Merge branch 'js-field'

main
Elbert Alias 7 years ago
commit 33c53bd639

@ -6,7 +6,7 @@ set -eu
echo "Validating apps.json..."
jsonlint-cli -s schema.json src/apps.json
jsonlint-cli -tps schema.json src/apps.json > /tmp/apps.json && mv /tmp/apps.json src/apps.json
echo "Validating regular expressions..."

@ -35,9 +35,9 @@
},
"required": true
},
"env": {
"type": [ "string", "array" ],
"items": {
"js": {
"type": "object",
"additionalProperties": {
"type": "string"
}
},

@ -38,6 +38,8 @@ class Driver {
this.wappalyzer.apps = json.apps;
this.wappalyzer.categories = json.categories;
this.wappalyzer.parseJsPatterns();
this.wappalyzer.driver.log = (message, source, type) => this.log(message, source, type);
this.wappalyzer.driver.displayApps = (detected, meta, context) => this.displayApps(detected, meta, context);
}
@ -123,34 +125,15 @@ class Driver {
.finally(() => {
this.timer('browser.wait end');
const headers = {};
browser.resources['0'].response.headers._headers.forEach(header => {
if ( !headers[header[0]] ){
headers[header[0]] = [];
}
headers[header[0]].push(header[1]);
});
let html = '';
try {
html = browser.html();
} catch ( e ) {
this.wappalyzer.log(error.message, 'browser', 'error');
}
const vars = Object.getOwnPropertyNames(browser.window);
const scripts = Array.prototype.slice
.apply(browser.document.scripts)
.filter(s => s.src)
.map(s => s.src);
const headers = this.getHeaders(browser);
const html = this.getHtml(browser);
const scripts = this.getScripts(browser);
const js = this.getJs(browser);
this.wappalyzer.analyze(pageUrl.hostname, pageUrl.href, {
headers,
html,
env: vars,
js,
scripts
});
@ -163,6 +146,70 @@ class Driver {
});
}
getHeaders(browser) {
const headers = {};
browser.resources['0'].response.headers._headers.forEach(header => {
if ( !headers[header[0]] ){
headers[header[0]] = [];
}
headers[header[0]].push(header[1]);
});
return headers;
}
getHtml(browser) {
let html = '';
try {
html = browser.html();
} catch ( e ) {
this.wappalyzer.log(error.message, 'browser', 'error');
}
return html;
}
getScripts(browser) {
const scripts = Array.prototype.slice
.apply(browser.document.scripts)
.filter(s => s.src)
.map(s => s.src);
return scripts;
}
getJs(browser) {
const patterns = this.wappalyzer.jsPatterns;
const js = {};
Object.keys(patterns).forEach(appName => {
js[appName] = {};
Object.keys(patterns[appName]).forEach(chain => {
js[appName][chain] = {};
patterns[appName][chain].forEach((pattern, index) => {
const properties = chain.split('.');
let value = properties.reduce((parent, property) => {
return parent && parent.hasOwnProperty(property) ? parent[property] : null;
}, browser.window);
value = typeof value === 'string' ? value : !!value;
if ( value ) {
js[appName][chain][index] = value;
}
});
});
});
return js;
}
crawl(pageUrl, index = 1, depth = 1) {
this.timer('crawl');

@ -1,58 +1,58 @@
/** global: browser */
if ( typeof browser !== 'undefined' && typeof document.body !== 'undefined' ) {
var html = document.documentElement.outerHTML;
try {
var html = document.documentElement.outerHTML;
if ( html.length > 50000 ) {
html = html.substring(0, 25000) + html.substring(html.length - 25000, html.length);
}
if ( html.length > 50000 ) {
html = html.substring(0, 25000) + html.substring(html.length - 25000, html.length);
}
var scripts = Array.prototype.slice
const scripts = Array.prototype.slice
.apply(document.scripts)
.filter(s => s.src)
.map(s => s.src);
try {
browser.runtime.sendMessage({
id: 'analyze',
subject: { html },
source: 'content.js'
});
.filter(script => script.src)
.map(script => script.src);
browser.runtime.sendMessage({
id: 'analyze',
subject: { scripts },
subject: { html, scripts },
source: 'content.js'
});
var container = document.createElement('wappalyzerData');
const script = document.createElement('script');
container.setAttribute('id', 'wappalyzerData');
container.setAttribute('style', 'display: none');
script.onload = () => {
addEventListener('message', event => {
if ( event.data.id !== 'js' ) {
return;
}
var script = document.createElement('script');
browser.runtime.sendMessage({
id: 'analyze',
subject: {
js: event.data.js
},
source: 'content.js'
});
}, true);
script.setAttribute('id', 'wappalyzerEnvDetection');
script.setAttribute('src', browser.extension.getURL('js/inject.js'));
container.addEventListener('wappalyzerEvent', (event => {
var env = event.target.childNodes[0].nodeValue;
document.documentElement.removeChild(container);
document.documentElement.removeChild(script);
env = env.split(' ').slice(0, 500);
browser.runtime.sendMessage({
id: 'analyze',
subject: { env },
( chrome || browser ).runtime.sendMessage({
id: 'init_js',
subject: {},
source: 'content.js'
}, response => {
postMessage({
id: 'patterns',
patterns: response.patterns
}, '*');
});
}), true);
};
script.setAttribute('id', 'wappalyzer');
script.setAttribute('src', browser.extension.getURL('js/inject.js'));
document.documentElement.appendChild(container);
document.documentElement.appendChild(script);
} catch(e) {
document.body.appendChild(script);
} catch (e) {
log(e);
}
}

@ -75,6 +75,8 @@ fetch('../apps.json')
wappalyzer.apps = json.apps;
wappalyzer.categories = json.categories;
wappalyzer.parseJsPatterns();
categoryOrder = Object.keys(wappalyzer.categories).sort((a, b) => wappalyzer.categories[a].priority - wappalyzer.categories[b].priority);
})
.catch(error => {
@ -191,6 +193,12 @@ browser.webRequest.onCompleted.addListener(request => {
categories: wappalyzer.categories
};
break;
case 'init_js':
response = {
patterns: wappalyzer.jsPatterns
};
break;
default:
}

@ -1,16 +1,43 @@
(function() {
try {
var i, environmentVars = '', e = document.createEvent('Events');
addEventListener('message', (event => {
if ( event.data.id !== 'patterns' ) {
return;
}
e.initEvent('wappalyzerEvent', true, false);
const patterns = event.data.patterns || {};
for ( i in window ) {
environmentVars += i + ' ';
}
const js = {};
document.getElementById('wappalyzerData').appendChild(document.createComment(environmentVars));
document.getElementById('wappalyzerData').dispatchEvent(e);
} catch(e) {
// Fail quietly
}
Object.keys(patterns).forEach(appName => {
js[appName] = {};
Object.keys(patterns[appName]).forEach(chain => {
js[appName][chain] = {};
patterns[appName][chain].forEach((pattern, index) => {
const value = detectJs(chain);
if ( value ) {
js[appName][chain][index] = value;
}
});
});
});
postMessage({ id: 'js', js }, '*');
}), false);
} catch(e) {
// Fail quietly
}
}());
function detectJs(chain) {
const properties = chain.split('.');
const value = properties.reduce((parent, property) => {
return parent && parent.hasOwnProperty(property) ? parent[property] : null;
}, window);
return typeof value === 'string' ? value : !!value;
}

Binary file not shown.

Before

Width:  |  Height:  |  Size: 247 B

Binary file not shown.

Before

Width:  |  Height:  |  Size: 140 B

@ -18,6 +18,7 @@ class Wappalyzer {
this.apps = {};
this.categories = {};
this.driver = {};
this.jsPatterns = {};
this.detected = {};
this.hostnameCache = {};
@ -87,6 +88,12 @@ class Wappalyzer {
}
})
if ( data.js ) {
Object.keys(data.js).forEach(appName => {
this.analyzeJs(apps[appName], data.js[appName]);
});
}
Object.keys(apps).forEach(appName => {
var app = apps[appName];
@ -249,6 +256,17 @@ class Wappalyzer {
return parsed;
}
/**
* Parse JavaScript patterns
*/
parseJsPatterns() {
Object.keys(this.apps).forEach(appName => {
if ( this.apps[appName].js ) {
this.jsPatterns[appName] = this.parsePatterns(this.apps[appName].js);
}
});
}
resolveExcludes(apps) {
var excludes = [];
@ -487,6 +505,25 @@ class Wappalyzer {
}
}
/**
* Analyze JavaScript variables
*/
analyzeJs(app, results) {
console.log(app, results);
Object.keys(results).forEach(string => {
Object.keys(results[string]).forEach(index => {
const pattern = this.jsPatterns[app.name][string][index];
const value = results[string][index];
if ( pattern.regex.test(value) ) {
this.addDetected(app, pattern, 'js', value);
}
});
});
}
/**
* Analyze robots.txt
*/