UNPKG

sitecheck

Version:

Open Source web application security scanner

384 lines (383 loc) 12.6 kB
<!doctype html> <html lang="en"> <head> <title>Code coverage report for src\checks\server\check_code_disclosure.js</title> <meta charset="utf-8" /> <link rel="stylesheet" href="../../../prettify.css" /> <link rel="stylesheet" href="../../../base.css" /> <meta name="viewport" content="width=device-width, initial-scale=1"> <style type='text/css'> .coverage-summary .sorter { background-image: url(../../../sort-arrow-sprite.png); } </style> </head> <body> <div class='wrapper'> <div class='pad1'> <h1> <a href="../../../index.html">all files</a> / <a href="index.html">src/checks/server/</a> check_code_disclosure.js </h1> <div class='clearfix'> <div class='fl pad1y space-right2'> <span class="strong">100% </span> <span class="quiet">Statements</span> <span class='fraction'>36/36</span> </div> <div class='fl pad1y space-right2'> <span class="strong">100% </span> <span class="quiet">Branches</span> <span class='fraction'>8/8</span> </div> <div class='fl pad1y space-right2'> <span class="strong">100% </span> <span class="quiet">Functions</span> <span class='fraction'>3/3</span> </div> <div class='fl pad1y space-right2'> <span class="strong">100% </span> <span class="quiet">Lines</span> <span class='fraction'>36/36</span> </div> </div> </div> <div class='status-line high'></div> <pre><table class="coverage"> <tr><td class="line-count quiet">1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107</td><td class="line-coverage quiet"><span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes">87×</span> <span class="cline-any cline-yes">87×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span></td><td class="text"><pre class="prettyprint lang-js">/** * @license Apache-2.0 * Copyright (C) 2016 The Sitecheck Project * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. * See the License for the specific language governing permissions and * limitations under the License. */ "use strict"; &nbsp; var Check = require('../../check'); var request = require('../../requestwrapper'); const CONSTANTS = require("../../constants.js"); &nbsp; const PHP = 'PHP'; const ASP = 'ASP'; const JSP = 'JSP'; const ASPX = 'ASPX'; const UNKNOWN = 'Unknown'; const SHELL = 'Shell script'; const JAVA = 'Java'; const RUBY = 'Ruby'; const PYTHON = 'Python'; const GROOVY = 'Groovy'; &nbsp; const SOURCE_CODE = [ { "regEx": '&lt;\\?php .*? \\?&gt;', "language": PHP }, { "regEx": '&lt;\\?php\\n.*?\\?&gt;', "language": PHP }, { "regEx": '&lt;\\?php\\r.*?\\?&gt;', "language": PHP }, { "regEx": '&lt;\\?php\\n.*?\\n\\?&gt;', "language": PHP }, { "regEx": '&lt;\\?php\\r.*?\\r\\?&gt;', "language": PHP }, { "regEx": '&lt;\\? .*?\\?&gt;', "language": PHP }, { "regEx": '&lt;\\?\n.*?\\?&gt;', "language": PHP }, { "regEx": '&lt;\\?\r.*?\\?&gt;', "language": PHP }, { "regEx": '&lt;% .*?%&gt;', "language": ASP + "/" + JSP }, { "regEx": '&lt;%\n.*?%&gt;', "language": ASP + "/" + JSP }, { "regEx": '&lt;%\r.*?%&gt;', "language": ASP + "/" + JSP }, { "regEx": '&lt;%@ .*?%&gt;', "language": ASPX }, { "regEx": '&lt;%@\n.*?%&gt;', "language": ASPX }, { "regEx": '&lt;%@\r.*?%&gt;', "language": ASPX }, { "regEx": '&lt;asp:.*?%&gt;', "language": ASPX }, { "regEx": '&lt;jsp:.*?&gt;', "language": JSP }, { "regEx": '&lt;%! .*%&gt;', "language": JSP }, { "regEx": '&lt;%!\n.*%&gt;', "language": JSP }, { "regEx": '&lt;%!\r.*%&gt;', "language": JSP }, { "regEx": '&lt;%=.*%&gt;', "language": JSP + "/" + PHP + "/" + RUBY }, { "regEx": '&lt;!--\\s*%.*?%(--)?&gt;', "language": PHP }, { "regEx": '&lt;!--\\s*\?.*?\\?(--)?&gt;', "language": ASP + "/" + JSP }, { "regEx": '&lt;!--\s*jsp:.*?(--)?&gt;', "language": JSP }, { "regEx": '#include &lt;', "language": UNKNOWN }, { "regEx": '#!\/usr', "language": SHELL }, { "regEx": '#!\/bin', "language": SHELL }, { "regEx": 'import java\.', "language": JAVA }, { "regEx": 'public class .+\{', "language": JAVA }, { "regEx": 'package\s\w+\;', "language": JAVA }, { "regEx": '&lt;!--g:render', "language": GROOVY }, { "regEx": 'def .*?\(.*?\):\n', "language": PYTHON }, { "regEx": 'class .*?&lt; .*?end', "language": RUBY } ]; &nbsp; const BLACKLIST = ['xml', 'xpacket']; &nbsp; module.exports = class CheckCodeDisclosure extends Check { constructor(target) { super(CONSTANTS.TARGETTYPE.SERVER, CONSTANTS.CHECKFAMILY.SECURITY, false, true, target); } &nbsp; _check(cancellationToken, done) { var self = this; var timeout = 15000; request.get({ url: self.target.uri, timeout: timeout, cancellationToken: cancellationToken }, function (err, res, body) { if (self._handleError(err)) { done(); return; } &nbsp; for (let reg of SOURCE_CODE) { let matched = body.match(new RegExp(reg.regEx, 'i')); if (matched) { for (let blacklist_item in BLACKLIST) { if (matched[0].indexOf(blacklist_item) === -1) { if (res.statusCode === 404) { self._raiseIssue("code_disclosure.xml", self.target.uri, "There is a code disclosure in your custom 404 script at '" + res.request.uri.href + "'", true); done(); return; } else { self._raiseIssue("code_disclosure.xml", self.target.uri, reg.language + " tag non interpreted by browser at '" + res.request.uri.href + "'", true); done(); return; } } } } } done(); }); } };</pre></td></tr> </table></pre> <div class='push'></div><!-- for sticky footer --> </div><!-- /wrapper --> <div class='footer quiet pad2 space-top1 center small'> Code coverage generated by <a href="http://istanbul-js.org/" target="_blank">istanbul</a> at Thu Jan 12 2017 18:36:02 GMT+0100 (Paris, Madrid) </div> </div> <script src="../../../prettify.js"></script> <script> window.onload = function () { if (typeof prettyPrint === 'function') { prettyPrint(); } }; </script> <script src="../../../sorter.js"></script> </body> </html>