Tony Torralba
|
227929508f
|
Merge pull request #6923 from atorralba/atorralba/android-fragment-injection
Java: CWE-470 - Queries to detect Fragment Injection in Android applications
|
2022-01-17 14:02:15 +01:00 |
|
Tony Torralba
|
7beab7cb59
|
Apply code review suggestions
|
2022-01-17 12:02:27 +01:00 |
|
Tony Torralba
|
9bbba3c96f
|
Adjust UnsupportedExternalAPIs test
|
2022-01-17 11:11:04 +01:00 |
|
Tony Torralba
|
1e4840e071
|
Fix predicate name
|
2022-01-17 11:11:03 +01:00 |
|
Tony Torralba
|
c1ac09a063
|
Added query for Cleartext Storage in Android Filesystem
|
2022-01-17 11:11:00 +01:00 |
|
Tony Torralba
|
9f616e7cbe
|
Refactor to use FlowState
Remove the auxiliary DataFlow configuration
|
2022-01-14 12:24:35 +01:00 |
|
Tony Torralba
|
a9757fbc83
|
Setting null Components is not a sanitizer
|
2022-01-14 10:32:37 +01:00 |
|
Tony Torralba
|
f963887c58
|
Change test to avoid collision with SensitiveCommunication.ql
|
2022-01-14 10:32:01 +01:00 |
|
Tony Torralba
|
9e3594fcf1
|
Added more sinks
|
2022-01-14 10:32:00 +01:00 |
|
Tony Torralba
|
d49e52fb73
|
Add support for PendingIntents in Notifications
|
2022-01-14 10:31:58 +01:00 |
|
Tony Torralba
|
7f85dae63b
|
Add support for implicit field read flows
|
2022-01-14 10:31:57 +01:00 |
|
Tony Torralba
|
e58a8587db
|
Add support for Slices
|
2022-01-14 10:31:56 +01:00 |
|
Tony Torralba
|
d43242d09e
|
Added tests
|
2022-01-14 10:31:56 +01:00 |
|
Tony Torralba
|
7b0d9ea525
|
Merge pull request #7054 from atorralba/atorralba/promote-log-injection
Java: Promote Log Injection from experimental
|
2022-01-11 17:26:18 +01:00 |
|
Tony Torralba
|
0e738622df
|
Merge branch 'main' into atorralba/promote-log-injection
|
2022-01-10 17:24:25 +01:00 |
|
Tony Torralba
|
ec8c234872
|
Fix predicate name
|
2022-01-10 17:09:41 +01:00 |
|
Tony Torralba
|
55dc783f28
|
Move from experimental and refactor
|
2022-01-10 17:09:37 +01:00 |
|
Tony Torralba
|
65b6c16254
|
Fix stub after merge
|
2021-12-15 16:53:47 +01:00 |
|
Tony Torralba
|
85526d71da
|
Add Fragment injection in PreferenceActivity query
|
2021-12-15 16:53:46 +01:00 |
|
Tony Torralba
|
701d12fb5b
|
Add Fragment injection query
|
2021-12-15 16:53:45 +01:00 |
|
Anders Schack-Mulligen
|
57fd397cb3
|
Merge pull request #7239 from smowton/smowton/fix/useless-comparison-surrogates
Range analysis and useless-comparison query: don't treat all unicode surrogates as if they are U+FFFD
|
2021-11-26 09:00:36 +01:00 |
|
Chris Smowton
|
db39c0b8be
|
CharacterLiteral.getCodePointValue: fix handling of surrogates
|
2021-11-25 14:07:21 +00:00 |
|
Chris Smowton
|
9540beeda9
|
Update java/ql/test/query-tests/security/CWE-611/DocumentBuilderTests.java
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
|
2021-11-25 12:52:08 +00:00 |
|
Chris Smowton
|
9eb9eb606e
|
Note that FEATURE_SECURE_PROCESSING isn't a sufficient defence against XXE
|
2021-11-25 12:22:48 +00:00 |
|
Benjamin Muskalla
|
3dbaa087d4
|
Remove class file
|
2021-11-16 16:36:27 +01:00 |
|
Anders Schack-Mulligen
|
85fdbda16f
|
Merge pull request #7002 from aschackmull/java/field-node
Java: Add FieldValueNode to break up cartesian step relation.
|
2021-11-08 09:31:42 +01:00 |
|
Tony Torralba
|
f4704f1325
|
Merge pull request #6397 from atorralba/atorralba/android-intent-redirect-query
Java: Create new Android Intent Redirection query
|
2021-11-04 10:42:59 +01:00 |
|
Tony Torralba
|
f1df542345
|
Add stubs & tests
Fix mistakes detected by the tests
|
2021-11-03 17:26:13 +01:00 |
|
Tony Torralba
|
ebd6529469
|
WIP: add tests
|
2021-11-02 10:37:41 +01:00 |
|
Anders Schack-Mulligen
|
e51a10a816
|
Java: Fix tests.
|
2021-10-29 14:25:43 +02:00 |
|
Joe Farebrother
|
a9dde419d2
|
Fix up test
|
2021-10-21 16:46:07 +01:00 |
|
Joe Farebrother
|
447e06d92a
|
Rename from SensitiveBroadcast to SensitiveCommmunication
|
2021-10-20 17:09:59 +01:00 |
|
Joe Farebrother
|
daf6ac2584
|
Update tests to InlineFlowTest
|
2021-10-20 17:09:58 +01:00 |
|
Joe Farebrother
|
d7c7776495
|
Add additional models; fix up tests
|
2021-10-20 17:09:57 +01:00 |
|
Joe Farebrother
|
ae461bcfe4
|
Switch to inline expectations tests
|
2021-10-20 17:09:57 +01:00 |
|
Joe Farebrother
|
c68a7077d7
|
Move query and tests out of experimental
|
2021-10-20 17:09:56 +01:00 |
|
Tony Torralba
|
392e2eebeb
|
Add intent creation from a URI as a taint step
|
2021-10-18 12:18:07 +02:00 |
|
Tony Torralba
|
d1d2d61d7e
|
Add more sinks
Also, fix things after rebase
|
2021-10-18 12:00:07 +02:00 |
|
Tony Torralba
|
e7983fb269
|
Add test and check for another edge case
|
2021-10-18 11:10:23 +02:00 |
|
Tony Torralba
|
bc6c13be69
|
Refactor to actually build the full flows from src to sink
Add more tests for edge cases
|
2021-10-18 11:10:22 +02:00 |
|
Tony Torralba
|
14963103aa
|
Add full path reconstruction from RemoteFlowSource to sink
|
2021-10-18 11:10:21 +02:00 |
|
Tony Torralba
|
2ab7a55545
|
Improve intermediate flow to add more potential sources
|
2021-10-18 11:09:52 +02:00 |
|
Tony Torralba
|
aa2cdb7a53
|
Add intermediate dataflow
Make sure that source intents are obtained from another intent's extras
|
2021-10-18 11:09:30 +02:00 |
|
Tony Torralba
|
9a537f9c23
|
Add guard sanitizer for component name checks
|
2021-10-18 11:08:14 +02:00 |
|
Tony Torralba
|
21b70a009e
|
Use CSV models
|
2021-10-18 11:07:58 +02:00 |
|
Tony Torralba
|
9eb4cda1af
|
Fix qhelp and formatting
|
2021-10-18 11:06:08 +02:00 |
|
Tony Torralba
|
031fa2199c
|
Fix stubs and tests
|
2021-10-18 11:06:06 +02:00 |
|
Tony Torralba
|
ef30ca211a
|
Fix stubs
|
2021-10-18 11:03:13 +02:00 |
|
Tony Torralba
|
fd8a128693
|
Renamed to AndroidIntentRedirection
Added qhelp
|
2021-10-18 11:02:34 +02:00 |
|
Tony Torralba
|
8c400d9b1b
|
Added tests and stubs
|
2021-10-18 11:02:10 +02:00 |
|