Skip to content

Latest commit

Β 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Code Injection

$ explode-js full index.js
[STEP 1] MDG: Generating...

[STEP 1] MDG: Completed.
[STEP 2] Queries: Importing the graph...
[INFO] Stop running Neo4j local instance.
[INFO] Import MDG to Neo4j.
[INFO] Starting Neo4j
[STEP 2] Queries: Imported
[STEP 3] Queries: Traversing Graph...
[INFO] Running injection query.
[INFO] Reconstructing attacker-controlled data.
[INFO] Assigning types to attacker-controlled data.
[INFO] Assigning types to attacker-controlled data.
[INFO] Assigning types to attacker-controlled data.
[INFO] Assigning types to attacker-controlled data.
[INFO] Running prototype pollution query.
[INFO] Prototype Pollution - Reconstructing attacker-controlled data.
[INFO] Assigning types to attacker-controlled data.
[INFO] Assigning types to attacker-controlled data.
[INFO] Assigning types to attacker-controlled data.
[INFO] Assigning types to attacker-controlled data.
[INFO] Assigning types to attacker-controlled data.
[INFO] Assigning types to attacker-controlled data.
[INFO] Detected 7 vulnerabilities.
[STEP 3] Queries: Completed.
── PHASE 1: TEMPLATE GENERATION ──
βœ” Loaded: _results/taint_summary.json
βš’ Generating 28 template(s):
β”œβ”€β”€ πŸ“„ ./symbolic_test_0.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_1.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_2.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_3.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_4.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_5.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_6.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_7.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_8.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_9.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_10.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_11.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_12.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_13.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_14.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_15.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_16.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_17.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_18.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_19.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_20.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_21.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_22.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_23.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_24.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_25.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_26.js
β”œβ”€β”€ πŸ“„ ./symbolic_test_27.js

── PHASE 2: ANALYSIS & VALIDATION ──
β—‰ [1/28] Procesing ./symbolic_test_0.js
β”œβ”€β”€ Symbolic execution output:
Eval failure: (str.++ ("(",
               (str.substr dp0 13
                (int.add
                 (int.sub
                  (int.reinterpret_float
                   (real.reinterpret_int (str.length dp0))) 13) 1)), ")"))
β”œβ”€β”€ Symbolic execution stats: clock: 32.300943s | solver: 31.997247s
β”œβ”€β”€ ⚠ Detected 1 issue(s)!
β”‚   β”œβ”€β”€ β†Ί Replaying 4 test case(s)
β”‚   β”‚   β”œβ”€β”€ πŸ“„ [1/4] Using test case: ./symbolic_test_0/test-suite/witness-0.json
β”‚   β”‚   β”‚   β”œβ”€β”€ Node exited with 1
β”‚   β”‚   β”‚   └── βœ– Status: No side effect
β”‚   β”‚   β”œβ”€β”€ πŸ“„ [2/4] Using test case: ./symbolic_test_0/test-suite/witness-1.json
β”‚   β”‚   β”‚   β”œβ”€β”€ Node exited with 0
β”‚   β”‚   β”‚   └── βœ” Status: Success ("success" in stdout)
β”‚   β”‚   β”œβ”€β”€ πŸ“„ [3/4] Using test case: ./symbolic_test_0/test-suite/witness-2.json
β”‚   β”‚   β”‚   β”œβ”€β”€ Node exited with 0
β”‚   β”‚   β”‚   └── βœ” Status: Success ("success" in stdout)