
njsscan v1.0.0
Node.js अनुप्रयोगों के लिए सिमैंटिक-अवेयर SAST स्कैनर जो libsast पैटर्न मिलान और semgrep सिंटैक्स-अवेयर विश्लेषण का उपयोग करके असुरक्षित कोड पैटर्न का पता लगाता है।
njsscan
njsscan एक स्टैटिक एप्लिकेशन टेस्टिंग (SAST) टूल है जो libsast के सरल पैटर्न मैचर और सिंटैक्स-अवेयर सेमांटिक कोड पैटर्न सर्च टूल semgrep का उपयोग करके आपके node.js एप्लिकेशन में असुरक्षित कोड पैटर्न खोज सकता है।
njsscan का समर्थन करें
e-Learning कोर्स और सर्टिफिकेशन
OpSecX Node.js Security: Pentesting and Exploitation - NJS
इंस्टॉलेशन
pip install njsscan
Python 3.10+ की आवश्यकता है और केवल Mac और Linux का समर्थन करता है
कमांड लाइन विकल्प
$ njsscan
usage: njsscan [-h] [--json] [--sarif] [--sonarqube] [--defectdojo] [--gitlab-sast] [--html] [-o OUTPUT] [-c CONFIG] [--missing-controls] [-w] [-v] [path ...]
positional arguments:
path Path can be file(s) or directories with source code
optional arguments:
-h, --help show this help message and exit
--json set output format as JSON
--sarif set output format as SARIF 2.1.0
--sonarqube set output format compatible with SonarQube
--defectdojo set output format compatible with DefectDojo Generic Findings Import
--gitlab-sast set output format as GitLab SAST report
--html set output format as HTML
-o OUTPUT, --output OUTPUT
output filename to save the result
-c CONFIG, --config CONFIG
Location to .njsscan config file
--missing-controls enable missing security controls check
-w, --exit-warning non zero exit code on warning
-v, --version show njsscan version
उदाहरण उपयोग
$ njsscan test.js
- Pattern Match ████████████████████████████████████████████████████████████ 1
- Semantic Grep ███████████████████████████ 160
njsscan: v0.1.9 | Ajin Abraham | opensecurity.in
╒═════════════╤═══════════════════════════════════════════════════════════════════════════════════════════════╕
│ RULE ID │ express_xss │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ OWASP │ A1: Injection │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ CWE │ CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ DESCRIPTION │ Untrusted User Input in Response will result in Reflected Cross Site Scripting Vulnerability. │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ SEVERITY │ ERROR │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ FILES │ ╒════════════════╤═══════════════════════════════════════════════╕ │
│ │ │ File │ test.js │ │
│ │ ├────────────────┼───────────────────────────────────────────────┤ │
│ │ │ Match Position │ 5 - 46 │ │
│ │ ├────────────────┼───────────────────────────────────────────────┤ │
│ │ │ Line Number(s) │ 7: 8 │ │
│ │ ├────────────────┼───────────────────────────────────────────────┤ │
│ │ │ Match String │ const { name } = req.query; │ │
│ │ │ │ res.send('<h1> Hello :' + name + "</h1>") │ │
│ │ ╘════════════════╧═══════════════════════════════════════════════╛ │
╘═════════════╧═══════════════════════════════════════════════════════════════════════════════════════════════╛
nodejsscan SAST
nodejsscan, जो njsscan के ऊपर बनाया गया है, अन्य उपयोगी इंटीग्रेशन के साथ एक पूर्ण विकसित भेद्यता प्रबंधन यूजर इंटरफेस प्रदान करता है।

nodejsscan देखें
Python API
>>> from njsscan.njsscan import NJSScan
>>> node_source = '/node_source/true_positives/sqli_node.js'
>>> scanner = NJSScan([node_source], json=True, check_controls=False)
>>> scanner.scan()
{
'templates': {},
'nodejs': {
'node_sqli_injection': {
'files': [{
'file_path': '/node_source/true_positives/sqli_node.js',
'match_position': (1, 24),
'match_lines': (4, 11),
'match_string': 'var employeeId = req.foo;\n\nvar sql = "SELECT * FROM trn_employee WHERE employee_id = " + employeeId;\n\n\n\nconnection.query(sql, function (error, results, fields) {\n\n if (error) {\n\n throw error;\n\n }\n\n console.log(results);'
}],
'metadata': {
'owasp': 'A1: Injection',
'cwe': "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
'description': 'Untrusted input concatinated with raw SQL query can result in SQL Injection.',
'severity': 'ERROR'
}
}
},
'errors': []
}
njsscan कॉन्फ़िगर करें
सोर्स कोड डायरेक्टरी की रूट में एक .njsscan फ़ाइल आपको njsscan कॉन्फ़िगर करने की अनुमति देती है। आप --config आर्ग्युमेंट का उपयोग करके एक कस्टम .njsscan फ़ाइल भी उपयोग कर सकते हैं।
---
- nodejs-extensions:
- .js
के साथ बनाया गया 
