此仓库包含由 Trail of Bits 开发并向公众提供的 Semgrep 规则。它们是我们持续开发工作的一部分,并用于我们的安全审计、漏洞研究和内部项目。随着我们发现新技术,它们将不断演变。
如需 Semgrep 指导,请访问 Testing Handbook。
运行这些规则最简单的方式是从 Semgrep 注册表 运行它们。为此,请导航到项目的根目录并运行以下命令:```shell $ semgrep --config "p/trailofbits"
或者,您可以克隆此仓库,导航到项目的根文件夹,并使用以下命令单独运行规则:```shell
$ semgrep --config /path/to/semgrep-rules/semgreprule.yml
要从克隆的仓库运行所有规则:```shell $ semgrep --config /path/to/semgrep-rules/ .
## 实用标志
Semgrep 将针对所有受支持的代码文件运行,但 `.gitignore` 文件中指定的文件除外。如果你希望对包括 `.gitignore` 中列出的文件和目录在内的所有文件和目录运行规则,请添加 `--no-git-ignore` 标志。```shell
$ semgrep --config /path/to/semgrep-rules/ . --no-git-ignore
你也可以让 Semgrep 忽略匹配任何模式的文件和目录。例如,如果你想告诉 Semgrep 忽略所有 Go 测试文件,可以运行以下命令:```shell $ semgrep --config /path/to/semgrep-rules/ . --exclude='*_test.go'
使用 `-o` 将结果输出到文件:```shell
$ semgrep --config /path/to/semgrep-rules/hanging-goroutine.yml -o leaks.txt'
| ID | Playground | Impact | Confidence | 描述 |
|---|---|---|---|---|
| eth-rpc-tracetransaction | 🛝🔗 | 🟥 | 🌕 | 检测从 EVM 交易或区块中提取跟踪信息的尝试。在交易所或桥接应用中,必须实现额外的逻辑来封装这些端点,以防止回滚调用帧期间转移的值被计入。 |
| eth-txreceipt-status | 🛝🔗 | 🟥 | 🌕 | 检测读取交易回执状态的情况 |
| hanging-goroutine | 🛝🔗 | 🟩 | 🌗 | Goroutine 泄漏 |
| invalid-usage-of-modified-variable | 🛝🔗 | 🟧 | 🌘 | 发生错误时可能出现非预期的赋值 |
| iterate-over-empty-map | 🛝🔗 | 🟩 | 🌗 | 可能是在对空 map 进行冗余迭代 |
| missing-runlock-on-rwmutex | 🛝🔗 | 🟧 | 🌗 | 在函数返回前缺少对 RWMutex 锁的 RUnlock 操作 |
| ID | Playground | Impact | Confidence | 描述 |
|---|---|---|---|---|
| automatic-memory-pinning | 🛝🔗 | 🟩 | 🌘 | PyTorch 内存未自动固定 |
| lxml-in-pandas | 🛝🔗 | 🟧 | 🌘 | 在 pandas 中加载 lxml 可能导致 XXE 攻击 |
| msgpack-numpy | 🛝🔗 | 🟥 | 🌗 | 依赖 pickle 的函数可能导致任意代码执行 |
| numpy-distutils | 🛝🔗 | 🟩 | 🌘 | 使用了已弃用的 numpy.distutils |
| numpy-f2py-compile | 🛝🔗 | 🟥 | 🌗 | NumPy f2py 编译可能导致任意代码执行 |
| numpy-in-pytorch-datasets | 🛝🔗 | 🟩 | 🌘 |
| ID | Playground | Impact | Confidence | 描述 |
|---|---|---|---|---|
| panic-in-function-returning-result | 🛝🔗 | 🟩 | 🌘 | 在返回 Result 的函数中调用 unwrap 或 expect |
| ID | Playground | Impact | Confidence | 描述 |
|---|---|---|---|---|
| schema-directives | 🛝🔗 | 🟥 | 🌗 | 使用了过时的 ApolloServer 选项 'schemaDirectives' |
| use-of-graphql-upload | 🛝🔗 | 🟧 | 🌕 | 使用了 graphql-upload 库 |
| v3-potentially-bad-cors | 🛝🔗 | 🟧 | 🌕 | 可能存在问题的 CORS 策略 |
| v3-express-bad-cors | 🛝🔗 | 🟥 | 🌗 | 存在问题的 CORS 策略 |
| v3-express-no-cors | 🛝🔗 | 🟩 | 🌘 | 缺少 CORS 策略 |
| v3-bad-cors | 🛝🔗 | 🟥 | 🌗 | 存在问题的 CORS 策略 |
| ID | Playground | Impact | Confidence | 描述 |
|---|---|---|---|---|
| gc-call | 🛝🔗 | 🟩 | 🌘 | |
| mongo-hostname-verification-disabled | 🛝🔗 | 🟥 | 🌘 |
| -- | :--------: | :----: | :--------: | ----------- | | apt-key-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | apt-key-validate-certs-disabled | 🛝🔗 | 🟥 | 🌘 | | | apt-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | dnf-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | dnf-validate-certs-disabled | 🛝🔗 | 🟥 | 🌘 | | | get-url-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | get-url-validate-certs-disabled | 🛝🔗 | 🟥 | 🌘 | | | rpm-key-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | rpm-key-validate-certs-disabled | 🛝🔗 | 🟥 | 🌘 | | | unarchive-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | unarchive-validate-certs-disabled | 🛝🔗 | 🟥 | 🌘 | | | wrm-cert-validation-ignore | 🛝🔗 | 🟥 | 🌘 | | | yum-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | yum-validate-certs-disabled | 🛝🔗 | 🟥 | 🌘 | | | zypper-repository-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | zypper-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | port-all-interfaces | 🛝🔗 | 🟩 | 🌕 | | | aws-secret-key | 🛝🔗 | 🟧 | 🌘 | | | azure-principal-secret | 🛝🔗 | 🟧 | 🌘 | | | gcp-credentials-json | 🛝🔗 | 🟧 | 🌘 | | | jfrog-hardcoded-credential | 🛝🔗 | 🟧 | 🌘 | | | pypi-publish-password | 🛝🔗 | 🟧 | 🌘 | | | rubygems-publish-key | 🛝🔗 | 🟧 | 🌘 | | | vault-token | 🛝🔗 | 🟧 | 🌘 | |
| ID | 演练场 | 影响 | 置信度 | 描述 |
|---|---|---|---|---|
| insecure-url-host-hassuffix-check | 🛝🔗 | 🌫️ | 🌘 |
欢迎提交 Pull Requests 和 issues!
更多信息请参阅 CONTRIBUTING.md。
本仓库中定义的规则采用 AGPLv3 许可证。
附带的示例 可能 衍生自其他作品,并在需要时保留其原始许可证。
| missing-unlock-before-return | 🛝🔗 | 🟧 | 🌗 | 在函数返回前缺少 mutex 解锁操作 |
| nil-check-after-call | 🛝🔗 | 🟧 | 🌗 | 可能的空指针解引用 |
| racy-append-to-slice | 🛝🔗 | 🟧 | 🌗 | 多个 goroutine 并发调用 append |
| racy-write-to-map | 🛝🔗 | 🟧 | 🌗 | 多个 goroutine 并发写入同一个 map |
| servercodec-readrequestbody-unhandled-nil | 🛝🔗 | 🟩 | 🌘 | ServerCodec 接口实现可能不正确 |
| string-to-int-signedness-cast | 🛝🔗 | 🟧 | 🌘 | 整数下溢 |
| sync-mutex-value-copied | 🛝🔗 | 🟩 | 🌘 | 通过值接收器复制 sync.Mutex |
| unmarshal-tag-is-dash | 🛝🔗 | 🟧 | 🌘 |
| unmarshal-tag-is-omitempty | 🛝🔗 | 🟩 | 🌘 |
| unsafe-dll-loading | 🛝🔗 | 🟥 | 🌘 | 使用了易受 DLL 劫持攻击的函数 |
| waitgroup-add-called-inside-goroutine | 🛝🔗 | 🟧 | 🌗 | 在匿名 goroutine 中调用 sync.WaitGroup.Add |
| waitgroup-wait-inside-loop | 🛝🔗 | 🟧 | 🌗 | 在循环中调用 sync.WaitGroup.Wait |
在 Torch 数据集中调用 NumPy 随机数生成器 |
| numpy-in-pytorch-modules | 🛝🔗 | 🌫️ | 🌗 | 在 PyTorch 模块中使用 NumPy 函数 |
| numpy-load-library | 🛝🔗 | 🟥 | 🌗 | NumPy 库加载可能导致任意代码执行 |
| onnx-session-options | 🛝🔗 | 🟥 | 🌗 | ONNX 库加载可能导致任意代码执行 |
| pandas-eval | 🛝🔗 | 🟥 | 🌕 | pandas 中求值用户提供表达式的函数可能导致任意代码执行 |
| pickles-in-keras-deprecation | 🛝🔗 | 🟥 | 🌗 | Keras 的 load_model 函数可能导致任意代码执行 |
| pickles-in-keras | 🛝🔗 | 🟥 | 🌗 | Keras 的 load_model 函数可能导致任意代码执行 |
| pickles-in-numpy | 🛝🔗 | 🟥 | 🌗 | 依赖 pickle 的 NumPy 函数可能导致任意代码执行 |
| pickles-in-pandas | 🛝🔗 | 🟥 | 🌗 | 依赖 pickle 的 Pandas 函数可能导致任意代码执行 |
| pickles-in-pytorch-distributed | 🛝🔗 | 🟥 | 🌗 | 依赖 pickle 的 PyTorch.Distributed 函数可能导致任意代码执行 |
| pickles-in-pytorch | 🛝🔗 | 🟥 | 🌗 | 依赖 pickle 的 PyTorch 函数可能导致任意代码执行 |
| pickles-in-tensorflow | 🛝🔗 | 🟥 | 🌗 | tensorflow 的 load 函数可能导致任意代码执行 |
| pytorch-classes-load-library | 🛝🔗 | 🟥 | 🌗 | PyTorch 库加载可能导致任意代码执行 |
| pytorch-package | 🛝🔗 | 🟥 | 🌕 | torch.package 可能导致任意代码执行 |
| pytorch-tensor | 🛝🔗 | 🌫️ | 🌘 | 不正确的张量创建可能导致解析问题和效率低下 |
| scikit-joblib-load | 🛝🔗 | 🟥 | 🌗 | 依赖 pickle 的 SciKit.Joblib 函数可能导致任意代码执行 |
| tarfile-extractall-traversal | 🛝🔗 | 🟧 | 🌗 | 对 tarfile 调用 extractall 时可能存在路径遍历 |
| tensorflow-load-library | 🛝🔗 | 🟥 | 🌗 | TensorFlow 库加载可能导致任意代码执行 |
| waiting-with-pytorch-distributed | 🛝🔗 | 🟩 | 🌗 | 未等待请求时可能出现 PyTorch 未定义行为 |
| v3-no-cors | 🛝🔗 | 🟩 | 🌘 | 缺少 CORS 策略 |
| v3-csrf-prevention | 🛝🔗 | 🟧 | 🌘 | 缺少 CSRF 防护 |
| v4-csrf-prevention | 🛝🔗 | 🟧 | 🌘 | CSRF 防护已禁用 |
| 🛝🔗 |
| 🟩 |
| 🌘 |
| json-create-deserialization | 🛝🔗 | 🟥 | 🌕 |
| rails-cache-store-marshal | 🛝🔗 | 🟩 | 🌗 |
| rails-cookie-attributes | 🛝🔗 | 🟩 | 🌘 |
| rails-params-json | 🛝🔗 | 🟥 | 🌕 |
| rest-client-disable-verification | 🛝🔗 | 🟥 | 🌘 |
| ruby-saml-skip-validation | 🛝🔗 | 🟧 | 🌘 |
| yaml-unsafe-load | 🛝🔗 | 🟥 | 🌘 |
| 🛝🔗 |
| 🟥 |
| 🌘 |
| vault-hardcoded-token | 🛝🔗 | 🟥 | 🌘 |
| vault-skip-tls-verify | 🛝🔗 | 🟥 | 🌘 |
| 🟥 |
| 🌘 |
| mongodb-insecure-transport | 🛝🔗 | 🟥 | 🌘 |
| mysql-insecure-sslmode | 🛝🔗 | 🟥 | 🌗 |
| node-disable-certificate-validation | 🛝🔗 | 🟥 | 🌘 |
| openssl-insecure-flags | 🛝🔗 | 🟥 | 🌗 |
| postgres-insecure-sslmode | 🛝🔗 | 🟥 | 🌘 |
| redis-unencrypted-transport | 🛝🔗 | 🟥 | 🌘 |
| ssh-disable-host-key-checking | 🛝🔗 | 🟥 | 🌗 |
| tar-insecure-flags | 🛝🔗 | 🟥 | 🌗 |
| wget-no-check-certificate | 🛝🔗 | 🟥 | 🌗 |
| wget-unencrypted-url | 🛝🔗 | 🟥 | 🌗 |