Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
njsscan — Node.jsアプリケーション向けのセマンティック対応SASTスキャナ。libsastのパターンマッチングとsemgrepの構文認識分析を用いて、安全でないコードパターンを検出します。 | Kitploit
ツール/GitHubGitHub/ajinabraham/njsscan
静的分析脆弱性スキャナーコード分析ウェブセキュリティDevSecOps
GitHubajinabraham/njsscan

njsscan

Node.jsアプリケーション向けのセマンティック対応SASTスキャナ。libsastのパターンマッチングとsemgrepの構文認識分析を用いて、安全でないコードパターンを検出します。

リポジトリを見る
4361089日前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
ウェブサイト

njsscan

njsscan は、libsast のシンプルなパターンマッチャーと、構文を認識するセマンティックコードパターン検索ツール semgrep を使用して、Node.js アプリケーションの不安全なコードパターンを見つけることができる静的アプリケーションテスト (SAST) ツールです。

Love を込めて、インドで作られました Tweet

PyPI version platform License python Build

njsscan をサポート

  • Paypal で寄付: Donate via Paypal
  • プロジェクトのスポンサーになる: Github Sponsors

eラーニングコース & 認定資格

OpSecX Video Course OpSecX Node.js Security: Pentesting and Exploitation - NJS

インストール

pip install njsscan

Python 3.10+ が必要で、Mac と Linux のみをサポートしています。

コマンドラインオプション

root@kitploit:~
$ njsscan
usage: njsscan [-h] [--json] [--sarif] [--sonarqube] [--defectdojo] [--gitlab-sast] [--html] [-o OUTPUT] [-c CONFIG] [--missing-controls] [-w] [-v] [path ...]

positional arguments:
  path                  Path can be file(s) or directories with source code

optional arguments:
  -h, --help            show this help message and exit
  --json                set output format as JSON
  --sarif               set output format as SARIF 2.1.0
  --sonarqube           set output format compatible with SonarQube
  --defectdojo          set output format compatible with DefectDojo Generic Findings Import
  --gitlab-sast         set output format as GitLab SAST report
  --html                set output format as HTML
  -o OUTPUT, --output OUTPUT
                        output filename to save the result
  -c CONFIG, --config CONFIG
                        Location to .njsscan config file
  --missing-controls    enable missing security controls check
  -w, --exit-warning    non zero exit code on warning
  -v, --version         show njsscan version

使用例

root@kitploit:~
$ njsscan test.js
- Pattern Match ████████████████████████████████████████████████████████████ 1
- Semantic Grep ███████████████████████████ 160

njsscan: v0.1.9 | Ajin Abraham | opensecurity.in
╒═════════════╤═══════════════════════════════════════════════════════════════════════════════════════════════╕
│ RULE ID     │ express_xss                                                                                   │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ OWASP       │ A1: Injection                                                                                 │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ CWE         │ CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')  │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ DESCRIPTION │ Untrusted User Input in Response will result in Reflected Cross Site Scripting Vulnerability. │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ SEVERITY    │ ERROR                                                                                         │
├─────────────┼───────────────────────────────────────────────────────────────────────────────────────────────┤
│ FILES       │ ╒════════════════╤═══════════════════════════════════════════════╕                            │
│             │ │ File           │ test.js                                       │                            │
│             │ ├────────────────┼───────────────────────────────────────────────┤                            │
│             │ │ Match Position │ 5 - 46                                        │                            │
│             │ ├────────────────┼───────────────────────────────────────────────┤                            │
│             │ │ Line Number(s) │ 7: 8                                          │                            │
│             │ ├────────────────┼───────────────────────────────────────────────┤                            │
│             │ │ Match String   │ const { name } = req.query;                   │                            │
│             │ │                │     res.send('<h1> Hello :' + name + "</h1>") │                            │
│             │ ╘════════════════╧═══════════════════════════════════════════════╛                            │
╘═════════════╧═══════════════════════════════════════════════════════════════════════════════════════════════╛

nodejsscan SAST

nodejsscan は、njsscan の上に構築されており、他の便利な統合機能とともに、本格的な脆弱性管理ユーザーインターフェースを提供します。

nodejsscan web ui

nodejsscan を参照してください。

Python API

root@kitploit:~
>>> from njsscan.njsscan import NJSScan
>>> node_source = '/node_source/true_positives/sqli_node.js'
>>> scanner = NJSScan([node_source], json=True, check_controls=False)
>>> scanner.scan()
{
    'templates': {},
    'nodejs': {
        'node_sqli_injection': {
            'files': [{
                'file_path': '/node_source/true_positives/sqli_node.js',
                'match_position': (1, 24),
                'match_lines': (4, 11),
                'match_string': 'var employeeId = req.foo;\n\nvar sql = "SELECT * FROM trn_employee WHERE employee_id = " + employeeId;\n\n\n\nconnection.query(sql, function (error, results, fields) {\n\n    if (error) {\n\n        throw error;\n\n    }\n\n    console.log(results);'
            }],
            'metadata': {
                'owasp': 'A1: Injection',
                'cwe': "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
                'description': 'Untrusted input concatinated with raw SQL query can result in SQL Injection.',
                'severity': 'ERROR'
            }
        }
    },
    'errors': []
}

njsscan の設定

ソースコードディレクトリのルートにある .njsscan ファイルを使用すると、njsscan を設定できます。また、--config 引数を使用してカスタム .njsscan ファイルを使用することもできます。

root@kitploit:~
---
- nodejs-extensions:
  - .js

  template-extensions:
  - .new
  - .hbs
  - ''

  ignore-filenames:
  - skip.js

  ignore-paths:
  - __MACOSX
  - skip_dir
  - node_modules

  ignore-extensions:
  - .jsx

  ignore-rules:
  - regex_injection_dos
  - pug_jade_template

  severity-filter:
  - WARNING
  - ERROR

  severity-overrides:
    express_xss: WARNING
    node_secret: ERROR

検出結果の抑制

JavaScript ソースファイルで検出結果を抑制するには、検出をトリガーする行にコメント // njsscan-ignore: rule_id1, rule_id2 を追加します。

例:

root@kitploit:~
app.get('/some/redirect', function (req, res) {
    var target = req.param("target");
    res.redirect(target); // njsscan-ignore: express_open_redirect
});

CI/CD 統合

CI/CD または DevSecOps パイプラインで njsscan を有効にできます。

Github Action

次の内容をファイル .github/workflows/njsscan.yml に追加してください。

root@kitploit:~
name: njsscan
on:
  push:
    branches: [ master, main ]
  pull_request:
    branches: [ master, main ]
jobs:
  njsscan:
    runs-on: ubuntu-latest
    name: njsscan check
    steps:
    - name: Checkout the code
      uses: actions/checkout@v7
    - uses: actions/setup-python@v7
      with:
        python-version: '3.12'
    - name: nodejsscan scan
      id: njsscan
      uses: ajinabraham/njsscan-action@master
      with:
        args: '.'

例: njsscan GitHub Action を使用した dvna

Github Code Scanning 統合

次の内容をファイル .github/workflows/njsscan_sarif.yml に追加してください。

root@kitploit:~
name: njsscan sarif
on:
  push:
    branches: [ master, main ]
  pull_request:
    branches: [ master, main ]
jobs:
  njsscan:
    runs-on: ubuntu-latest
    name: njsscan code scanning
    steps:
    - name: Checkout the code
      uses: actions/checkout@v7
    - uses: actions/setup-python@v7
      with:
        python-version: '3.12'
    - name: nodejsscan scan
      id: njsscan
      uses: ajinabraham/njsscan-action@master
      with:
        args: '. --sarif --output results.sarif || true'
    - name: Upload njsscan report
      uses: github/codeql-action/upload-sarif@v3
      with:
        sarif_file: results.sarif

nodejsscan web ui

Gitlab CI/CD

次の内容をファイル .gitlab-ci.yml に追加してください。

root@kitploit:~
stages:
  - test

njsscan:
  image: python:3.12
  stage: test
  before_script:
    - pip3 install --upgrade njsscan
  script:
    - njsscan . --gitlab-sast -o gl-sast-report.json
  artifacts:
    reports:
      sast: gl-sast-report.json

コマンド例(ローカル):

root@kitploit:~
njsscan . --gitlab-sast -o gl-sast-report.json

これにより、ネイティブな GitLab SAST レポート が書き出され、SARIF コンバーターなしで脆弱性レポート / MR セキュリティウィジェットに検出結果が表示されます。

例: njsscan GitLab を使用した dvna

Travis CI

次の内容をファイル .travis.yml に追加してください。

root@kitploit:~
language: python
install:
    - pip3 install --upgrade njsscan
script:
    - njsscan .

Circle CI

次の内容をファイル .circleci/config.yaml に追加してください。

root@kitploit:~
version: 2.1
jobs:
  njsscan:
    docker:
      - image: cimg/python:3.9.6
    steps:
      - checkout
      - run:
          name: Install njsscan
          command: pip install --upgrade njsscan
      - run:
           name: njsscan check
           command: njsscan .

Docker

DockerHub のプレビルドイメージ

root@kitploit:~
docker pull opensecurity/njsscan
docker run -v /path-to-source-dir:/src opensecurity/njsscan /src

ローカルでのビルド

root@kitploit:~
docker build -t njsscan .
docker run -v /path-to-source-dir:/src njsscan /src
ツールをダウンロード