; mode=block' -H 'cv-fuzzed-event: 1' -d '{"user_id1": "1,,,00.html", "beneficiary_id": "1,,,00.html", "description": "1,,,00.html", "amount": "1,,,00.html", "account_id": "1,,,00.html"}' http://54.236.47.36:31236/app-demo/api/v1/transfers ---------------------------------------------------------------------------------------------------------------------------------------------------------------- anomalies observed in status codes
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[0,,,00-0,,,00-0,,,00-0,,,00-0,,,00] 0.56
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=0,,,00"} ---------------------- Request: {'data': {'user_id1': '0,,,00', 'beneficiary_id': '0,,,00', 'description': '0,,,00', 'amount': '0,,,00', 'account_id': '0,,,00'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[0,,,00.html-0,,,00.html-0,,,00.html-0,,,00.html-0,,,00.html] 0.47
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=0,,,00.html"} ---------------------- Request: {'data': {'user_id1': '0,,,00.html', 'beneficiary_id': '0,,,00.html', 'description': '0,,,00.html', 'amount': '0,,,00.html', 'account_id': '0,,,00.html'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[1,,,00-1,,,00-1,,,00-1,,,00-1,,,00] 0.48
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 201 {"transfer":{"id":475,"account_id":1,"beneficiary_id":1,"amount":"1.0","beneficiary_account_number":"6655443358","transfer_date":"2020-06-17T09:04:59.070Z","beneficiary_name":"Test","beneficiary_type":"at_savings","description":"1,,,00","account":{"id":1,"user_id":3,"account_number":"9876543210","account_type":"at_savings","balance":"10041.0"},"beneficiary":{"id":1,"user_id":3,"account_number":"6655443358","home_account":false,"beneficiary_name":"Test","beneficiary_type":"at_savings"}}} ---------------------- Request: {'data': {'user_id1': '1,,,00', 'beneficiary_id': '1,,,00', 'description': '1,,,00', 'amount': '1,,,00', 'account_id': '1,,,00'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [201]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[1,,,00.html-1,,,00.html-1,,,00.html-1,,,00.html-1,,,00.html] 0.52
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 201 {"transfer":{"id":476,"account_id":1,"beneficiary_id":1,"amount":"1.0","beneficiary_account_number":"6655443358","transfer_date":"2020-06-17T09:04:59.591Z","beneficiary_name":"Test","beneficiary_type":"at_savings","description":"1,,,00.html","account":{"id":1,"user_id":3,"account_number":"9876543210","account_type":"at_savings","balance":"10040.0"},"beneficiary":{"id":1,"user_id":3,"account_number":"6655443358","home_account":false,"beneficiary_name":"Test","beneficiary_type":"at_savings"}}} ---------------------- Request: {'data': {'user_id1': '1,,,00.html', 'beneficiary_id': '1,,,00.html', 'description': '1,,,00.html', 'amount': '1,,,00.html', 'account_id': '1,,,00.html'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [201]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[CDA-CDA-CDA-CDA-CDA] 0.49
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=CDA"} ---------------------- Request: {'data': {'user_id1': 'CDA', 'beneficiary_id': 'CDA', 'description': 'CDA', 'amount': 'CDA', 'account_id': 'CDA'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[CDS-CDS-CDS-CDS-CDS] 0.58
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=CDS"} ---------------------- Request: {'data': {'user_id1': 'CDS', 'beneficiary_id': 'CDS', 'description': 'CDS', 'amount': 'CDS', 'account_id': 'CDS'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[CMA-CMA-CMA-CMA-CMA] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=CMA"} ---------------------- Request: {'data': {'user_id1': 'CMA', 'beneficiary_id': 'CMA', 'description': 'CMA', 'amount': 'CMA', 'account_id': 'CMA'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[CMS-CMS-CMS-CMS-CMS] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=CMS"} ---------------------- Request: {'data': {'user_id1': 'CMS', 'beneficiary_id': 'CMS', 'description': 'CMS', 'amount': 'CMS', 'account_id': 'CMS'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[Deleting-Deleting-Deleting-Deleting-Deleting] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=Deleting"} ---------------------- Request: {'data': {'user_id1': 'Deleting', 'beneficiary_id': 'Deleting', 'description': 'Deleting', 'amount': 'Deleting', 'account_id': 'Deleting'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[Docs-Docs-Docs-Docs-Docs] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=Docs"} ---------------------- Request: {'data': {'user_id1': 'Docs', 'beneficiary_id': 'Docs', 'description': 'Docs', 'amount': 'Docs', 'account_id': 'Docs'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[Editing-Editing-Editing-Editing-Editing] 0.61
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=Editing"} ---------------------- Request: {'data': {'user_id1': 'Editing', 'beneficiary_id': 'Editing', 'description': 'Editing', 'amount': 'Editing', 'account_id': 'Editing'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[HOME-HOME-HOME-HOME-HOME] 0.61
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=HOME"} ---------------------- Request: {'data': {'user_id1': 'HOME', 'beneficiary_id': 'HOME', 'description': 'HOME', 'amount': 'HOME', 'account_id': 'HOME'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[Images-Images-Images-Images-Images] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=Images"} ---------------------- Request: {'data': {'user_id1': 'Images', 'beneficiary_id': 'Images', 'description': 'Images', 'amount': 'Images', 'account_id': 'Images'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[Internal-Internal-Internal-Internal-Internal] 0.61
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=Internal"} ---------------------- Request: {'data': {'user_id1': 'Internal', 'beneficiary_id': 'Internal', 'description': 'Internal', 'amount': 'Internal', 'account_id': 'Internal'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[MetaDataUpdate-MetaDataUpdate-MetaDataUpdate-MetaDataUpdate-MetaDataUpdate] 0.44
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=MetaDataUpdate"} ---------------------- Request: {'data': {'user_id1': 'MetaDataUpdate', 'beneficiary_id': 'MetaDataUpdate', 'description': 'MetaDataUpdate', 'amount': 'MetaDataUpdate', 'account_id': 'MetaDataUpdate'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[Report-Report-Report-Report-Report] 0.47
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=Report"} ---------------------- Request: {'data': {'user_id1': 'Report', 'beneficiary_id': 'Report', 'description': 'Report', 'amount': 'Report', 'account_id': 'Report'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[Select-Select-Select-Select-Select] 0.61
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=Select"} ---------------------- Request: {'data': {'user_id1': 'Select', 'beneficiary_id': 'Select', 'description': 'Select', 'amount': 'Select', 'account_id': 'Select'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[StoryServer-StoryServer-StoryServer-StoryServer-StoryServer] 0.61
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=StoryServer"} ---------------------- Request: {'data': {'user_id1': 'StoryServer', 'beneficiary_id': 'StoryServer', 'description': 'StoryServer', 'amount': 'StoryServer', 'account_id': 'StoryServer'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[TMT-TMT-TMT-TMT-TMT] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=TMT"} ---------------------- Request: {'data': {'user_id1': 'TMT', 'beneficiary_id': 'TMT', 'description': 'TMT', 'amount': 'TMT', 'account_id': 'TMT'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[VGN-VGN-VGN-VGN-VGN] 0.71
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=VGN"} ---------------------- Request: {'data': {'user_id1': 'VGN', 'beneficiary_id': 'VGN', 'description': 'VGN', 'amount': 'VGN', 'account_id': 'VGN'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[XML-XML-XML-XML-XML] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=XML"} ---------------------- Request: {'data': {'user_id1': 'XML', 'beneficiary_id': 'XML', 'description': 'XML', 'amount': 'XML', 'account_id': 'XML'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[ac-ac-ac-ac-ac] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=ac"} ---------------------- Request: {'data': {'user_id1': 'ac', 'beneficiary_id': 'ac', 'description': 'ac', 'amount': 'ac', 'account_id': 'ac'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[allvars-allvars-allvars-allvars-allvars] 0.44
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=allvars"} ---------------------- Request: {'data': {'user_id1': 'allvars', 'beneficiary_id': 'allvars', 'description': 'allvars', 'amount': 'allvars', 'account_id': 'allvars'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[asp-asp-asp-asp-asp] 0.48
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=asp"} ---------------------- Request: {'data': {'user_id1': 'asp', 'beneficiary_id': 'asp', 'description': 'asp', 'amount': 'asp', 'account_id': 'asp'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[aspstatus-aspstatus-aspstatus-aspstatus-aspstatus] 0.61
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=aspstatus"} ---------------------- Request: {'data': {'user_id1': 'aspstatus', 'beneficiary_id': 'aspstatus', 'description': 'aspstatus', 'amount': 'aspstatus', 'account_id': 'aspstatus'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[cda-cda-cda-cda-cda] 0.47
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=cda"} ---------------------- Request: {'data': {'user_id1': 'cda', 'beneficiary_id': 'cda', 'description': 'cda', 'amount': 'cda', 'account_id': 'cda'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[cds-cds-cds-cds-cds] 0.55
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=cds"} ---------------------- Request: {'data': {'user_id1': 'cds', 'beneficiary_id': 'cds', 'description': 'cds', 'amount': 'cds', 'account_id': 'cds'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[cma-cma-cma-cma-cma] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=cma"} ---------------------- Request: {'data': {'user_id1': 'cma', 'beneficiary_id': 'cma', 'description': 'cma', 'amount': 'cma', 'account_id': 'cma'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[cms-cms-cms-cms-cms] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=cms"} ---------------------- Request: {'data': {'user_id1': 'cms', 'beneficiary_id': 'cms', 'description': 'cms', 'amount': 'cms', 'account_id': 'cms'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[controller-controller-controller-controller-controller] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=controller"} ---------------------- Request: {'data': {'user_id1': 'controller', 'beneficiary_id': 'controller', 'description': 'controller', 'amount': 'controller', 'account_id': 'controller'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[diag-diag-diag-diag-diag] 0.58
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=diag"} ---------------------- Request: {'data': {'user_id1': 'diag', 'beneficiary_id': 'diag', 'description': 'diag', 'amount': 'diag', 'account_id': 'diag'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[docs-docs-docs-docs-docs] 0.46
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=docs"} ---------------------- Request: {'data': {'user_id1': 'docs', 'beneficiary_id': 'docs', 'description': 'docs', 'amount': 'docs', 'account_id': 'docs'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[edit-edit-edit-edit-edit] 0.44
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=edit"} ---------------------- Request: {'data': {'user_id1': 'edit', 'beneficiary_id': 'edit', 'description': 'edit', 'amount': 'edit', 'account_id': 'edit'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[error-error-error-error-error] 0.47
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=error"} ---------------------- Request: {'data': {'user_id1': 'error', 'beneficiary_id': 'error', 'description': 'error', 'amount': 'error', 'account_id': 'error'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[errorpage-errorpage-errorpage-errorpage-errorpage] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=errorpage"} ---------------------- Request: {'data': {'user_id1': 'errorpage', 'beneficiary_id': 'errorpage', 'description': 'errorpage', 'amount': 'errorpage', 'account_id': 'errorpage'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[errors-errors-errors-errors-errors] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=errors"} ---------------------- Request: {'data': {'user_id1': 'errors', 'beneficiary_id': 'errors', 'description': 'errors', 'amount': 'errors', 'account_id': 'errors'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[executequery-executequery-executequery-executequery-executequery] 0.55
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=executequery"} ---------------------- Request: {'data': {'user_id1': 'executequery', 'beneficiary_id': 'executequery', 'description': 'executequery', 'amount': 'executequery', 'account_id': 'executequery'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[external-external-external-external-external] 0.50
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=external"} ---------------------- Request: {'data': {'user_id1': 'external', 'beneficiary_id': 'external', 'description': 'external', 'amount': 'external', 'account_id': 'external'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[home-home-home-home-home] 0.46
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=home"} ---------------------- Request: {'data': {'user_id1': 'home', 'beneficiary_id': 'home', 'description': 'home', 'amount': 'home', 'account_id': 'home'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[ibm-ibm-ibm-ibm-ibm] 0.47
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=ibm"} ---------------------- Request: {'data': {'user_id1': 'ibm', 'beneficiary_id': 'ibm', 'description': 'ibm', 'amount': 'ibm', 'account_id': 'ibm'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[initialize-initialize-initialize-initialize-initialize] 0.48
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=initialize"} ---------------------- Request: {'data': {'user_id1': 'initialize', 'beneficiary_id': 'initialize', 'description': 'initialize', 'amount': 'initialize', 'account_id': 'initialize'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[internal-internal-internal-internal-internal] 0.60
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=internal"} ---------------------- Request: {'data': {'user_id1': 'internal', 'beneficiary_id': 'internal', 'description': 'internal', 'amount': 'internal', 'account_id': 'internal'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[jsp-jsp-jsp-jsp-jsp] 0.61
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=jsp"} ---------------------- Request: {'data': {'user_id1': 'jsp', 'beneficiary_id': 'jsp', 'description': 'jsp', 'amount': 'jsp', 'account_id': 'jsp'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[jspstatus-jspstatus-jspstatus-jspstatus-jspstatus] 0.61
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=jspstatus"} ---------------------- Request: {'data': {'user_id1': 'jspstatus', 'beneficiary_id': 'jspstatus', 'description': 'jspstatus', 'amount': 'jspstatus', 'account_id': 'jspstatus'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[jsptest-jsptest-jsptest-jsptest-jsptest] 0.50
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=jsptest"} ---------------------- Request: {'data': {'user_id1': 'jsptest', 'beneficiary_id': 'jsptest', 'description': 'jsptest', 'amount': 'jsptest', 'account_id': 'jsptest'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[legacy-legacy-legacy-legacy-legacy] 0.56
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=legacy"} ---------------------- Request: {'data': {'user_id1': 'legacy', 'beneficiary_id': 'legacy', 'description': 'legacy', 'amount': 'legacy', 'account_id': 'legacy'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[license-license-license-license-license] 0.47
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=license"} ---------------------- Request: {'data': {'user_id1': 'license', 'beneficiary_id': 'license', 'description': 'license', 'amount': 'license', 'account_id': 'license'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[listcolumns-listcolumns-listcolumns-listcolumns-listcolumns] 0.53
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=listcolumns"} ---------------------- Request: {'data': {'user_id1': 'listcolumns', 'beneficiary_id': 'listcolumns', 'description': 'listcolumns', 'amount': 'listcolumns', 'account_id': 'listcolumns'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[login-login-login-login-login] 0.49
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=login"} ---------------------- Request: {'data': {'user_id1': 'login', 'beneficiary_id': 'login', 'description': 'login', 'amount': 'login', 'account_id': 'login'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[loginlogo-loginlogo-loginlogo-loginlogo-loginlogo] 0.61
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=loginlogo"} ---------------------- Request: {'data': {'user_id1': 'loginlogo', 'beneficiary_id': 'loginlogo', 'description': 'loginlogo', 'amount': 'loginlogo', 'account_id': 'loginlogo'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[logo-logo-logo-logo-logo] 0.46
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=logo"} ---------------------- Request: {'data': {'user_id1': 'logo', 'beneficiary_id': 'logo', 'description': 'logo', 'amount': 'logo', 'account_id': 'logo'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[main-main-main-main-main] 0.56
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=main"} ---------------------- Request: {'data': {'user_id1': 'main', 'beneficiary_id': 'main', 'description': 'main', 'amount': 'main', 'account_id': 'main'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[menu-menu-menu-menu-menu] 0.50
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=menu"} ---------------------- Request: {'data': {'user_id1': 'menu', 'beneficiary_id': 'menu', 'description': 'menu', 'amount': 'menu', 'account_id': 'menu'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[metadataupdate-metadataupdate-metadataupdate-metadataupdate-metadataupdate] 0.56
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=metadataupdate"} ---------------------- Request: {'data': {'user_id1': 'metadataupdate', 'beneficiary_id': 'metadataupdate', 'description': 'metadataupdate', 'amount': 'metadataupdate', 'account_id': 'metadataupdate'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[performance-performance-performance-performance-performance] 0.44
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=performance"} ---------------------- Request: {'data': {'user_id1': 'performance', 'beneficiary_id': 'performance', 'description': 'performance', 'amount': 'performance', 'account_id': 'performance'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[portal-portal-portal-portal-portal] 0.55
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=portal"} ---------------------- Request: {'data': {'user_id1': 'portal', 'beneficiary_id': 'portal', 'description': 'portal', 'amount': 'portal', 'account_id': 'portal'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[ppstats-ppstats-ppstats-ppstats-ppstats] 0.53
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=ppstats"} ---------------------- Request: {'data': {'user_id1': 'ppstats', 'beneficiary_id': 'ppstats', 'description': 'ppstats', 'amount': 'ppstats', 'account_id': 'ppstats'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[preview-preview-preview-preview-preview] 0.58
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=preview"} ---------------------- Request: {'data': {'user_id1': 'preview', 'beneficiary_id': 'preview', 'description': 'preview', 'amount': 'preview', 'account_id': 'preview'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[previewer-previewer-previewer-previewer-previewer] 0.51
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=previewer"} ---------------------- Request: {'data': {'user_id1': 'previewer', 'beneficiary_id': 'previewer', 'description': 'previewer', 'amount': 'previewer', 'account_id': 'previewer'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[record-record-record-record-record] 0.47
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=record"} ---------------------- Request: {'data': {'user_id1': 'record', 'beneficiary_id': 'record', 'description': 'record', 'amount': 'record', 'account_id': 'record'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[reset-reset-reset-reset-reset] 0.44
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=reset"} ---------------------- Request: {'data': {'user_id1': 'reset', 'beneficiary_id': 'reset', 'description': 'reset', 'amount': 'reset', 'account_id': 'reset'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[save-save-save-save-save] 0.62
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=save"} ---------------------- Request: {'data': {'user_id1': 'save', 'beneficiary_id': 'save', 'description': 'save', 'amount': 'save', 'account_id': 'save'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[stat-stat-stat-stat-stat] 0.45
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=stat"} ---------------------- Request: {'data': {'user_id1': 'stat', 'beneficiary_id': 'stat', 'description': 'stat', 'amount': 'stat', 'account_id': 'stat'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[status-status-status-status-status] 0.59
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=status"} ---------------------- Request: {'data': {'user_id1': 'status', 'beneficiary_id': 'status', 'description': 'status', 'amount': 'status', 'account_id': 'status'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[storyserver-storyserver-storyserver-storyserver-storyserver] 0.60
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=storyserver"} ---------------------- Request: {'data': {'user_id1': 'storyserver', 'beneficiary_id': 'storyserver', 'description': 'storyserver', 'amount': 'storyserver', 'account_id': 'storyserver'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[style-style-style-style-style] 0.56
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=style"} ---------------------- Request: {'data': {'user_id1': 'style', 'beneficiary_id': 'style', 'description': 'style', 'amount': 'style', 'account_id': 'style'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[stylepreviewer-stylepreviewer-stylepreviewer-stylepreviewer-stylepreviewer] 0.56
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=stylepreviewer"} ---------------------- Request: {'data': {'user_id1': 'stylepreviewer', 'beneficiary_id': 'stylepreviewer', 'description': 'stylepreviewer', 'amount': 'stylepreviewer', 'account_id': 'stylepreviewer'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[utils-utils-utils-utils-utils] 0.47
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=utils"} ---------------------- Request: {'data': {'user_id1': 'utils', 'beneficiary_id': 'utils', 'description': 'utils', 'amount': 'utils', 'account_id': 'utils'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[vdc-vdc-vdc-vdc-vdc] 0.45
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=vdc"} ---------------------- Request: {'data': {'user_id1': 'vdc', 'beneficiary_id': 'vdc', 'description': 'vdc', 'amount': 'vdc', 'account_id': 'vdc'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[vgn-vgn-vgn-vgn-vgn] 0.61
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=vgn"} ---------------------- Request: {'data': {'user_id1': 'vgn', 'beneficiary_id': 'vgn', 'description': 'vgn', 'amount': 'vgn', 'account_id': 'vgn'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[vr-vr-vr-vr-vr] 0.44
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=vr"} ---------------------- Request: {'data': {'user_id1': 'vr', 'beneficiary_id': 'vr', 'description': 'vr', 'amount': 'vr', 'account_id': 'vr'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[Ping.jsp-Ping.jsp-Ping.jsp-Ping.jsp-Ping.jsp] 0.49
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=Ping.jsp"} ---------------------- Request: {'data': {'user_id1': 'Ping.jsp', 'beneficiary_id': 'Ping.jsp', 'description': 'Ping.jsp', 'amount': 'Ping.jsp', 'account_id': 'Ping.jsp'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[HelloWorld.jsp-HelloWorld.jsp-HelloWorld.jsp-HelloWorld.jsp-HelloWorld.jsp] 0.49
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'=HelloWorld.jsp"} ---------------------- Request: {'data': {'user_id1': 'HelloWorld.jsp', 'beneficiary_id': 'HelloWorld.jsp', 'description': 'HelloWorld.jsp', 'amount': 'HelloWorld.jsp', 'account_id': 'HelloWorld.jsp'}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------
Passed tests/test_app_demo_api_v1_transfers_for_vulns_fuzzing.py::test_app_demo_api_v1_transfers_for_vulns[----] 0.44
------------------------------Captured stdout call------------------------------
Regenerating traffic from CloudVector events.... 404 {"message":"Couldn't find Account with 'id'="} ---------------------- Request: {'data': {'user_id1': '', 'beneficiary_id': '', 'description': '', 'amount': '', 'account_id': ''}, 'headers': {'Accept': 'application/vnd.demoapp.com; version=1', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'en-US,en;q=0.9', 'Authorization': 'Bearer eyJhbGciOiJIUzUxMiJ9.eyJpc3MiOiJkZW1vYXBwLWFwaSIsImlhdCI6MTU5MjM1MzYzMiwidGkiOiI5MmM5ZWJlMi0xYjBkLTRjOTUtYjNjYi1kNDg3NmJhODM2NTAiLCJ1c2VyIjp7ImlkIjozLCJlbWFpbCI6ImpvaG5AZGVtb2FwcC5jb20ifX0.C8BZ3vZW3heVdMPXnynYBHD-NPw3o5M36TIgdkaXXxuoScZhLGnBhMzpH5iPSP-v10M3-4INuJB8iqNzzumhyQ', 'Connection': 'keep-alive', 'Content-Length': '92', 'Content-Type': 'application/json; charset=utf-8', 'Origin': 'http://34.238.148.157:31380', 'Referer': 'http://34.238.148.157:31380/profile', 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36', 'Access-Control-Allow-Methods': 'GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD', 'Access-Control-Allow-Origin': '*', 'Access-Control-Expose-Headers': '', 'Access-Control-Max-Age': '1728000', 'Cache-Control': 'max-age=0, private, must-revalidate', 'Date': 'Wed, 17 Jun 2020 00:27:12 GMT', 'Etag': 'W/"f21d0acb657593909d7dc1dad0f31408"', 'Referrer-Policy': 'strict-origin-when-cross-origin', 'Server': 'nginx/1.17.10', 'Set-Cookie-params': None, 'Vary': 'Origin', 'X-Content-Type-Options': 'nosniff', 'X-Download-Options': 'noopen', 'X-Frame-Options': 'SAMEORIGIN', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-Request-Id': '5cb20a88-dbbf-46c5-8a9f-87e0538f5895', 'X-Runtime': '0.188602', 'X-Xss-Protection': '1; mode=block', 'cv-fuzzed-event': '1'}} Response: <Response [404]> ----------------------