{"id":13841106,"url":"https://github.com/cdaller/security_taint_propagation","last_synced_at":"2025-07-11T11:32:51.273Z","repository":{"id":4662559,"uuid":"5808486","full_name":"cdaller/security_taint_propagation","owner":"cdaller","description":"Java taint propagation for java. Define tainted sources, sanitizer methods and sinks via aspects.","archived":false,"fork":false,"pushed_at":"2018-10-11T07:28:40.000Z","size":225,"stargazers_count":27,"open_issues_count":0,"forks_count":10,"subscribers_count":5,"default_branch":"master","last_synced_at":"2024-11-21T11:38:29.465Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/cdaller.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"security_taint_extension/.classpath","support":null}},"created_at":"2012-09-14T11:32:23.000Z","updated_at":"2024-09-12T21:11:18.000Z","dependencies_parsed_at":"2022-07-05T13:09:30.074Z","dependency_job_id":null,"html_url":"https://github.com/cdaller/security_taint_propagation","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/cdaller/security_taint_propagation","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cdaller%2Fsecurity_taint_propagation","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cdaller%2Fsecurity_taint_propagation/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cdaller%2Fsecurity_taint_propagation/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cdaller%2Fsecurity_taint_propagation/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/cdaller","download_url":"https://codeload.github.com/cdaller/security_taint_propagation/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cdaller%2Fsecurity_taint_propagation/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":264795402,"owners_count":23665231,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:01:02.734Z","updated_at":"2025-07-11T11:32:49.375Z","avatar_url":"https://github.com/cdaller.png","language":"Java","funding_links":[],"categories":["Java","Java (504)"],"sub_categories":[],"readme":"# Dynamic Security Taint Propagation in Java via Java Aspects\n\nThis project defines some java aspects that allow to follow tainted strings from a\nsource to a sink to find security leaks in software (SQL-Injection, Cross-Site-Scripting (XSS)).\n\nTherefore the ```java.lang.String``` class is extended with a \"tainted\" flag. This flag is\nset on all strings that come from defined sources (e.g. ```HttpServletRequest.getParameter()```)\nand passed to all strings that use the tainted string (e.g. ```String foo = \"foo\" + tainted;```\nresults in tainted foo). When a tainted string reaches a sink, the system can react in\ndifferent ways (log message, throw exception, ...).\n\nSome \"cleaner\" or \"sanitizer\" methods can be used to remove the tainted flag. E.g. when\nyou want to protect your application from XSS, a cleaner method would escape all\ncharacters that may be interpreted by the browser (especially the \"\u003c\" sign).\n\nChristof Dallermassl (christof at dallermassl dot at)\n\n## Background knowledge\n\nI found some papers about this topic:\n* [Vivek Haldar, Deepak Chandra, Michael Franz: Dynamic Taint Propagation for Java](http://www.acsac.org/2005/papers/45.pdf)\n* [A presentation at blackhat security conference](http://www.blackhat.com/presentations/bh-dc-08/Chess-West/Presentation/bh-dc-08-chess-west.pdf)\n* [Towards Fully Automatic Placement of Security\nSanitizers and Declassifiers](http://research.microsoft.com/en-us/um/people/livshits/papers/tr/autosani_tr.pdf)\n* [Meder Kydyraliev and Josh Deprez: Gravizapa - Ruby and Java Taint Propagation using agent transformations](http://conference.hitb.org/hitbsecconf2012kul/materials/D1T2%20-%20Meder%20Kydyraliev%20-%20Defibrilating%20Web%20Security.pdf)\n\n### Other projects\n\n* [Taint propagation in python](https://github.com/felixgr/pytaint/)\n\n## Note\nThis project is probably not stable for production systems but works quite well in development environment!\n\nEveryone is welcome to help to improve this project!\n\n## Quickstart\n\n* Clone the project from github\n* ```mvn install``` in the top level directory of the project\n* change to the project ```security_taint_webapp```\n* ```mvn jetty:run-forked``` starts a webserver \n* browse to http://localhost:8080/taintwebapp\n* enter some values in the input fields and push the button\n* check the console where you started jetty for some warnings about tainted values in jsp page!\n  * warnings show that some user input (tainted) is output to the web page without sanitation! This\n    could be used for an XSS hacker attack.\n\n## There are multiple parts in this project\n* **security_taint_extension**: contains aspects that extend java.lang.String (add property\n  \"tainted\"). Therefore you need to weave the new aspect into the jdk's rt.jar (on OSX's\n  1.6 jdk it is named classes.jar) and create a new \"tainted-rt.jar\". This new jar is\n  used in the bootclasspath of all projects that use the aspects (and the application\n  itself as well!).\n* **security_taint_propagation**: holds aspects that propagate the tainted flag from\n  String to StringBuffer and StringBuilder objects (e.g. copy a tainted String into\n  a StringBuilder, the new StringBuilder has to be flagged as tainted as well).\n  Additionally it holds some definitions of sinks and sources.\n* **security_taint_propagation_http**: holds taint sources and sinks for web applications\n* **security_taint_webapp**: very simple example webapp that demonstrates sources, sinks\n  and sanitation of tainted strings. It can either be started from a maven jetty with \n  ```mvn jetty:run-forked``` or deployed to an an instrumented tomcat\n  server (see Readme.md in the project).\n\n## Eclipse setup\nThe projects can be used as maven nature projects. Beware that the tainted-rt-1.x.jar\nalways comes before the system lib (jre lib) as otherwise the java.lang.String modification\nwill not be found! Use the projects properties, \"Java Build Path\"/\"Order and Export\" to put the\n\"JRE System Library\" to the bottom. This needs to be done every time after \"Maven/Update Project\"\nwas executed.\n\nSet the default jre to 1.8 (project also works with java 1.6 and java 1.7 - change in parent pom.xml if needed).\n\nDo a ```mvn package``` first, so the modified tainted-rt-1.8.jar will be found in eclipse.\n\nPlease note that the security_taint_extension project will not build correctly in eclipse, as\nit needs the modified rt.jar which it produces (hen/egg problem). In maven it works.\nUse maven to package.\n\nAdd the aspect-Nature to the project: Right click on project, Configure, Convert to AspectJ Project\n\nIf you cannot start any unit tests in eclipse after modification in the aspects, remove all\nRun-Configurations of the tests!\n\nSometimes eclipse gets confused and reports hundreds of errors:\n* delete the files .classpath and .project\n* in eclipse update maven nature: Maven/Update Project\n* move the JRE System Library to the bottom (Properties/Java Build Path/Order and Export)\n* remove AspectJ Nature and add it again\n\n## Working with Taint Propagation\n\n### Tomcat setup\nSome libraries are needed to \"arm\" tomcat:\n* the load time weaver of aspectj (as a java agent on startup)\n* the aspectj runtime jar (aspectjrt-\u003cversion\u003e.jar)\n* the modified String class (in tainted-rt.jar) as bootclasspath (replaces the original rt.jar from the jdk)\n* the aspect that ensures that the tainted flag is propagated on string operations (security.taint.propagation-\u003cversion\u003e.jar) and also contains the sink for sql classes (prevening sql injection attacks).\n* the aspect instrumenting http sources and sinks (security.taint.propagation.http-\u003cversion\u003e.jar)\n\nIf you want to start tomcat in eclipse with taint propagation you have to\n\n1. create a new tomcat server named \"Tomcat 8 tainted\" (or similar)\n2. start tomcat once (to get an entry in \"Run/Debug configurations\")\n3. settings in \"Run/Debug configurations\"\n  * Arguments:\n```\n-Xbootclasspath/p:D:/PATH_TO/tainted-rt-1.8.jar\n-javaagent:D:/PATH_TO/aspectjweaver-1.8.8.jar\n```\n  * Classpath tab: Add the two jar files in \"User Entries\": security.taint.propagation-VERSION.jar, security.taint.propagation.http-VERSION.jar\n\nIf you want to start a stand-alone tomcat with taint propagation you have to:\n\nfirst create a setenv.sh/setenv.bat file to add the neccessary jars.\nsetenv.bat:\n\n```\nrem setenv.bat: adding taint propagation to tomcat: \n\nset BASE_DIR=\u003cpath_to_this_directory\u003e/security_taint_propagation\nset MAVEN_REPO=F:/work/m2repo\nset ASPECTJ_VERSION=1.8.8\n\nset JAVA_OPTS=-Xbootclasspath/p:%BASE_DIR%/security_taint_extension/target/tainted-rt-1.8.jar %JAVA_OPTS%\nset JAVA_OPTS=-javaagent:%MAVEN_REPO%/org/aspectj/aspectjweaver/%ASPECTJ_VERSION%/aspectjweaver-%ASPECTJ_VERSION%.jar %JAVA_OPTS%\n\nset JAVA_OPTS=-Xms256m -Xmx1800M -XX:MaxPermSize=256m %JAVA_OPTS%\n\nset JAVA_ENDORSED_DIRS=%MAVEN_REPO%/org/aspectj/aspectjrt/%ASPECTJ_VERSION%/;%JAVA_ENDORSED_DIRS%\nset JAVA_ENDORSED_DIRS=%BASE_DIR%/security_taint_propagation_http/target/;%JAVA_ENDORSED_DIRS%\nset JAVA_ENDORSED_DIRS=%BASE_DIR%/security_taint_propagation/target/;%JAVA_ENDORSED_DIRS%\n\nrem set JAVA_ENDORSED_DIRS=%BASE_DIR%/security_taint_propagation_safehtml/target;%JAVA_ENDORSED_DIRS%\n```\nsetenv.sh is similar :-)\n\nthen start tomcat as usual\n\n### Output\nThe tools are configured to print a warning to system.out whenever a security leak was detected (line breaks added for better readability):\n```\nSECURITY-TAINT-WARNING: Tainted value will be used in a sink![\n  type: XSS, sink code: org.apache.jsp.xxx.jsp:136/call(JspWriter.print(..)),\n  tainted sources: JDBC Sql Result Set(5),\n  value: '\u003cTABLE\u003e\u003ctr\u003e\u003ctd\u003eHugo von Hofmannsthal\u003c/td\u003e\u003c/tr\u003e\u003c/TABLE\u003e'\n]\n```\nThis means that a tainted string (coming from a insecure source (user input, database)) was detected to be used in a defined sink (jsp writer, database query).\n\n## Problems\nSome problems make working with taint propagation sometimes cumbersome:\n* If a jsp page is the sink (JSP Writer) only the line number in the compiled jsp servlet is printed. So the developer has to find the java code of the jsp page, find the code and then try to find the corresponding line in the jsp file. In eclipse the java classes are placed into $ECLIPSE_WORKSPACE/.metadata/.plugins/org.eclipse.wst.server.core/tmpX/work/Catalina/localhost/$WEBAPPNAME/org/apache/jsp\n* The final tainted string is sometimes a concatenation of lots of parts and it is sometimes difficult to find the tainted string.\n* It would be helpful to see the different tainted parts of the final string and their way through the code to detect if there really is a security leak or not.\n* The project does not work with java 9 or newer because the project modifies the rt.jar file, which was removed in java9 and newer - if someone likes to provide a solution for that, please to not hesitate to contact me.\n\nApart from that the tool works quite reliable.\n\n## License\nThis project is licensed under [Apache 2.0](http://opensource.org/licenses/apache2.0)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcdaller%2Fsecurity_taint_propagation","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcdaller%2Fsecurity_taint_propagation","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcdaller%2Fsecurity_taint_propagation/lists"}