srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md53
1 files changed, 49 insertions, 4 deletions
diff --git a/PLAN.md b/PLAN.md
index 9a53d0e..014c902 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -973,7 +973,52 @@ visually in the TUI with the JSON-array tag data rendering correctly
(the first tag payload to exercise `jsoncolor.go`'s top-level-array
path outside its own unit tests).
-Next: the remaining Phase 1 plugins (Backslash Powered Scanner,
-Retire.js - no new protocol capability needed, same pattern `authcheck`
-and `paramminer` already validate), then the live-RPC protocol addition
-for JWT Editor/SAML Raider.
+### Third plugin shipped: `plugins/jslibscan`
+
+A Retire.js-style passive scanner for known-vulnerable JavaScript
+library versions - and, deliberately, the first purely passive plugin:
+subscribe, inspect a response body already captured by ordinary
+proxying, tag, nothing else. No `repeat` calls at all, unlike
+`authcheck` and `paramminer`. Worth having one of these in the
+reference set specifically because it's the shape least likely to
+surprise anyone running it against traffic they can't afford to
+actively probe - the safest possible plugin to try first.
+
+Checks any JS library version string it can find in a response body
+against a small, explicitly-illustrative built-in table (five
+libraries - jQuery, Lodash, Handlebars, Moment.js, AngularJS - one
+well-known vulnerable-version threshold each), tagging a match
+`jslibscan:hit` with the version found, the first fixed version, and a
+one-line advisory. Deliberately NOT a maintained vulnerability feed the
+way real Retire.js's continuously-updated JSON database is; documented
+as such in the plugin's own package doc, since claiming otherwise would
+be misleading. CVE numbers deliberately omitted from the advisory text
+in favor of a plain description of the vulnerability class - precise
+enough to be useful, without asserting a specific CVE identifier this
+reference implementation hasn't independently verified against.
+
+Found and fixed a real regex bug while verifying this one live rather
+than trusting it from the code: the first version matched jQuery's own
+actual banner comment ("jQuery v1.8.3") against nothing at all, because
+the separator pattern only allowed a single non-digit character between
+the library name and its version digits, and that banner has two (a
+space, then "v"). Confirmed the failure directly, then confirmed the
+fix against three real-world version-string shapes at once - banner
+comment, minified filename ("jquery-3.4.1.min.js"), and cache-busting
+query string ("jquery.min.js?v=1.11.0") - before it went back into the
+plugin, using a bounded non-greedy gap (`.{0,15}?`) between name and
+version rather than trying to enumerate every separator combination.
+
+Verified live end to end: a real daemon, a real origin serving both an
+outdated jQuery 1.8.3 banner and a current 3.7.1 one - the outdated
+file was correctly tagged with the right version and fix threshold, the
+current one correctly left alone, confirmed via the JSON-array tag data
+in the TUI. The same run also incidentally reconfirmed the regex fix
+was real: an entry captured *before* the fix (same file, same content,
+requested moments earlier against the buggy binary) sat right next to
+the correctly-tagged one in the history list, untagged.
+
+Next: the remaining Phase 1 plugin (Backslash Powered Scanner - no new
+protocol capability needed, same pattern the three shipped plugins
+already validate), then the live-RPC protocol addition for JWT
+Editor/SAML Raider.