Rasmus Wriedt Larsen
|
88184ba9f5
|
Python: Update path-injection .expected
AHA! This change happened because we are no longer importing all the old
deprecated implementation.
|
2022-03-21 20:24:12 +01:00 |
|
Arthur Baars
|
9412b331db
|
Revert "Revert "Python: switch to shared implementation of IncompleteHostnameRegExp.ql""
This reverts commit 6d24591416.
|
2022-03-18 16:31:22 +01:00 |
|
Mathias Vorreiter Pedersen
|
abe30457ee
|
Python: Accept test changes.
|
2022-03-17 14:03:58 +01:00 |
|
Rasmus Wriedt Larsen
|
ae1ba11d57
|
Merge branch 'main' into orm
|
2022-03-16 11:23:14 +01:00 |
|
Rasmus Wriedt Larsen
|
461e2f3663
|
Python: Apply suggestions from code review
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2022-03-16 10:43:20 +01:00 |
|
Erik Krogh Kristensen
|
c7509c4dd3
|
Merge branch 'main' into deadCode
|
2022-03-15 09:19:14 +01:00 |
|
Erik Krogh Kristensen
|
3bf5e06d53
|
delete all dead code
|
2022-03-14 13:03:31 +01:00 |
|
Rasmus Wriedt Larsen
|
2f4a22c86c
|
Merge pull request #6112 from jorgectf/jorgectf/python/deserialization
Python: Port and extend XXE modeling
|
2022-03-14 11:59:28 +01:00 |
|
Taus
|
4ee4bba4d1
|
Merge branch 'main' into ZipSlip
|
2022-03-10 13:30:51 +01:00 |
|
Erik Krogh Kristensen
|
755b0bbcb9
|
PY: update tests to not use deleted deprecations
|
2022-03-09 18:28:13 +01:00 |
|
Erik Krogh Kristensen
|
61e282da84
|
PY: delete test that mostly used deleted deprecated features
|
2022-03-09 18:28:13 +01:00 |
|
Erik Krogh Kristensen
|
309e376c6d
|
PY: convert test to not use deleted deprecations
|
2022-03-09 18:28:12 +01:00 |
|
Erik Krogh Kristensen
|
d5a76e8c98
|
Python: delete test that only used deprecated classes
|
2022-03-09 18:28:12 +01:00 |
|
Erik Krogh Kristensen
|
a1769f8036
|
Python: add default implementation of getName() and deprecate it
|
2022-03-09 18:28:12 +01:00 |
|
Taus
|
7b877fb317
|
Merge pull request #8336 from tausbn/python-fix-a-bunch-of-ql-warnings
Python: Fix a bunch of QL warnings
|
2022-03-09 16:31:28 +01:00 |
|
Ahmed Farid
|
23bd53a325
|
Update zipslip_good.py
|
2022-03-08 23:55:17 +01:00 |
|
Taus
|
063a8bbc43
|
Python: Apply suggestions from code review
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2022-03-08 15:20:35 +01:00 |
|
Rasmus Wriedt Larsen
|
6b14c1d6b9
|
Merge branch 'main' into jorgectf/python/deserialization
|
2022-03-08 11:15:03 +01:00 |
|
Taus
|
5a8ba6a7af
|
Python: Fix use of singleton set
|
2022-03-07 18:59:49 +00:00 |
|
Taus
|
d2603884ca
|
Python: Fix a bunch of class QLDoc
|
2022-03-07 18:59:49 +00:00 |
|
Taus
|
af7f532212
|
Python: Fix up a bunch of function QLDoc
|
2022-03-07 18:59:49 +00:00 |
|
Ahmed Farid
|
3b8c7e8944
|
Update ZipSlip.expected
|
2022-03-07 10:11:34 +01:00 |
|
Ahmed Farid
|
8402d661df
|
Update zipslip_bad.py
|
2022-03-07 10:11:00 +01:00 |
|
haby0
|
7e6666bc63
|
Merge branch 'main' into py/add-ssrf-sinks
|
2022-03-07 12:09:14 +08:00 |
|
Ahmed Farid
|
35a1c80ceb
|
Update zipslip_bad.py
|
2022-03-07 00:24:45 +01:00 |
|
Ahmed Farid
|
6233309028
|
Update ZipSlip.expected
|
2022-03-07 00:23:48 +01:00 |
|
Ahmed Farid
|
e8449d8f40
|
Update zipslip_bad.py
|
2022-03-07 00:23:03 +01:00 |
|
Ahmed Farid
|
b7d4715c4e
|
Create ZipSlip.expected
|
2022-03-07 00:06:24 +01:00 |
|
Ahmed Farid
|
908db6a05f
|
Update zipslip_bad.py
|
2022-03-07 00:01:09 +01:00 |
|
Ahmed Farid
|
7f2d242702
|
Update zipslip_good.py
|
2022-03-06 23:59:11 +01:00 |
|
Rasmus Wriedt Larsen
|
f620e2599d
|
Merge branch 'main' into py/add-ssrf-sinks
|
2022-03-04 11:50:12 +01:00 |
|
Rasmus Wriedt Larsen
|
02a97b08bb
|
Python: Move urllib and urllib2 to be part of stdlib modeling
|
2022-03-04 11:31:47 +01:00 |
|
Rasmus Wriedt Larsen
|
c65839bb77
|
Python: improve urllib3 modeling
|
2022-03-04 11:25:14 +01:00 |
|
Rasmus Wriedt Larsen
|
7d6d8be179
|
Python: Fix httpx modeling
|
2022-03-04 11:07:51 +01:00 |
|
Rasmus Wriedt Larsen
|
40feb1fb8d
|
Python: SPURIOUS results for httpx
|
2022-03-04 11:03:32 +01:00 |
|
yoff
|
d0a393e8d1
|
Update python/ql/test/library-tests/frameworks/stdlib/XPathExecution.py
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2022-03-04 10:56:53 +01:00 |
|
Rasmus Wriedt Larsen
|
1a9620a87a
|
Python: Add conditional assignment check for sax parser
|
2022-03-04 10:16:28 +01:00 |
|
Rasmus Wriedt Larsen
|
f0131afc54
|
Python: Fix huge_tree modeling
|
2022-03-04 10:16:28 +01:00 |
|
Rasmus Wriedt Larsen
|
d6cbfec434
|
Python: huge_tree tests were wrong
Nice spotted @jorgectf!
|
2022-03-04 10:16:28 +01:00 |
|
Ahmed Farid
|
be7c619ca8
|
Update zipslip_bad.py
|
2022-03-04 00:48:45 +01:00 |
|
Rasmus Wriedt Larsen
|
3f6c55e8ae
|
Python: Rename vulnerable predicate => vulnerableTo
|
2022-03-03 22:09:31 +01:00 |
|
Rasmus Wriedt Larsen
|
c0a6f9f3fd
|
Python: Restructure lxml modeling
and handle parser being passed as positional argument
|
2022-03-03 22:00:55 +01:00 |
|
Rasmus Wriedt Larsen
|
c0a2c25f5a
|
Python: Restructure modeling of xml.etree parsers
|
2022-03-03 21:59:34 +01:00 |
|
Rasmus Wriedt Larsen
|
46238d5ea0
|
Python: Add test for XMLPullParser
But handling this in a nice way will require some restructuring
|
2022-03-03 21:28:46 +01:00 |
|
Rasmus Wriedt Larsen
|
33ebcdf437
|
Python: Support feed method of lxml/xml.etree Parsers
|
2022-03-03 21:26:24 +01:00 |
|
Rasmus Wriedt Larsen
|
f72f673e7e
|
Python: Update XmlEntityInjection.expected
I had forgotten about this, but better late than never... also added a
small representative test
|
2022-03-03 21:18:18 +01:00 |
|
Rasmus Wriedt Larsen
|
3278793972
|
Python: Handle more functions and kw-args
|
2022-03-03 21:18:18 +01:00 |
|
Rasmus Wriedt Larsen
|
2451123c67
|
Python: Move XML PoC to new test dir
|
2022-03-03 21:18:18 +01:00 |
|
Rasmus Wriedt Larsen
|
c739ae40b6
|
Python: Port xmltodict tests
|
2022-03-03 21:18:18 +01:00 |
|
Rasmus Wriedt Larsen
|
0b12d91817
|
Python: Port xml.sax tests
|
2022-03-03 21:18:18 +01:00 |
|