अपडेट पर वापस जाएँ
New releaseAug 11, 2026

njsscan v1.0.0

Node.js अनुप्रयोगों के लिए सिमैंटिक-अवेयर SAST स्कैनर जो libsast पैटर्न मिलान और semgrep सिंटैक्स-अवेयर विश्लेषण का उपयोग करके असुरक्षित कोड पैटर्न का पता लगाता है।

साझा करें

njsscan

njsscan एक स्टैटिक एप्लिकेशन टेस्टिंग (SAST) टूल है जो libsast के सरल पैटर्न मैचर और सिंटैक्स-अवेयर सेमांटिक कोड पैटर्न सर्च टूल semgrep का उपयोग करके आपके node.js एप्लिकेशन में असुरक्षित कोड पैटर्न खोज सकता है।

भारत में Love के साथ बनाया गया Tweet

PyPI version platform License python Build

njsscan का समर्थन करें

  • Paypal के माध्यम से दान करें: Donate via Paypal
  • प्रोजेक्ट को स्पॉन्सर करें: Github Sponsors

e-Learning कोर्स और सर्टिफिकेशन

OpSecX Video Course OpSecX Node.js Security: Pentesting and Exploitation - NJS

इंस्टॉलेशन

pip install njsscan

Python 3.10+ की आवश्यकता है और केवल Mac और Linux का समर्थन करता है

कमांड लाइन विकल्प

$ njsscan
usage: njsscan [-h] [--json] [--sarif] [--sonarqube] [--defectdojo] [--gitlab-sast] [--html] [-o OUTPUT] [-c CONFIG] [--missing-controls] [-w] [-v] [path ...]

positional arguments:
  path                  Path can be file(s) or directories with source code

optional arguments:
  -h, --help            show this help message and exit
  --json                set output format as JSON
  --sarif               set output format as SARIF 2.1.0
  --sonarqube           set output format compatible with SonarQube
  --defectdojo          set output format compatible with DefectDojo Generic Findings Import
  --gitlab-sast         set output format as GitLab SAST report
  --html                set output format as HTML
  -o OUTPUT, --output OUTPUT
                        output filename to save the result
  -c CONFIG, --config CONFIG
                        Location to .njsscan config file
  --missing-controls    enable missing security controls check
  -w, --exit-warning    non zero exit code on warning
  -v, --version         show njsscan version

उदाहरण उपयोग

$ njsscan test.js
- Pattern Match ████████████████████████████████████████████████████████████ 1
- Semantic Grep ███████████████████████████ 160

njsscan: v0.1.9 | Ajin Abraham | opensecurity.in
╒═════════════╤═══════════════════════════════════════════════════════════════════════════════════════════════╕
│ RULE ID     │ express_xss                                                                                   │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ OWASP       │ A1: Injection                                                                                 │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ CWE         │ CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')  │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ DESCRIPTION │ Untrusted User Input in Response will result in Reflected Cross Site Scripting Vulnerability. │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ SEVERITY    │ ERROR                                                                                         │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ FILES       │ ╒════════════════╤═══════════════════════════════════════════════╕                            │
│             │ │ File           │ test.js                                       │                            │
│             │ ├────────────────┼───────────────────────────────────────────────┤                            │
│             │ │ Match Position │ 5 - 46                                        │                            │
│             │ ├────────────────┼───────────────────────────────────────────────┤                            │
│             │ │ Line Number(s) │ 7: 8                                          │                            │
│             │ ├────────────────┼───────────────────────────────────────────────┤                            │
│             │ │ Match String   │ const { name } = req.query;                   │                            │
│             │ │                │     res.send('<h1> Hello :' + name + "</h1>") │                            │
│             │ ╘════════════════╧═══════════════════════════════════════════════╛                            │
╘═════════════╧═══════════════════════════════════════════════════════════════════════════════════════════════╛

nodejsscan SAST

nodejsscan, जो njsscan के ऊपर बनाया गया है, अन्य उपयोगी इंटीग्रेशन के साथ एक पूर्ण विकसित भेद्यता प्रबंधन यूजर इंटरफेस प्रदान करता है।

nodejsscan web ui

nodejsscan देखें

Python API

>>> from njsscan.njsscan import NJSScan
>>> node_source = '/node_source/true_positives/sqli_node.js'
>>> scanner = NJSScan([node_source], json=True, check_controls=False)
>>> scanner.scan()
{
    'templates': {},
    'nodejs': {
        'node_sqli_injection': {
            'files': [{
                'file_path': '/node_source/true_positives/sqli_node.js',
                'match_position': (1, 24),
                'match_lines': (4, 11),
                'match_string': 'var employeeId = req.foo;\n\nvar sql = "SELECT * FROM trn_employee WHERE employee_id = " + employeeId;\n\n\n\nconnection.query(sql, function (error, results, fields) {\n\n    if (error) {\n\n        throw error;\n\n    }\n\n    console.log(results);'
            }],
            'metadata': {
                'owasp': 'A1: Injection',
                'cwe': "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
                'description': 'Untrusted input concatinated with raw SQL query can result in SQL Injection.',
                'severity': 'ERROR'
            }
        }
    },
    'errors': []
}

njsscan कॉन्फ़िगर करें

सोर्स कोड डायरेक्टरी की रूट में एक .njsscan फ़ाइल आपको njsscan कॉन्फ़िगर करने की अनुमति देती है। आप --config आर्ग्युमेंट का उपयोग करके एक कस्टम .njsscan फ़ाइल भी उपयोग कर सकते हैं।

---
- nodejs-extensions:
  - .js

श्रेणियाँ