diff options
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 53 |
1 files changed, 49 insertions, 4 deletions
@@ -973,7 +973,52 @@ visually in the TUI with the JSON-array tag data rendering correctly (the first tag payload to exercise `jsoncolor.go`'s top-level-array path outside its own unit tests). -Next: the remaining Phase 1 plugins (Backslash Powered Scanner, -Retire.js - no new protocol capability needed, same pattern `authcheck` -and `paramminer` already validate), then the live-RPC protocol addition -for JWT Editor/SAML Raider. +### Third plugin shipped: `plugins/jslibscan` + +A Retire.js-style passive scanner for known-vulnerable JavaScript +library versions - and, deliberately, the first purely passive plugin: +subscribe, inspect a response body already captured by ordinary +proxying, tag, nothing else. No `repeat` calls at all, unlike +`authcheck` and `paramminer`. Worth having one of these in the +reference set specifically because it's the shape least likely to +surprise anyone running it against traffic they can't afford to +actively probe - the safest possible plugin to try first. + +Checks any JS library version string it can find in a response body +against a small, explicitly-illustrative built-in table (five +libraries - jQuery, Lodash, Handlebars, Moment.js, AngularJS - one +well-known vulnerable-version threshold each), tagging a match +`jslibscan:hit` with the version found, the first fixed version, and a +one-line advisory. Deliberately NOT a maintained vulnerability feed the +way real Retire.js's continuously-updated JSON database is; documented +as such in the plugin's own package doc, since claiming otherwise would +be misleading. CVE numbers deliberately omitted from the advisory text +in favor of a plain description of the vulnerability class - precise +enough to be useful, without asserting a specific CVE identifier this +reference implementation hasn't independently verified against. + +Found and fixed a real regex bug while verifying this one live rather +than trusting it from the code: the first version matched jQuery's own +actual banner comment ("jQuery v1.8.3") against nothing at all, because +the separator pattern only allowed a single non-digit character between +the library name and its version digits, and that banner has two (a +space, then "v"). Confirmed the failure directly, then confirmed the +fix against three real-world version-string shapes at once - banner +comment, minified filename ("jquery-3.4.1.min.js"), and cache-busting +query string ("jquery.min.js?v=1.11.0") - before it went back into the +plugin, using a bounded non-greedy gap (`.{0,15}?`) between name and +version rather than trying to enumerate every separator combination. + +Verified live end to end: a real daemon, a real origin serving both an +outdated jQuery 1.8.3 banner and a current 3.7.1 one - the outdated +file was correctly tagged with the right version and fix threshold, the +current one correctly left alone, confirmed via the JSON-array tag data +in the TUI. The same run also incidentally reconfirmed the regex fix +was real: an entry captured *before* the fix (same file, same content, +requested moments earlier against the buggy binary) sat right next to +the correctly-tagged one in the history list, untagged. + +Next: the remaining Phase 1 plugin (Backslash Powered Scanner - no new +protocol capability needed, same pattern the three shipped plugins +already validate), then the live-RPC protocol addition for JWT +Editor/SAML Raider. |