{"id":13844426,"url":"https://github.com/shengqi158/pyvulhunter","last_synced_at":"2025-07-11T22:32:00.710Z","repository":{"id":35595799,"uuid":"39868740","full_name":"shengqi158/pyvulhunter","owner":"shengqi158","description":"python audit tool 审计 注入 inject","archived":false,"fork":false,"pushed_at":"2016-02-25T08:41:11.000Z","size":365,"stargazers_count":179,"open_issues_count":0,"forks_count":59,"subscribers_count":7,"default_branch":"master","last_synced_at":"2024-08-05T17:41:45.739Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/shengqi158.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2015-07-29T02:28:14.000Z","updated_at":"2024-07-29T06:21:36.000Z","dependencies_parsed_at":"2022-09-02T15:51:09.884Z","dependency_job_id":null,"html_url":"https://github.com/shengqi158/pyvulhunter","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/shengqi158%2Fpyvulhunter","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/shengqi158%2Fpyvulhunter/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/shengqi158%2Fpyvulhunter/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/shengqi158%2Fpyvulhunter/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/shengqi158","download_url":"https://codeload.github.com/shengqi158/pyvulhunter/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225763413,"owners_count":17520455,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:02:42.123Z","updated_at":"2024-11-21T16:31:28.573Z","avatar_url":"https://github.com/shengqi158.png","language":"Python","funding_links":[],"categories":["Python","Python (1887)"],"sub_categories":[],"readme":"# python 代码审计工具readme\n\npython audit tool  \n\n---\n# 1,python的语法树  \n根据王垠的python静态分析工具[PySonar](https://github.com/yinwang0/pysonar2)得到静态语法树，这是一个庞大的dict结构，递归去除一些不必要的参数得到稍微简单点的一个语法树，以免影响后续分析。\n简单说明一下一个函数的实现，首先是”type”:”FunctionDef”表明这一段代码是函数定义，函数中则会有args，表明函数的参数，lineno是代码所在的行，name是函数名。更详细的接口文档见\nhttps://greentreesnakes.readthedocs.org/en/latest/nodes.html 在这里包含了各个结构的定义，分析整个树就可以依照这个来实现。\n# 2,基本原理\n\n基本实现原理就是寻找危险函数和可控参数,危险函数有eval,system,popen等系统函数，同时也有咱们自定义的包含这些危险函数的函数，如果这些函数的参数是可控的，就会认为这行代码是有注入风险的，那么这个函数也是有注入风险的.\n\n对于可控参数，首先会从函数参数入手，认为函数参数是可控的，分析程序会根据前面的语法树去分析代码结构，发现有将函数参数赋值的操作，并且这个赋值是简单的转换，这些简单的转换包含如下类型：\n  * （1） 简单的取属性，如get取值，对request单独处理，只认为GET,POST,FILES可控，其他request字段如META,user,session,url等都是不可控的。\n  * （2） 字符串拼接，被拼接的字符串中包含可控参数，则认为赋值后的值也是可控的\n  * （3） 列表解析式，如果列表解析式是基于某个可控因子进行迭代的，则认为赋值后的列表也是可控的\n  * （4） 分片符取值，一般认为分片后的值也是可控的，当然这个也不绝对。\n  * （5） 一般的函数处理过程：a,函数是常见的字符串操作函数（str，encode，strip等）或者是简单的未过滤函数；b,处理属性；c,如果经过了未知的函数处理则将赋值后的值从可控列表中去掉。\n  * （6） 如果代码中的if中有exists，isdigit等带可控参数的的return语句，则将该参数从可控参数列表中去掉（if not os.path.isdir(parentPath)：return None），或者将可控参数定死在某个范围之内的（if type not in [\"R\", \"B\"]：return HttpResponse(\"2\")）\n\n# 3,使用方法  \n  使用方法如下：\n$ python judge_injection.py -h\n  Usage: judge_injection.py [options]\n\n  Options:\n  -h, --help            show this help message and exit\n  -d FILE_PATH, --dir=FILE_PATH\n  files to be checked\n  -c, --cmd             cmd check\n  -s, --sql             sql check\n  -a, --all             cmd check and sql check\n  -v, --verbose         print all unsafe func\n\n默认是对所有情况进行检查，包括代码注入，sql注入，命令注入，xss注入，危险的文件操作等\n\n# 4,代码结构\njudge_injection类负责分析文件，得到一个python语法树，提炼出代码中包含的函数语句，分析每一行代码在碰到函数的时候会调用look_up_arg函数，该函数会得出函数中的可变变量，如果可变变量在危险函数中出现了就认为该外层调用函数是危险的。\n\n# 5,详细设计文档\n参见https://github.com/shengqi158/pyvulhunter/blob/master/python_audit.pdf\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fshengqi158%2Fpyvulhunter","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fshengqi158%2Fpyvulhunter","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fshengqi158%2Fpyvulhunter/lists"}