首页 扩展程序 JS Vulnerability Detector

JS Vulnerability Detector

提供方: randysekvojta
1
开发者工具 288 位用户

插件简介

JavaSript Vulnerability Detector is a result of my Master Thesis at Brno University of Technology, Faculty of Information…
JavaSript Vulnerability Detector is a result of my Master Thesis at Brno University of Technology, Faculty of Information technology, graduation year 2022. The extension aims to add security features to the end-users of various websites containing vulnerable JavaScript library code. The principle of extension is following:

1. After page loads the extension scans all the JavaScript contained on the page and sends it to background script for processing.
2. If the script contains a known vulnerability (initial version focuses mostly on jQuery), it is tracked and shown in the extension popup. After detection the vulnerable script can be blocked, patched or left as is and only tracked.

All data is stored locally and can be cleared by a "Clear" button in the extension popup. There is no server communication going on, no data leaves the browser.

Extension runs in 4 modes:
1. disabled - no action
2. analyze - standard analysis only mode - no patching or blocking of vulnerable scripts
3. bloc - vulnerable scripts are removed from website
4. repair - experimental, vulnerable scripts are patched if possible

Currently it can detect vulnerable versions of jQuery (all up to 3.5.0) and repair them by updating them in runtime to 3.5.0 and couple more (around 30, including some of lodash, remarkjs, axios, handlebars and other vulnerabilities).

Source codes are open, available at https://github.com/xrandy00/mt_2022

其他信息

ID bmcojnncgfmglejiinbdnahmkmbgifhk 版本 1.0.0 上次更新日期 2022年12月12日 大小 459KiB 语言 支持1 种语言 开发者

randysekvojta@seznam.cz

适用浏览器

谷歌浏览器、其他Chromium内核的浏览器

JS Vulnerability Detector Chrome插件下载

为打击盗链困扰,本站已启用人机验证
微信扫码关注左侧公众号,发送“插件”二字获得验证码,验证码5分钟全站有效