r13658 - in Products.PortalTransforms/branches/1.6/Products/PortalTransforms: tests transforms
"David Glick" <[email protected]> Thu, 02 Jun 2011 03:49:56 +0000
| Newsgroups | gmane.comp.web.zope.plone.archetypes.cvs |
|---|---|
| Message-ID | <[email protected]> |
Author: davisagli
Date: Thu Jun 2 03:49:55 2011
New Revision: 13658
Modified:
Products.PortalTransforms/branches/1.6/Products/PortalTransforms/tests/test_xss.py
Products.PortalTransforms/branches/1.6/Products/PortalTransforms/transforms/safe_html.py
Log:
fix indentation
Modified: Products.PortalTransforms/branches/1.6/Products/PortalTransforms/tests/test_xss.py
==============================================================================
--- Products.PortalTransforms/branches/1.6/Products/PortalTransforms/tests/test_xss.py (original)
+++ Products.PortalTransforms/branches/1.6/Products/PortalTransforms/tests/test_xss.py Thu Jun 2 03:49:55 2011
@@ -2,7 +2,7 @@
"""
import os, sys
if __name__ == '__main__':
- execfile(os.path.join(sys.path[0], 'framework.py'))
+ execfile(os.path.join(sys.path[0], 'framework.py'))
from Testing import ZopeTestCase
from Products.Archetypes.tests.atsitetestcase import ATSiteTestCase
@@ -10,145 +10,145 @@
class TestXSSFilter(ATSiteTestCase):
- def afterSetUp(self):
- ATSiteTestCase.afterSetUp(self)
- self.engine = self.portal.portal_transforms
-
- def doTest(self, data_in, data_out):
- html = self.engine.convertTo('text/x-html-safe', data_in, mimetype="text/html")
- assert(html.getData())
- self.assertEqual (data_out,html.getData())
-
-
-
- def test_1(self):
- data_in = """<html><body><img src="javascript:Alert('XSS');" /></body></html>"""
- data_out = """<img />"""
- self.doTest(data_in, data_out)
-
- def test_2(self):
- data_in = """<img src="javascript:Alert('XSS');" />"""
- data_out = """<img />"""
- self.doTest(data_in, data_out)
-
- def test_3(self):
- data_in = """<html><body><IMG SRC=javascript:alert('XSS')></body></html>"""
- data_out = """<img />"""
- self.doTest(data_in, data_out)
-
- def test_4(self):
- data_in = """<IMG SRC=javascript:alert('XSS')>"""
- data_out = """<img />"""
-
- self.doTest(data_in, data_out)
-
- def test_5(self):
- data_in = """<img src="jav
- asc
- ript:Alert('XSS');" />"""
- data_out = """<img />"""
- self.doTest(data_in, data_out)
-
-
- def test_6(self):
- data_in = """<img src="jav asc ript:Alert('XSS');"/>"""
- data_out = """<img />"""
- self.doTest(data_in, data_out)
-
- def test_7(self):
- data_in = """<a href=javascript:alert('XSS')>test med a-tag</a>"""
- data_out = """<a>test med a-tag</a>"""
- self.doTest(data_in, data_out)
-
- def test_8(self):
- data_in = """<div style="bacground:url(jav asc ript:Alert('XSS')">test</div>"""
- data_out = """<div>test</div>"""
- self.doTest(data_in, data_out)
-
- def test_9(self):
- data_in = """<div style="bacground:url(jav
- asc
- ript:
- Alert('XSS')">test</div>"""
- data_out = """<div>test</div>"""
- self.doTest(data_in, data_out)
-
- def test_10(self):
- data_in = """<div style="bacground:url(javascript:alert('XSS')">test</div>"""
- data_out = """<div>test</div>"""
- self.doTest(data_in, data_out)
-
- def test_11(self):
- data_in = """<div style="bacground:url(v b sc ript:msgbox('XSS')">test</div>"""
- data_out = """<div>test</div>"""
- self.doTest(data_in, data_out)
-
- def test_12(self):
- data_in = """<img src="vbscript:msgbox('XSS')"/>"""
- data_out = """<img />"""
- self.doTest(data_in, data_out)
-
- def test_13(self):
- data_in = """<img src="vb
- sc
- ript:msgbox('XSS')"/>"""
- data_out = """<img />"""
- self.doTest(data_in, data_out)
-
- def test_14(self):
- data_in = """<a href="vbscript:Alert('XSS')">test</a>"""
- data_out = """<a>test</a>"""
- self.doTest(data_in, data_out)
-
- def test_15(self):
- data_in = """<div STYLE="width: expression(window.location='http://www.dr.dk';);">div</div>"""
- data_out = """<div>div</div>"""
- self.doTest(data_in, data_out)
-
- def test_16(self):
- data_in = """<div STYLE="width: ex pre ss io n(window.location='http://www.dr.dk';);">div</div>"""
- data_out = """<div>div</div>"""
- self.doTest(data_in, data_out)
-
- def test_17(self):
- data_in = """<div STYLE="width: ex
- pre
- ss
- io
- n(window.location='http://www.dr.dk';);">div</div>"""
- data_out = """<div>div</div>"""
- self.doTest(data_in, data_out)
-
- def test_18(self):
- data_in = """<div style="width: 14px;">div</div>"""
- data_out = data_in
- self.doTest(data_in, data_out)
-
- def test_19(self):
- data_in = """<a href="http://www.headnet.dk">headnet</a>"""
- data_out = data_in
- self.doTest(data_in, data_out)
-
- def test_20(self):
- data_in = """<img src="http://www.headnet.dk/log.jpg" />"""
- data_out = data_in
- self.doTest(data_in, data_out)
-
- def test_21(self):
- data_in = """<mustapha name="mustap" tlf="11 11 11 11" address="unknown">bla bla bla</mustapha>"""
- data_out = """bla bla bla"""
- self.doTest(data_in, data_out)
-
- def test_22(self):
- data_in = '<<frame></frame>script>alert("XSS");<<frame></frame>/script>'
- data_out = '<script>alert("XSS");</script>'
- self.doTest(data_in, data_out)
+ def afterSetUp(self):
+ ATSiteTestCase.afterSetUp(self)
+ self.engine = self.portal.portal_transforms
+
+ def doTest(self, data_in, data_out):
+ html = self.engine.convertTo('text/x-html-safe', data_in, mimetype="text/html")
+ assert(html.getData())
+ self.assertEqual (data_out,html.getData())
+
+
+
+ def test_1(self):
+ data_in = """<html><body><img src="javascript:Alert('XSS');" /></body></html>"""
+ data_out = """<img />"""
+ self.doTest(data_in, data_out)
+
+ def test_2(self):
+ data_in = """<img src="javascript:Alert('XSS');" />"""
+ data_out = """<img />"""
+ self.doTest(data_in, data_out)
+
+ def test_3(self):
+ data_in = """<html><body><IMG SRC=javascript:alert('XSS')></body></html>"""
+ data_out = """<img />"""
+ self.doTest(data_in, data_out)
+
+ def test_4(self):
+ data_in = """<IMG SRC=javascript:alert('XSS')>"""
+ data_out = """<img />"""
+
+ self.doTest(data_in, data_out)
+
+ def test_5(self):
+ data_in = """<img src="jav
+ asc
+ ript:Alert('XSS');" />"""
+ data_out = """<img />"""
+ self.doTest(data_in, data_out)
+
+
+ def test_6(self):
+ data_in = """<img src="jav asc ript:Alert('XSS');"/>"""
+ data_out = """<img />"""
+ self.doTest(data_in, data_out)
+
+ def test_7(self):
+ data_in = """<a href=javascript:alert('XSS')>test med a-tag</a>"""
+ data_out = """<a>test med a-tag</a>"""
+ self.doTest(data_in, data_out)
+
+ def test_8(self):
+ data_in = """<div style="bacground:url(jav asc ript:Alert('XSS')">test</div>"""
+ data_out = """<div>test</div>"""
+ self.doTest(data_in, data_out)
+
+ def test_9(self):
+ data_in = """<div style="bacground:url(jav
+ asc
+ ript:
+ Alert('XSS')">test</div>"""
+ data_out = """<div>test</div>"""
+ self.doTest(data_in, data_out)
+
+ def test_10(self):
+ data_in = """<div style="bacground:url(javascript:alert('XSS')">test</div>"""
+ data_out = """<div>test</div>"""
+ self.doTest(data_in, data_out)
+
+ def test_11(self):
+ data_in = """<div style="bacground:url(v b sc ript:msgbox('XSS')">test</div>"""
+ data_out = """<div>test</div>"""
+ self.doTest(data_in, data_out)
+
+ def test_12(self):
+ data_in = """<img src="vbscript:msgbox('XSS')"/>"""
+ data_out = """<img />"""
+ self.doTest(data_in, data_out)
+
+ def test_13(self):
+ data_in = """<img src="vb
+ sc
+ ript:msgbox('XSS')"/>"""
+ data_out = """<img />"""
+ self.doTest(data_in, data_out)
+
+ def test_14(self):
+ data_in = """<a href="vbscript:Alert('XSS')">test</a>"""
+ data_out = """<a>test</a>"""
+ self.doTest(data_in, data_out)
+
+ def test_15(self):
+ data_in = """<div STYLE="width: expression(window.location='http://www.dr.dk';);">div</div>"""
+ data_out = """<div>div</div>"""
+ self.doTest(data_in, data_out)
+
+ def test_16(self):
+ data_in = """<div STYLE="width: ex pre ss io n(window.location='http://www.dr.dk';);">div</div>"""
+ data_out = """<div>div</div>"""
+ self.doTest(data_in, data_out)
+
+ def test_17(self):
+ data_in = """<div STYLE="width: ex
+ pre
+ ss
+ io
+ n(window.location='http://www.dr.dk';);">div</div>"""
+ data_out = """<div>div</div>"""
+ self.doTest(data_in, data_out)
+
+ def test_18(self):
+ data_in = """<div style="width: 14px;">div</div>"""
+ data_out = data_in
+ self.doTest(data_in, data_out)
+
+ def test_19(self):
+ data_in = """<a href="http://www.headnet.dk">headnet</a>"""
+ data_out = data_in
+ self.doTest(data_in, data_out)
+
+ def test_20(self):
+ data_in = """<img src="http://www.headnet.dk/log.jpg" />"""
+ data_out = data_in
+ self.doTest(data_in, data_out)
+
+ def test_21(self):
+ data_in = """<mustapha name="mustap" tlf="11 11 11 11" address="unknown">bla bla bla</mustapha>"""
+ data_out = """bla bla bla"""
+ self.doTest(data_in, data_out)
+
+ def test_22(self):
+ data_in = '<<frame></frame>script>alert("XSS");<<frame></frame>/script>'
+ data_out = '<script>alert("XSS");</script>'
+ self.doTest(data_in, data_out)
def test_suite():
- from unittest import TestSuite, makeSuite
- suite = TestSuite()
- suite.addTest(makeSuite(TestXSSFilter))
- return suite
+ from unittest import TestSuite, makeSuite
+ suite = TestSuite()
+ suite.addTest(makeSuite(TestXSSFilter))
+ return suite
if __name__ == '__main__':
- framework()
+ framework()
Modified: Products.PortalTransforms/branches/1.6/Products/PortalTransforms/transforms/safe_html.py
==============================================================================
--- Products.PortalTransforms/branches/1.6/Products/PortalTransforms/transforms/safe_html.py (original)
+++ Products.PortalTransforms/branches/1.6/Products/PortalTransforms/transforms/safe_html.py Thu Jun 2 03:49:55 2011
@@ -42,40 +42,40 @@
"""
def hasScript(s):
- """Dig out evil Java/VB script inside an HTML attribute.
-
- >>> hasScript('script:evil(1);')
- True
- >>> hasScript('expression:evil(1);')
- True
- >>> hasScript('http://foo.com/ExpressionOfInterest.doc')
- False
- """
- s = decode_htmlentities(s)
- s = ''.join(s.split()).lower()
- for t in ('script:', 'expression:', 'expression('):
- if t in s:
- return True
- return False
+ """Dig out evil Java/VB script inside an HTML attribute.
+
+ >>> hasScript('script:evil(1);')
+ True
+ >>> hasScript('expression:evil(1);')
+ True
+ >>> hasScript('http://foo.com/ExpressionOfInterest.doc')
+ False
+ """
+ s = decode_htmlentities(s)
+ s = ''.join(s.split()).lower()
+ for t in ('script:', 'expression:', 'expression('):
+ if t in s:
+ return True
+ return False
def decode_htmlentities(s):
- """ XSS code can be hidden with htmlentities """
+ """ XSS code can be hidden with htmlentities """
- entity_pattern = re.compile("&#(?P<htmlentity>x?\w+)?;?")
- s = entity_pattern.sub(decode_htmlentity,s)
- return s
+ entity_pattern = re.compile("&#(?P<htmlentity>x?\w+)?;?")
+ s = entity_pattern.sub(decode_htmlentity,s)
+ return s
def decode_htmlentity(m):
- entity_value = m.groupdict()['htmlentity']
- if entity_value.lower().startswith('x'):
- try:
- return chr(int('0'+entity_value,16))
- except ValueError:
- return entity_value
- try:
- return chr(int(entity_value))
- except ValueError:
- return entity_value
+ entity_value = m.groupdict()['htmlentity']
+ if entity_value.lower().startswith('x'):
+ try:
+ return chr(int('0'+entity_value,16))
+ except ValueError:
+ return entity_value
+ try:
+ return chr(int(entity_value))
+ except ValueError:
+ return entity_value
class StrippingParser(SGMLParser):
"""Pass only allowed tags; raise exception for known-bad.
------------------------------------------------------------------------------
Simplify data backup and recovery for your virtual environment with vRanger.
Installation's a snap, and flexible recovery options mean your data is safe,
secure and there when you need it. Data protection magic?
Nope - It's vRanger. Get your free trial download today.
http://p.sf.net/sfu/quest-sfdev2dev