forked from bl4de/security-tools
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdetection_engine.py
More file actions
173 lines (143 loc) · 5.89 KB
/
Copy pathdetection_engine.py
File metadata and controls
173 lines (143 loc) · 5.89 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
#!/usr/bin/python
"""HTML source analyzer
bl4de | bloorq@gmail.com | Twitter: @_bl4de | H1: bl4de
This tool goes through HTML document and shows all interesting places,
like inline JavaScript calls, commented paths, 'debug' and similar
words occurences, possible DOM Injection points, references to
resources like images or iframes
detection_engine.py contains all specific logic which detects interesting
parts of HTML
"""
from console_output_beautifier import ConsoleOutputBeautifier
from utils import print_output_line
# @TODO: libraries/framework detection
# detects frontend framework used
line_cache = []
def get_line(_line, _line_number, _chars=80):
"""returns formatted line to print"""
return (_line_number, ConsoleOutputBeautifier.getColor("grey"), '\n\t\t'
+ _line.lstrip().rstrip()[0:_chars])
def detect_framework(_line):
"""frontend framework detection (simplified)
WARNING!!!
This detection is only some assumption based on some constant
elements but can not be treat as 100% sure.
"""
_fw = ""
if "ng-app" or "angular.js" or "angular.min.js" in _line:
_fw = "Angular 1.*"
if "react.js" in _line or "react-dom.js" in _line:
_fw = "ReactJS"
return _fw
def identify(_line):
"""backend detection (simplified)"""
_ident = "unknown"
if "Joomla" in _line:
_ident = "Joomla CMS"
if "wp-content" in _line:
_ident = "WordPress CMS"
if 'content="Drupal"' in _line:
_ident = "Drupal CMS"
return _ident
def detect_developer_comments(_line, i):
"""detection of comments left by developers"""
developer_comments = [
'bug',
'problem',
'issue',
'fix',
'ticket',
'bad',
'todo',
'inject',
'crash',
'trust',
'dev',
'temporary',
'remove'
]
for developer_comment in developer_comments:
if developer_comment in _line.lower():
print_output_line(i, ConsoleOutputBeautifier.getColor("yellow"),
"probably developer(s) related comment string found at line %d: %s %s",
get_line(_line, i, 120), "DOM BASED XSS")
def detect_dombased_xss(_line, i):
"""detection of DOM based XSS weaknesses"""
dombased_calls = [
'document.location',
'document.url',
'document.urlencoded',
'document.referrer',
'window.location',
'document.write(',
'document.writeln('
'.innerHTML',
'eval(',
'setInterval(',
'setTimeout(',
'Function('
]
for dombased_call in dombased_calls:
if dombased_call in _line:
print_output_line(i, ConsoleOutputBeautifier.getColor("red"),
"POSSIBLE DOM BASED INJECTION POINT found at line %d: %s %s",
get_line(_line, i, 120), "DOM BASED XSS")
def detect_ajax_calls(_line, i):
ajax_calls = [
'$.ajax',
'$.getJSON',
'$http.'
]
for call in ajax_calls:
if call in _line:
print_output_line(i, ConsoleOutputBeautifier.getColor("red"),
"AJAX CALL (possible REST endpoint revealed) at line %d: %s %s",
get_line(_line, i, 120), "AJAX/REST CALL")
def detect_comments(_line, i):
"""detects comments"""
if '<!--' in _line.lstrip():
if "\"/" in _line:
print_output_line(i, ConsoleOutputBeautifier.getColor("red"),
"COMMENTED PATH found at line %d: %s %s",
get_line(_line, i, 120), "COMMENT")
else:
print_output_line(i, ConsoleOutputBeautifier.getColor("yellow"),
"COMMENT found at line %d: %s %s",
get_line(_line, i, 120), "COMMENT")
def detect_admin_stuff(_line, i):
"""detects anything related to administration area"""
if "admin" in _line.lower():
print_output_line(i, ConsoleOutputBeautifier.getColor("red"),
"'admin' string found at line: %d: %s %s",
get_line(_line, i, 120), "ADMIN")
def detect_debug(_line, i):
"""detects debug messages left by developers"""
if "debug" in _line.lower():
print_output_line(i, ConsoleOutputBeautifier.getColor("red"),
"DEBUG information found at line %d", i, "DEBUG")
def detect_external_resources(_line, i):
"""detects external resources like imgs, iframes, scripts"""
if "src" in _line:
if "<img" in _line:
print_output_line(i, ConsoleOutputBeautifier.getColor("cyan"),
"PATH to external resource image "
" file found in %d: %s %s",
get_line(_line, i, 120), "RESOURCES")
if "<iframe" in _line:
print_output_line(i, ConsoleOutputBeautifier.getColor("cyan"),
"IFRAME path found in %d: %s %s",
get_line(_line, i, 120), "RESOURCES")
if "<script" in _line:
print_output_line(i, ConsoleOutputBeautifier.getColor("cyan"),
"external SCRIPT path found in %d: %s %s",
get_line(_line, i, 120), "RESOURCES")
def detect_javascript(_line, i):
"""detects inline JavaScript occurences, as a script or event handler
inside HTML tag"""
if "<script" in _line and "src" not in _line:
print_output_line(i, ConsoleOutputBeautifier.getColor("green"),
"inline <SCRIPT> tag found at line %d", i, "SCRIPT")
if "javascript:" in _line:
print_output_line(i, ConsoleOutputBeautifier.getColor("cyan"),
"INLINE JavaScript event handler found at line %d", i,
"JAVASCRIPT")