{"id":13821459,"url":"https://github.com/uber-archive/focuson","last_synced_at":"2025-05-16T12:33:26.861Z","repository":{"id":76800465,"uuid":"80828018","full_name":"uber-archive/focuson","owner":"uber-archive","description":"A tool to surface security issues in python code","archived":true,"fork":false,"pushed_at":"2017-04-20T15:54:40.000Z","size":176,"stargazers_count":226,"open_issues_count":0,"forks_count":29,"subscribers_count":1793,"default_branch":"master","last_synced_at":"2024-10-29T16:58:29.211Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/uber-archive.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2017-02-03T12:41:32.000Z","updated_at":"2024-09-10T03:47:01.000Z","dependencies_parsed_at":null,"dependency_job_id":"9b1fedac-c911-498c-b68a-c507203824e8","html_url":"https://github.com/uber-archive/focuson","commit_stats":null,"previous_names":["uber/focuson"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/uber-archive%2Ffocuson","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/uber-archive%2Ffocuson/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/uber-archive%2Ffocuson/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/uber-archive%2Ffocuson/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/uber-archive","download_url":"https://codeload.github.com/uber-archive/focuson/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":254530696,"owners_count":22086665,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T08:01:22.317Z","updated_at":"2025-05-16T12:33:26.247Z","avatar_url":"https://github.com/uber-archive.png","language":"Python","funding_links":[],"categories":["Python"],"sub_categories":[],"readme":"## Overview\n\nFocuson is an experimental tool to find security bugs in flask-based python\nweb applications. It will emit a list of places for a security engineer to \ninvestigate with a reasonable signal to noise ratio on account of using\ndataflow analysis. \n\nIt will require manual effort to find bugs in your environment but has been \nused to regularly find bugs by the Uber product security team in its \ncurrent state. \n\nIt uses dataflow analysis to model security flaws like xss as instances\nof a source (user input) flowing to a sink (dangerous function).\n\nWhile mostly useful primarily for flask + jinja apps it can be extended to \ninclude other frameworks. Focuson will be most useful not as a tool to be run \nonce but a framework upon which to build your own set of security rules\napplicable to your codebase. \n\nUber now uses focuson to automatically to surface probable security issues\nto the security team or, given high confidence, back to the engineer that wrote\nthe issue. \n\n\n##  Background\n\nFocuson was started as an experiment to find XSS in flask + jinja web \napplications at Uber. It ended up being useful so we have extended it a \nbit over time but it is still very raw. \n\nFocuson is a path-insensitive, inter-functional dataflow analysis engine. \n\nPath-insensitive = ignores the control flow (if/then/else/etc)\ninter-functional = \"tracks\" variables across functions, not just within\ndataflow analysis = \"follows\" variables through assignments, function calls,etc\n\nFocuson works by parsing the program into an abstract syntax tree, constructing\ncall and dataflow graphs then traversing them. This all ultimately rests on being\nable to predict ahead of time how the program runs, which we know is\nundecidable so focuson, and any program analysis tool, is best considered a\ncollection of approximations to mine insight into how the program will execute. \n\nThe expectation is focuson will show you areas a security engineer should\ninvestigate more deeply with a good signal to noise ration\n\nFocuson runs quickly, in testing taking ~15 sec for 100kb of python.\n\n## Installation\n1. cd focuson\n2. virtualenv venv\n3. source venv/bin/activate\n4. pip install -r requirements.txt\n5. python focuson.py \u003cdir\u003e\n\n\n## Usage\n1. source venv/bin/activate\n2. python focuson.py \u003cdir containting source code\u003e\n\n## Output\nThe output from focuson isn't exactly intuitive but follows the format of\n\n$variablename -\u003e [optional number of functions] -\u003e sink-y area of code\n\n$variablename is straightforward\n\nThe middle part is meant to show all the functions through which the tainted\nvariable passes en route to the sink. \n\nThe final section is the part of the code where the chain of taintedness ends.\n\nExample: mobileapp::fourth\nThis means in mobileapp.py, in the function fourth() exists a sink that\nfocuson believes constitutes a vulnerability.\n\nFor many more examples of output see the test directory and print out the\nvariables being asserted. \n\n## Examples\n\nWorlds simplest RCE in python:\n```\neval(request.args.get(\"foo\"))\n```\n\nMore complex\n```\nfoo = request.args.get(\"foo\")\neval(foo)\n```\n\nMore complex\n```\nfoo = request.args.get(\"foo\")\nbar = foo\neval(bar)\n```\n\nYet more complex:\n```\ndef func1(arg1):\n    eval(arg1)\nfoo = request.args.get(\"foo\")\nbar = foo\nfunc1(bar)\n```\n\nA good sized example is to run\n```\npython focuson.py tests/simple_4_hop/\n$android_deep_link -\u003e ['first_layer', 'second', 'third', 'fourth'] to second() in mobile_app::fourth\n```\nThe output here designates that the variable $android_deep_link is user-controlled and flows through those 4 functions on its path to the function second() which contains a vulnerable sink that absorbs what began as $android_deep_link which constitutes a potential vulnerability. \n\n\n## How to make focuson useful\nFocuson is customized for Uber's codebase.\n\nTo make it useful you will need to identify a relevant set of sources and sinks\nfor your codebase. Some of these are globally true and already built-in, \nlike eval() as a sink for RCE.\n\nIf you dont use flask you will need to determine how to model what \nuser-controlled input looks like for your codebase and add it as a source\n\nYou will need to do the same for sinks. \n\n## Improvements\nLots of additional good work to be done. \n- Adding additional sources and sinks\n- Refactoring sink() idea to generalized rule()\n- Make output less cryptic\n- Add support for web frameworks beyond flask\n\n## Inspiration\n* https://github.com/facebook/pfff\n* http://www.mlsec.org/joern/\n* https://github.com/openstack/bandit\n* http://simpsons.wikia.com/wiki/Focusyn\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fuber-archive%2Ffocuson","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fuber-archive%2Ffocuson","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fuber-archive%2Ffocuson/lists"}