Home Product Architecture Security Capabilities Install MCP & Skills
DEMO EXPERIENCES ⚡ Interactive Security Demo 🔍 View Demo Code (Syntax Highlighted)
About
DemoDeterministic Assessment Engine

DEMO-0001

Interactive illustrative assessment replay · breachlabs-demo · 4820ms · 12 routes mapped

COMPLETED Deterministic Replay
Target Scenario:
STAGE 01 Discovery & Recon
STAGE 02 Deterministic Scans
STAGE 03 AI Investigation
STAGE 04 Targeted Verification
STAGE 05 Fix & Retest Proof
Discovered Findings
3
2 Verified · 1 Investigating
Verification Rate
100%
Zero unproven claims
Target Execution Time
4820ms
Deterministic pipeline replay
Mapped Surface
12
Routes, forms & APIs
live assessment telemetry — breachlabs-demo
STREAM ACTIVE
01[00:00.120] INTAKE: Repository checked out at revision a9f82d1 (clean sandbox)
02[00:01.450] DISCOVER: Enumerated 14 HTTP routes, 3 forms, 9 JSON endpoints
03[00:02.810] SAST: Taint sink in search.py:38 -> direct string concatenation into SQL query
04[00:03.200] AGENT: Correlated route GET /search?q= with unvalidated query parameter
05[00:04.110] VERIFY: Dispatched deterministic probe -> Syntax verification payload confirmed BL-DEMO-001
06[00:04.820] SUMMARY: Assessment complete · 3 findings recorded in append-only evidence store
BL-DEMO-001 VERIFIED

SQL injection in search parameter

SeverityHIGH
ConfidenceVERIFIED
SurfaceGET /search?q=
Click to inspect Evidence & Fix →
BL-DEMO-002 VERIFIED

Reflected XSS in comment field

SeverityHIGH
ConfidenceVERIFIED
SurfacePOST /comments
Click to inspect Evidence & Fix →
BL-DEMO-003 VERIFIED

Missing security response headers

SeverityMEDIUM
ConfidenceVERIFIED
SurfaceGET /
Click to inspect Evidence & Fix →
BL-DEMO-001 VERIFIED CWE-89: SQL Injection

SQL injection in search parameter

Surface: GET /search?q=

1. Vulnerable Code Context

search.py:38
36def search_products(request):
37    term = request.args.get('q', '')
38    query = "SELECT * FROM items WHERE name = '" + term + "'"
39    return db.engine.execute(query).fetchall()

2. Evidence Provenance Chain

search.py:38 — AST Taint analysis sink SAST
GET /search?q='%20OR%20'1'='1 → HTTP 200 with full DB dump DAST PROBE
Unparameterized SQL executed in 2 surrounding helper calls CORRELATION

3. AI Security Analysis

The q query parameter is read directly from untrusted user input and concatenated without sanitization or SQL parameter binding. The verification probe confirmed that arbitrary SQL syntax executes against the SQLite datastore.

4. Remediation Patch

git diff — search.py
1- query = "SELECT * FROM items WHERE name = '" + term + "'"
2- return db.engine.execute(query).fetchall()
3+ query = "SELECT * FROM items WHERE name = ?"
4+ return db.engine.execute(query, (term,)).fetchall()
Retest Verified: Replaying probe payload against patched code resulted in HTTP 200 with zero injected query syntax execution. Finding marked RESOLVED.

3 of 3 findings shown. Assessment replay is fully deterministic.