
Statischer Code-Analyse-Scanner für WordPress-Plugins und -Themes. Erkennt Schwachstellen wie XSS und SQL-Injection über eine modulare, erweiterbare Pattern-Matching-Engine mit Schweregradbewertungen und JSON-Berichterstattung.

Eine statische Code-Analyse für WordPress-Plugins/Themes (und PHP)
Klonen Sie einfach das Repository, installieren Sie die Abhängigkeiten und führen Sie das Skript aus:
$ git clone https://github.com/webarx-security/wpbullet wpbullet$ cd wpbullet$ pip install -r requirements.txt$ python wpbullet.pyVerfügbare Optionen:
--path (required) System path or download URL
Examples:
--path="/path/to/plugin"
--path="https://wordpress.org/plugins/example-plugin"
--path="https://downloads.wordpress.org/plugin/example-plugin.1.5.zip"
--enabled (optional) Check only for given modules, ex. --enabled="SQLInjection,CrossSiteScripting"
--disabled (optional) Don't check for given modules, ex. --disabled="SQLInjection,CrossSiteScripting"
--cleanup (optional) Automatically remove content of .temp folder after scanning remotely downloaded plugin (boolean)
--report (optional) Saves result inside reports/ directory in JSON format (boolean)
$ python wpbullet.py --path="/var/www/wp-content/plugins/plugin-name"
Das Erstellen eines Moduls ist flexibel und erlaubt das Überschreiben der BaseClass-Methoden für jedes Modul sowie das Erstellen eigener Methoden.
Jedes Modul im Verzeichnis Modules implementiert Eigenschaften und Methoden aus core.modules.BaseClass,
daher ist der erforderliche Parameter jedes Moduls BaseClass.
Nach der Erstellung muss das Modul in modules/__init__.py importiert werden. Modul- und Klassenname müssen konsistent sein,
damit das Modul geladen werden kann.
Wenn Sie einen Pull-Request zum Hinzufügen eines neuen Moduls öffnen, stellen Sie bitte auch Unit-Tests für Ihr Modul bereit.
Modules/ExampleVulnerability.py
from core.modules import BaseClass
class ExampleVulnerability(object):
# Name der Schwachstelle
name = "Cross-site Scripting"
# Schweregrad der Schwachstelle
severity = "Low-Medium"
# Funktionen, die die Schwachstelle verursachen
functions = [
"print"
"echo"
]
# Funktionen/Regex, die eine Ausnutzung verhindern
blacklist = [
"htmlspecialchars",
"esc_attr"
]
Das Regex-Muster wird in core.modules.BaseClass.build_pattern generiert und kann daher in
jeder Modulklasse überschrieben werden.
Modules/ExampleVulnerability.py
import copy
...
# Dynamisches Regex-Muster erstellen, um Schwachstellen im gegebenen Inhalt zu lokalisieren
def build_pattern(self, content, file):
user_input = copy.deepcopy(self.user_input)
variables = self.get_input_variables(self, content)
if variables:
user_input.extend(variables)
if self.blacklist:
blacklist_pattern = r"(?!(\s?)+(.*(" + '|'.join(self.blacklist) + ")))"
else:
blacklist_pattern = ""
self.functions = [self.functions_prefix + x for x in self.functions]
pattern = r"((" + '|'.join(self.functions) + ")\s{0,}\(?\s{0,1}" + blacklist_pattern + ".*(" + '|'.join(user_input) + ").*)"
return pattern
Ausführen der Unit-Tests: $ python3 -m unittest