UNPKG

sitecheck

Version:

Open Source web application security scanner

420 lines (419 loc) 14.6 kB
<!doctype html> <html lang="en"> <head> <title>Code coverage report for src\checks\server\check_error_pages.js</title> <meta charset="utf-8" /> <link rel="stylesheet" href="../../../prettify.css" /> <link rel="stylesheet" href="../../../base.css" /> <meta name="viewport" content="width=device-width, initial-scale=1"> <style type='text/css'> .coverage-summary .sorter { background-image: url(../../../sort-arrow-sprite.png); } </style> </head> <body> <div class='wrapper'> <div class='pad1'> <h1> <a href="../../../index.html">all files</a> / <a href="index.html">src/checks/server/</a> check_error_pages.js </h1> <div class='clearfix'> <div class='fl pad1y space-right2'> <span class="strong">100% </span> <span class="quiet">Statements</span> <span class='fraction'>24/24</span> </div> <div class='fl pad1y space-right2'> <span class="strong">100% </span> <span class="quiet">Branches</span> <span class='fraction'>16/16</span> </div> <div class='fl pad1y space-right2'> <span class="strong">100% </span> <span class="quiet">Functions</span> <span class='fraction'>3/3</span> </div> <div class='fl pad1y space-right2'> <span class="strong">100% </span> <span class="quiet">Lines</span> <span class='fraction'>24/24</span> </div> </div> </div> <div class='status-line high'></div> <pre><table class="coverage"> <tr><td class="line-count quiet">1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119</td><td class="line-coverage quiet"><span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes">32×</span> <span class="cline-any cline-yes">24×</span> <span class="cline-any cline-yes">24×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-yes">416×</span> <span class="cline-any cline-yes">312×</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-yes"></span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span> <span class="cline-any cline-neutral">&nbsp;</span></td><td class="text"><pre class="prettyprint lang-js">/** * @license Apache-2.0 * Copyright (C) 2016 The Sitecheck Project * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. * See the License for the specific language governing permissions and * limitations under the License. */ "use strict"; &nbsp; var Check = require('../../check'); var request = require('../../requestwrapper'); const CONSTANTS = require("../../constants.js"); &nbsp; const ERROR_PAGES = [ '&lt;H1&gt;Error page exception&lt;/H1&gt;', '&lt;span&gt;&lt;H1&gt;Server Error in ', '&lt;h2&gt; &lt;i&gt;Runtime Error&lt;/i&gt; &lt;/h2&gt;&lt;/span&gt;', '&lt;h2&gt; &lt;i&gt;Access is denied&lt;/i&gt; &lt;/h2&gt;&lt;/span&gt;', '&lt;H3&gt;Original Exception: &lt;/H3&gt;', 'Server object error', 'invalid literal for int()', 'exceptions.ValueError', '&lt;font face="Arial" size=2&gt;Type mismatch: ', '[an error occurred while processing this directive]', '&lt;HTML&gt;&lt;HEAD&gt;&lt;TITLE&gt;Error Occurred While Processing Request&lt;/TITLE&gt;', '&lt;/HEAD&gt;&lt;BODY&gt;&lt;HR&gt;&lt;H3&gt;Error Occurred While Processing Request&lt;/H3&gt;&lt;P&gt;', '&lt;p&gt;Microsoft VBScript runtime &lt;/font&gt;', "&lt;font face=\"Arial\" size=2&gt;error '800a000d'&lt;/font&gt;", '&lt;TITLE&gt;nwwcgi Error', '&lt;font face="Arial" size=2&gt;error \'800a0005\'&lt;/font&gt;', '&lt;h2&gt; &lt;i&gt;Runtime Error&lt;/i&gt; &lt;/h2&gt;&lt;/span&gt;', 'Operation is not allowed when the object is closed.', '&lt;p&gt;Active Server Pages&lt;/font&gt; &lt;font face="Arial" size=2&gt;error \'ASP 0126\'&lt;/font&gt;', '&lt;b&gt; Description: &lt;/b&gt;An unhandled exception occurred during the execution of the current web request', '] does not contain handler parameter named', '&lt;b&gt;Warning&lt;/b&gt;: ', 'No row with the given identifier', 'open_basedir restriction in effect', "eval()'d code&lt;/b&gt; on line &lt;b&gt;", "Cannot execute a blank command in", "Fatal error&lt;/b&gt;: preg_replace", "thrown in &lt;b&gt;", "#0 {main}", "Stack trace:", "&lt;/b&gt; on line &lt;b&gt;", "PythonHandler django.core.handlers.modpython", "t = loader.get_template(template_name) # You need to create a 404.html template.", '&lt;h2&gt;Traceback &lt;span&gt;(innermost last)&lt;/span&gt;&lt;/h2&gt;', '[java.lang.', 'class java.lang.', 'java.lang.NullPointerException', 'java.rmi.ServerException', 'at java.lang.', 'onclick="toggle(\'full exception chain stacktrace\')"', 'at org.apache.catalina', 'at org.apache.coyote.', 'at org.apache.tomcat.', 'at org.apache.jasper.', '&lt;h1 class="error_title"&gt;Ruby on Rails application could not be started&lt;/h1&gt;', '&lt;title&gt;Error Occurred While Processing Request&lt;/title&gt;&lt;/head&gt;&lt;body&gt;&lt;p&gt;&lt;/p&gt;', '&lt;HTML&gt;&lt;HEAD&gt;&lt;TITLE&gt;Error Occurred While Processing Request&lt;/TITLE&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;HR&gt;&lt;H3&gt;', '&lt;TR&gt;&lt;TD&gt;&lt;H4&gt;Error Diagnostic Information&lt;/H4&gt;&lt;P&gt;&lt;P&gt;', '&lt;li&gt;Search the &lt;a href="http://www.macromedia.com/support/coldfusion/" target="new"&gt;Knowledge Base&lt;/a&gt; to find a solution to your problem.&lt;/li&gt;', 'Server.Execute Error', '&lt;h2 style="font:8pt/11pt verdana; color:000000"&gt;HTTP 403.6 - Forbidden: IP address rejected&lt;br&gt;', '&lt;TITLE&gt;500 Internal Server Error&lt;/TITLE&gt;', ]; &nbsp; const VERSION_REGEX = [ { "regEx": '&lt;address&gt;(.*?)&lt;/address&gt;', "server": 'Apache' }, { "regEx": '&lt;HR size="1" noshade="noshade"&gt;&lt;h3&gt;(.*?)&lt;/h3&gt;&lt;/body&gt;', "server": "Apache Tomcat" }, { "regEx": '&lt;a href="http://www.microsoft.com/ContentRedirect.asp\?prd=iis&amp;sbp=&amp;pver=(.*?)&amp;pid=&amp;ID', "server": 'IIS' }, { "regEx": '&lt;b&gt;Version Information:&lt;/b&gt;&amp;nbsp;(.*?)\n', "server": 'ASP .NET' } ]; &nbsp; &nbsp; module.exports = class CheckErrorPages extends Check { constructor(target) { super(CONSTANTS.TARGETTYPE.SERVER, CONSTANTS.CHECKFAMILY.SECURITY, false, true, target); } &nbsp; _check(cancellationToken, done) { var self = this; var timeout = 3000; request.get({ url: self.target.uri, timeout: timeout, cancellationToken: cancellationToken }, function (err, res, body) { if (self._handleError(err)) { done(); return; } for (let reg in VERSION_REGEX) { if (400 &lt; parseInt(res.statusCode, 10) &amp;&amp; 600 &gt; parseInt(res.statusCode, 10)) { let matched = body.match(new RegExp(VERSION_REGEX[reg].regEx, 'i')); if (matched) { if (res.headers.server) self._raiseIssue("error_pages.xml", null, VERSION_REGEX[reg].server + " server found with version '" + res.headers.server + "' at Url '" + res.request.uri.href + "'", true); } } } &nbsp; for (let error in ERROR_PAGES) { if (400 &lt; parseInt(res.statusCode, 10) &amp;&amp; 600 &gt; parseInt(res.statusCode, 10)) { if (body.indexOf(ERROR_PAGES[error]) !== -1) { self._raiseIssue("error_pages.xml", null, "Descriptive error page found at Url '" + res.request.uri.href + "'", true); } } } done(); }); } };</pre></td></tr> </table></pre> <div class='push'></div><!-- for sticky footer --> </div><!-- /wrapper --> <div class='footer quiet pad2 space-top1 center small'> Code coverage generated by <a href="http://istanbul-js.org/" target="_blank">istanbul</a> at Thu Jan 12 2017 18:36:02 GMT+0100 (Paris, Madrid) </div> </div> <script src="../../../prettify.js"></script> <script> window.onload = function () { if (typeof prettyPrint === 'function') { prettyPrint(); } }; </script> <script src="../../../sorter.js"></script> </body> </html>