Sim4n6
|
bca053f855
|
Move the config query to the parent directory
|
2023-01-27 13:42:14 +01:00 |
|
Sim4n6
|
998f1bf215
|
Some reformatting
|
2023-01-26 18:54:36 +01:00 |
|
Sim4n6
|
1a211485a4
|
Restrain the source and add two steps.
|
2023-01-26 17:07:59 +01:00 |
|
Sim4n6
|
51b11de44a
|
Add a Django Upload examples
|
2023-01-26 15:16:24 +01:00 |
|
Sim4n6
|
54cc4d6498
|
Opt for any source from RemoteFlowSource.
|
2023-01-26 12:51:55 +01:00 |
|
Sim4n6
|
aaa0040612
|
Seperate the dataflow config from the query
|
2023-01-26 08:53:47 +01:00 |
|
Sim4n6
|
2e4cb63049
|
Optimize the Argparse filename as a source.
|
2023-01-26 01:00:01 +01:00 |
|
Sim4n6
|
9b5b0c60b8
|
Handle the download of a tarball using wget pkg.
|
2023-01-26 00:02:20 +01:00 |
|
Sim4n6
|
22af6f5182
|
Restrict download_file() to boto3 lib
|
2023-01-25 23:00:00 +01:00 |
|
Sim4n6
|
2d38993075
|
Add a missing "and"
|
2023-01-25 19:46:13 +01:00 |
|
Sim4n6
|
0ed480855a
|
Update python/ql/src/experimental/Security/CWE-022bis/UnsafeUnpack.ql
Yes, definitely
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2023-01-25 19:44:28 +01:00 |
|
Sim4n6
|
b5a6f6e165
|
Merge pull request #1 from github/main
Sync with the upstream
|
2023-01-25 19:13:35 +01:00 |
|
yoff
|
5a82012d03
|
Merge pull request #11854 from yoff/python/fix-tarslip-improv-bug
Python: fix bug in `py/tarslip-extended`
|
2023-01-17 20:44:06 +01:00 |
|
Rasmus Lerchedahl Petersen
|
c142495a8b
|
python: simplify code
|
2023-01-09 17:51:45 +01:00 |
|
Rasmus Lerchedahl Petersen
|
5fe62e293a
|
python: fix bug, add clarifying comment
|
2023-01-09 17:45:50 +01:00 |
|
Sim4n6
|
4376870a51
|
An uploded file is considered a source
|
2022-12-15 23:39:02 +01:00 |
|
turbo
|
4ec401a3f6
|
Tag all security queries in supported languages' experimental directories with an experimental tag
|
2022-12-14 17:15:50 +01:00 |
|
ALJI Mohamed
|
54109b8ea7
|
Add source wget.download
|
2022-12-13 15:34:01 +01:00 |
|
ALJI Mohamed
|
2f68b54b27
|
A simple download_file() call from maybe boto3
|
2022-12-12 19:46:34 +01:00 |
|
ALJI Mohamed
|
b19452467d
|
read by chunks as additional step
|
2022-12-10 21:59:14 +01:00 |
|
ALJI Mohamed
|
eff132512c
|
Copying the response data to the archive
|
2022-12-10 08:15:42 +01:00 |
|
ALJI Mohamed
|
545aab0e07
|
tarball path provided using CLI argument (source)
|
2022-12-09 15:54:43 +01:00 |
|
Henry Mercer
|
5674251839
|
Python: Disable TarSlipImprov qhelp
|
2022-12-08 13:03:31 +00:00 |
|
ALJI Mohamed
|
9336f4f1a2
|
Considering the use of contextlib.closing() method
|
2022-12-08 12:26:59 +01:00 |
|
ALJI Mohamed
|
2801b8495a
|
A fix of the tag name
|
2022-12-06 14:50:47 +01:00 |
|
ALJI Mohamed
|
4896e62117
|
Use of more generic terms
|
2022-12-06 14:44:52 +01:00 |
|
Sim4n6
|
58570b4d2c
|
Update python/ql/src/experimental/Security/CWE-022bis/UnsafeUnpack.ql
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
|
2022-12-06 14:40:48 +01:00 |
|
Sim4n6
|
9a60202de6
|
Update python/ql/src/experimental/Security/CWE-022bis/UnsafeUnpack.qhelp
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
|
2022-12-06 14:40:35 +01:00 |
|
Sim4n6
|
c22c0b5029
|
Update python/ql/src/experimental/Security/CWE-022bis/UnsafeUnpack.qhelp
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
|
2022-12-06 14:39:16 +01:00 |
|
ALJI Mohamed
|
a5849eb9b0
|
Improved the additional taint step using InstanceSource
|
2022-12-06 14:00:08 +01:00 |
|
ALJI Mohamed
|
054c06be65
|
Update UnsafeUnpack.ql
|
2022-12-06 02:51:07 +01:00 |
|
Henry Mercer
|
5b040a9476
|
Python: Fix duplicate query IDs
|
2022-12-05 19:04:10 +00:00 |
|
ALJI Mohamed
|
68fd75ca34
|
UnpackUnsafe query and tests
|
2022-12-05 17:20:22 +01:00 |
|
Daniel Santos
|
feece6f7b4
|
Merge branch 'github:main' into main
|
2022-10-25 10:43:20 -05:00 |
|
Daniel Santos
|
5b080481aa
|
TokenBuiltFromUuid formatting
|
2022-10-25 09:51:48 -05:00 |
|
Daniel Santos
|
b8d60edb49
|
TokenBuiltFromUuid isAdditionalTaintStep refactor
|
2022-10-25 09:51:07 -05:00 |
|
Daniel Santos
|
375edf7455
|
TokenAssignmentValueSink refactor
|
2022-10-25 09:50:04 -05:00 |
|
Daniel Santos
|
5ab068a3cc
|
Update python/ql/src/experimental/Security/CWE-340/TokenBuiltFromUUID.ql
Co-authored-by: Taus <tausbn@github.com>
|
2022-10-24 11:55:21 -05:00 |
|
Daniel Santos
|
be8780742b
|
Update python/ql/src/experimental/Security/CWE-340/TokenBuiltFromUUID.ql
You are totally right! I just scanned the module's document and assumed it would implement it all. Pasting the documentation here for future reference https://docs.python.org/3/library/uuid.html?highlight=uuid#uuid.UUID.
Co-authored-by: Taus <tausbn@github.com>
|
2022-10-24 11:49:17 -05:00 |
|
Daniel Santos
|
a2ad924376
|
Minor formatting fixes
|
2022-10-24 09:38:17 -05:00 |
|
Daniel Santos
|
066ffb7520
|
Tokens built from predictable UUIDs
|
2022-10-22 11:15:43 -05:00 |
|
ALJI Mohamed
|
92a3846102
|
Fix query to omit sinks within std lib files
|
2022-10-22 09:35:55 +01:00 |
|
ALJI Mohamed
|
7319052495
|
Delete the examples/
|
2022-10-21 21:47:00 +01:00 |
|
Sim4n6
|
925f9d09e5
|
Update python/ql/src/experimental/Security/CWE-022bis/TarSlipImprov.ql
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2022-10-21 21:06:51 +01:00 |
|
ALJI Mohamed
|
9163cbec09
|
Restrict the reach for an additional taint step
|
2022-10-19 16:08:49 +01:00 |
|
ALJI Mohamed
|
25a7fcffc0
|
Add an additional taint step
|
2022-10-19 16:01:34 +01:00 |
|
ALJI Mohamed
|
d6fa745279
|
Add TarSlip Improv query
|
2022-10-19 14:01:40 +01:00 |
|
Josh Soref
|
ad7dc81bdc
|
spelling: sanitize
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-13 11:21:09 -04:00 |
|
Jeroen Ketema
|
d389a183f0
|
Merge pull request #10743 from jsoref/spelling
Spelling
|
2022-10-12 12:48:22 +02:00 |
|
erik-krogh
|
4da0508dae
|
Merge branch 'main' into py-last-msg
|
2022-10-11 10:49:19 +02:00 |
|