/
JSWindowsOpenReaderObserver.java
128 lines (107 loc) · 3.93 KB
/
JSWindowsOpenReaderObserver.java
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
package com.github.adriancitu.burp.tabnabbing.parser;
import com.github.adriancitu.burp.tabnabbing.scanner.IssueType;
import com.github.adriancitu.burp.tabnabbing.util.HtmlByteArrayUtility;
import java.util.Objects;
import java.util.Optional;
import java.util.logging.Level;
import java.util.logging.Logger;
/**
* Observer that is able to find JavaScript "<script>" tag and
* "window.open" call inside a code block.
*/
public class JSWindowsOpenReaderObserver extends AbstractObserver {
private static final Logger LOGGER =
Logger.getLogger(JSWindowsOpenReaderObserver.class.getName());
private boolean scriptTagFound = false;
private boolean windowsOpenFound = false;
public JSWindowsOpenReaderObserver(boolean noReferrerHeaderPresent1) {
super(noReferrerHeaderPresent1);
}
@Override
public void handleByte(IByteReader byteReader, byte toHandle) {
try {
if (problemFound()) {
return;
}
//<
handle60dByte(byteReader, toHandle);
//w or W
if (scriptTagFound
&& (toHandle == 119d //w
|| toHandle == 87d) //W
) {
final byte[] next11Bytes = byteReader.fetchMoreBytes(10);
if ("indow.open".equalsIgnoreCase(new String(next11Bytes))) {
windowsOpenFound = true;
getBuffer().add(toHandle);
return;
}
}
if (windowsOpenFound) {
getBuffer().add(toHandle);
//;
if (toHandle == 59d) {
if (HtmlByteArrayUtility
.tabNabbingProblemFound(
HtmlByteArrayUtility
.fromByteListToByteArray(getBuffer())
)) {
setProblemFound(true);
} else {
this.close();
}
}
}
} catch (RuntimeException e) {
this.close();
LOGGER.log(Level.WARNING, e.getMessage(), e);
}
}
private void handle60dByte(IByteReader byteReader, byte toHandle) {
if (toHandle == 60d) {
final byte[] next7Bytes = byteReader.fetchMoreBytes(7);
if ("script>".equalsIgnoreCase(new String(next7Bytes))) {
scriptTagFound = true;
return;
}
if (scriptTagFound) {
final byte[] next8Bytes = byteReader.fetchMoreBytes(8);
if ("/script>".equalsIgnoreCase(new String(next8Bytes))) {
scriptTagFound = false;
}
}
}
}
@Override
public Optional<TabNabbingProblem> getProblem() {
if (problemFound()) {
return Optional.of(
new TabNabbingProblem(
isNoReferrerHeaderPresent() ?
IssueType.JAVASCRIPT_WIN_OPEN_REFERRER_POLICY_HEADER :
IssueType.JAVASCRIPT_WIN_OPEN_NO_REFERRER_POLICY_HEADER
,
getProblemAsString()));
} else {
return Optional.empty();
}
}
@Override
public void close() {
super.close();
this.windowsOpenFound = false;
this.scriptTagFound = false;
}
@Override
public boolean equals(Object o) {
if (this == o) return true;
if (!(o instanceof JSWindowsOpenReaderObserver)) return false;
JSWindowsOpenReaderObserver that = (JSWindowsOpenReaderObserver) o;
return scriptTagFound == that.scriptTagFound &&
windowsOpenFound == that.windowsOpenFound;
}
@Override
public int hashCode() {
return Objects.hash(scriptTagFound, windowsOpenFound);
}
}