Skip to content

Commit

Permalink
Merge pull request #308 from lunasec-io/add-jar-patcher
Browse files Browse the repository at this point in the history
Add jar patcher command to log4shell cli
  • Loading branch information
breadchris committed Dec 27, 2021
2 parents eda04aa + 449f700 commit 74e545a
Show file tree
Hide file tree
Showing 21 changed files with 1,160 additions and 821 deletions.
1 change: 1 addition & 0 deletions .idea/vcs.xml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion tools/log4shell/Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ payload:

cli:
touch ${LIBRARY_HASHES}
go build -o ${BINARY_NAME} .
CGO_ENABLED=0 GOOS=linux go build -o ${BINARY_NAME} .

library-hashes: cli
./log4shell analyze --output ${LIBRARY_HASHES} test/vulnerable-log4j2-versions/apache test/vulnerable-log4j2-versions/target/dependency
Expand Down
54 changes: 46 additions & 8 deletions tools/log4shell/analyze/analyze.go
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@
package analyze

import (
"archive/zip"
"github.com/blang/semver/v4"
"github.com/lunasec-io/lunasec/tools/log4shell/constants"
"github.com/lunasec-io/lunasec/tools/log4shell/types"
Expand Down Expand Up @@ -96,7 +97,35 @@ func fileNameToSemver(fileNameNoExt string) string {
return semverVersion
}

func ProcessArchiveFile(reader io.Reader, filePath, fileName string) (finding *types.Finding) {
func GetJndiLookupHash(zipReader *zip.Reader, filePath string) (fileHash string) {
reader, err := zipReader.Open(constants.JndiLookupClasspath)
if err != nil {
log.Debug().
Str("fieName", constants.JndiLookupClasspath).
Str("path", filePath).
Err(err).
Msg("cannot find file in zip")
return
}
defer reader.Close()

fileHash, err = util.HexEncodedSha256FromReader(reader)
if err != nil {
log.Debug().
Str("fieName", constants.JndiLookupClasspath).
Str("path", filePath).
Err(err).
Msg("unable to hash JndiLookup.class file")
return
}
return
}

func ProcessArchiveFile(zipReader *zip.Reader, reader io.Reader, filePath, fileName string) (finding *types.Finding) {
var (
jndiLookupFileHash string
)

_, file := path.Split(filePath)
fileNameNoExt := strings.TrimSuffix(file, path.Ext(file))

Expand Down Expand Up @@ -128,26 +157,35 @@ func ProcessArchiveFile(reader io.Reader, filePath, fileName string) (finding *t
return
}

log.Log().
Str("path", filePath).
Str("fileName", fileName).
Str("fileHash", fileHash).
Msg("identified library version")

if versionCve == "" {
log.Debug().
Str("hash", fileHash).
Str("version", semverVersion).
Msg("Skipping version as it is not vulnerable to any known CVE")
return nil
return
}

if versionIsInRange(fileNameNoExt, semverVersion, constants.JndiLookupPatchFileVersions) {
jndiLookupFileHash = GetJndiLookupHash(zipReader, filePath)
}

log.Log().
Str("path", filePath).
Str("fileName", fileName).
Str("fileHash", fileHash).
Str("jndiLookupFileName", constants.JndiLookupClasspath).
Str("jndiLookupFileHash", jndiLookupFileHash).
Msg("identified library version")

finding = &types.Finding{
Path: filePath,
FileName: fileName,
Hash: fileHash,
JndiLookupFileName: constants.JndiLookupClasspath,
JndiLookupHash: jndiLookupFileHash,
Version: semverVersion,
CVE: versionCve,
Severity: constants.CveSeverityLookup[versionCve],
}
return
}

0 comments on commit 74e545a

Please sign in to comment.