Skip to content

Commit

Permalink
disable domflow and intro esflow for static analysis
Browse files Browse the repository at this point in the history
  • Loading branch information
skepticfx committed Jan 14, 2016
1 parent cff5a11 commit c5254cf
Show file tree
Hide file tree
Showing 3 changed files with 52 additions and 6 deletions.
45 changes: 45 additions & 0 deletions src/esflow.html
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
<!doctype html>
<link href='css/Lato.css' rel='stylesheet' type='text/css' />
<link href='dragula/dragula.css' rel='stylesheet' type='text/css' />
<link href='dragula/domflow.css' rel='stylesheet' type='text/css' />
<title>DomFlow - Hookish!</title>
<h1>DomFlow - Hookish!</h1>
<h3>Analyze DOM sources and sinks</h3>
<body>
<div class="parent">
<div class='left'>
<h3>Sources</h3>
<div id='sources' class='container'>
<div data-type="source" data-name="location_hash">location.hash</div>
<div data-type="source" data-name="window_name">window.name</div>
<div data-type="source" data-name="document_referrer">document.referrer</div>
<div data-type="source" data-name="document_cookie">document.cookie</div>
<div data-type="source" data-name="xhr">XMLHttpRequest</div>
<div data-type="source" data-name="ws">WebSocket</div>
</div>
</div>

<div class="right">
<h3>Sinks</h3>
<div id='sinks' class='container'>
<div data-type="sink" data-name="dom_nodes">innerHTML</div>
<div data-type="sink" data-name="dom_nodes">outerHTML</div>
<div data-type="sink" data-name="window_eval">window.eval</div>
<div data-type="sink" data-name="window_setTimeout">window.setTimeout</div>
<div data-type="sink" data-name="document_write">document.write</div>
<div data-type="sink" data-name="window_setInterval">window.setInterval</div>
</div>
</div>
</div>

<div class="container" id="dragToMe">
<button id="identifyFlowsButton">Identify flows</button>
<span id="dragToMeInfo">Drag sources and sinks to me</span>
</div>

<script src='dragula/dragula.js'></script>
<script src='dragula/domflow.js'></script>
<script src='js/taintAnalyzer.js'></script>

</body>
</html>
11 changes: 6 additions & 5 deletions src/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -43,11 +43,15 @@
<div class="collapse navbar-collapse" id="bs-example-navbar-collapse-1">
<ul class="nav navbar-nav navbar-right">
<li>
<a href="#" id="listGlobalVariables">List Globals</a>
<a href="esflow.html" target="_blank">Static Analysis</a>
</li>
<li>
<a href="#" id="listGlobalVariables">List Globals</a>
</li>
<!-- <li>
<a href="domflow.html" target="_blank">DomFlow</a>
</li>
-->
<li class="page-scroll">
<a href="#section_settings">Settings</a>
</li>
Expand Down Expand Up @@ -101,14 +105,11 @@ <h2>Whats Next?</h2>
</div>
</div>
<div class="row">
<div class="col-lg-4 col-lg-offset-2">
<p>Dom Flow - Drag & drop your sources & sinks.</p>
</div>
<div class="col-lg-4 col-lg-offset-2">
<p>Hooking User defined Functions</p>
</div>
<div class="col-lg-4 col-lg-offset-2">
<p>Point, Click, Generate report for the traditional pentester.</p>
<p>Point, Click, Generate report for the classic pentester.</p>
</div>
<br/>
<br/>
Expand Down
2 changes: 1 addition & 1 deletion src/manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
"description": "Hooks in to interesting functions and helps reverse the web app faster.",
"manifest_version": 2,
"short_name": "Hook Dom sources and sinks.",
"version": "0.5.1",
"version": "0.6.0",
"permissions": [
"tabs",
"<all_urls>",
Expand Down

0 comments on commit c5254cf

Please sign in to comment.