锋盈数科-知识库 Logo
首页
软件开发
计算机基础
Hello Halo
新手必读
关于本知识库
登录 →
锋盈数科-知识库 Logo
首页 软件开发 计算机基础 Hello Halo 新手必读 关于本知识库
登录
  1. 首页
  2. 软件开发
  3. jacodb污点配置类名与代码中不一致问题

jacodb污点配置类名与代码中不一致问题

0
  • 软件开发
  • 发布于 2024-09-21
  • 0 次阅读
黄健
黄健

问题

有如下测试代码:

java代码:

    @Override
    public void doPost(HttpServletRequest request, HttpServletResponse response)
            throws ServletException, IOException {
        String param = request.getHeader("BenchmarkTest00008");
        try {
            java.sql.Connection connection = DriverManager.getConnection("jdbc:mysql://localhost:3306/testdb", "root", "password");
            java.sql.CallableStatement statement = connection.prepareCall(param);
            java.sql.ResultSet rs = statement.executeQuery();
        } catch (java.sql.SQLException e) {
            throw new ServletException(e);
        }
    }

污点配置:

[
  {
    "_": "MethodSource",
    "methodInfo": {
      "cls": {
        "packageMatcher":{"_":"NameIsEqualTo","name":"javax.servlet.http"},
        "classNameMatcher":{"_":"NameIsEqualTo","name":"HttpServletRequest"}
      },
      "functionName": {"_":"NameIsEqualTo","name":"getHeader"},
      "parametersMatchers": [],
      "returnTypeMatcher": {"_":"AnyTypeMatches"},
      "applyToOverrides": true,
      "functionLabel": null,
      "modifier": -1,
      "exclude": []
    },
    "condition": {"_":"ConstantTrue"},
    "actionsAfter": [
      {"_":"AssignMark","mark":{"name":"UNTRUSTED"},"position":{"_":"Result"}}
    ]
  },
  {
    "_": "PassThrough",
    "methodInfo": {
      "cls": {
        "packageMatcher":{"_":"NameIsEqualTo","name":"java.sql"},
        "classNameMatcher":{"_":"NameIsEqualTo","name":"Connection"}
      },
      "functionName": {"_": "NameIsEqualTo","name": "prepareCall"},
      "parametersMatchers": [],
      "returnTypeMatcher": {"_": "AnyTypeMatches"},
      "applyToOverrides": true,
      "functionLabel": null,
      "modifier": -1,
      "exclude": []
    },
    "condition": {
      "_": "Or",
      "args": [
        {"_":"ContainsMark","mark":{"name":"UNTRUSTED"},"position":{"_":"Argument","number":0}},
        {"_":"ContainsMark","mark":{"name":"ENVIRONMENT"},"position":{"_":"Argument","number":0}}
      ]
    },
    "actionsAfter": [
      {"_":"CopyAllMarks","from":{"_":"Argument","number":0},"to":{"_":"Result"}}
    ]
  },
  {
    "_": "MethodSink",
    "ruleNote": "SQL-Injection",
    "cwe": [89],
    "methodInfo": {
      "cls": {
        "packageMatcher": {"_": "NameIsEqualTo","name": "java.sql"},
        "classNameMatcher": {"_": "NameMatches","pattern": "CallableStatement"}
      },
      "functionName": {"_":"NameMatches","pattern":"executeQuery"},
      "parametersMatchers": [],
      "returnTypeMatcher": {"_":"AnyTypeMatches"},
      "applyToOverrides": true,
      "functionLabel": null,
      "modifier": -1,
      "exclude": []
    },
    "condition": {
      "_": "Or",
      "args": [
        {
          "_": "ContainsMark",
          "position": {
            "_": "This"
          },
          "mark": {
            "name": "UNTRUSTED"
          }
        }
      ]
    }
  }
]

解决过程

测试代码,都是按照代码配置的规则,而且规则也比较简单。但是在测试时就是不报问题,检查了很多遍规则都没发下什么问题。加上了new edge的日志输出,内容如下:

NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=noop, fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=noop, fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%0 = request.getHeader("BenchmarkTest00008"), fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=this.doPost(request, response), fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%2 = java.sql.DriverManager.getConnection("jdbc:mysql://localhost:3306/testdb", "root", "password"), fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%2 = java.sql.DriverManager.getConnection("jdbc:mysql://localhost:3306/testdb", "root", "password"), fact=Tainted(variable=%0, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=return, fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%4 = %2.prepareCall(%0), fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=catch (%9: java.sql.SQLException), fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%4 = %2.prepareCall(%0), fact=Tainted(variable=%0, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=catch (%9: java.sql.SQLException), fact=Tainted(variable=%0, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%6 = %4.executeQuery(), fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%11 = new javax.servlet.ServletException, fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%6 = %4.executeQuery(), fact=Tainted(variable=%0, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%6 = %4.executeQuery(), fact=Tainted(variable=%4, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=catch (%9: java.sql.SQLException), fact=Tainted(variable=%4, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%11 = new javax.servlet.ServletException, fact=Tainted(variable=%0, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=goto JcInstRef(index=9), fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%11.<init>(%9), fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=goto JcInstRef(index=9), fact=Tainted(variable=%0, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=goto JcInstRef(index=9), fact=Tainted(variable=%4, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%11 = new javax.servlet.ServletException, fact=Tainted(variable=%4, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%11.<init>(%9), fact=Tainted(variable=%0, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=return, fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=throw %11, fact=Zero))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=return, fact=Tainted(variable=%0, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=return, fact=Tainted(variable=%4, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%11.<init>(%9), fact=Tainted(variable=%4, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=throw %11, fact=Tainted(variable=%0, mark=UNTRUSTED)))
NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=throw %11, fact=Tainted(variable=%4, mark=UNTRUSTED)))

从该条edge处理可以看出,污点已经传播到了%4变量,就是源码中的statement,而且标的也是"UNTRUSTED”,和MethodSink中配置的一致,只是结果没报问题。

NewEdge=Edge(from=Vertex(statement=noop, fact=Zero), to=Vertex(statement=%6 = %4.executeQuery(), fact=Tainted(variable=%4, mark=UNTRUSTED)))

后面拿源码一步一步debug,发现根据污点配置匹配MethodSink时,源码中的statement类型变成了PreparedStatement,而看代码应该是CallableStatement 。

java.sql.CallableStatement statement = connection.prepareCall(param);
java.sql.ResultSet rs = statement.executeQuery();

将MethodSink中的类名匹配给为"PreparedStatement"后,终于报出了问题。

(TaintAnalyzers.kt:76)- Found sink=Vertex(statement=%6 = %4.executeQuery(), fact=Tainted(variable=%4, mark=UNTRUSTED)) in (id:72)org.owasp.benchmark.testcode.BenchmarkTest00008#doPost(javax.servlet.http.HttpServletRequest, javax.servlet.http.HttpServletResponse)

此处也可以改成Statement,结合applyToVverrides参数设置为True,所有实现了Statement接口的类都可以匹配上了。

MethodSink配置改为

{
    "_": "MethodSink",
    "ruleNote": "SQL-Injection",
    "cwe": [89],
    "methodInfo": {
      "cls": {
        "packageMatcher": {"_": "NameIsEqualTo","name": "java.sql"},
        "classNameMatcher": {"_": "NameMatches","pattern": "Statement"}
      },
      "functionName": {"_":"NameMatches","pattern":"executeQuery"},
      "parametersMatchers": [],
      "returnTypeMatcher": {"_":"AnyTypeMatches"},
      "applyToOverrides": true,
      "functionLabel": null,
      "modifier": -1,
      "exclude": []
    },
    "condition": {
      "_": "Or",
      "args": [
        {
          "_": "ContainsMark",
          "position": {
            "_": "This"
          },
          "mark": {
            "name": "UNTRUSTED"
          }
        }
      ]
    }
  }

最终原因猜测

Statement 和 PreparedStatement 以及 CallableStatement的关系为:

public interface CallableStatement extends PreparedStatement {
```java
public interface PreparedStatement extends Statement {
```
三个接口依次继承,后面发现只有PreparedStatement定义了executeQuery()方法,CallableStatement没有executeQuery方法,Statement中定义的是executeQuery(String sql),这就解析了为什么上面statement的类为PreparedStatement。

所有后续污点配置中需要关注类的层级问题,可以使配置文件精简一些,也可以避免配置错误。

原文链接: https://blog.csdn.net/javajingling/article/details/141028097

标签: #软件开发 1171
相关文章

万字:支付“核心系统”详解 2024-11-02 15:33

专栏作者:隐墨星辰 \| 主编:陈天宇宙 这篇文章也尝试化繁为简,探寻支付系统的本质,讲清楚在线支付系统最核心的一些概念和设计理念。 虽然支付行业已经过了风头最劲的时光,但跨境支付仍然在蓬勃发展,每年依然有很多新人进入这个行业,这篇文章尝试为这些刚入行的新人提供一点帮助。 文章只介绍一些支付行业十几

资深支付架构师视角:实战从问题定义到代码落地的完整套路 2024-11-02 15:33

前言 今天从一个实际案例入手,介绍站在架构师的角度,如何识别并定义问题,提炼需求,技术方案选型,再到详细设计,最后利用AI的能力协助写出核心的代码,验证与调优。 解决问题存在一定的模式,也可以称之为框架,总结出自己的思考和解题框架,以后再碰到同类型的问题就可以如庖丁解牛一样容易。 很多年前,我写代码

Spring 实现 3 种异步接口 2024-10-18 09:07

大家好,我是苏三~ 如何处理比较耗时的接口? 这题我熟,直接上异步接口,使用 Callable、WebAsyncTask 和 DeferredResult、CompletableFuture等均可实现。 但这些方法有局限性,处理结果仅返回单个值。在某些场景下,如果需要接口异步处理的同时,还持续不断地

重学SpringBoot3-集成Redis(五)之布隆过滤器 2024-10-08 11:24

更多SpringBoot3内容请关注我的专栏:《SpringBoot3》 期待您的点赞👍收藏⭐评论✍ 重学SpringBoot3-集成Redis(五)之布隆过滤器 1. 什么是布隆过滤器? * 基本概念 适用场景 2. 使用 Redis 实现布隆过滤器 * 项目依赖 Redis 配置

设计模式第16讲——迭代器模式(Iterator) 2024-10-08 11:24

一、什么是迭代器模式 迭代器模式是一种行为型设计模式,它提供了一种统一的方式来访问集合对象中的元素,而不是暴露集合内部的表示方式。简单地说,就是将遍历集合的责任封装到一个单独的对象中,我们可以按照特定的方式访问集合中的元素。 二、角色组成 抽象迭代器(Iterator):定义了遍历聚合对象所需的方法

vue2路由和vue3路由区别及原理 2024-10-08 11:24

一、Vue2 与 Vue3 路由的区别 1. 创建路由实例方式的不同 Vue 2 中,通过 Vue.use() 注册路由插件,并通过 new VueRouter() 来创建路由实例。 import Vue from 'vue';import VueRouter from 'vue-router';i

目录

IT 外包服务商

  • 意见投递
  • zyf6619

软件开发应用

主菜单

  • 首页
  • 软件开发
  • 计算机基础
  • Hello Halo
  • 新手必读
  • 关于本知识库
Copyright © 2024 your company All Rights Reserved. Powered by Halo.