2010-11-05 00:05:34 +00:00
|
|
|
#!/usr/bin/env ruby
|
|
|
|
#
|
|
|
|
# Check (recursively) for style compliance violations and other
|
|
|
|
# tree inconsistencies.
|
|
|
|
#
|
2012-01-10 20:53:20 +00:00
|
|
|
# by jduck and friends
|
2010-11-05 00:05:34 +00:00
|
|
|
#
|
|
|
|
|
2011-12-12 21:12:01 +00:00
|
|
|
CHECK_OLD_RUBIES = !!ENV['MSF_CHECK_OLD_RUBIES']
|
|
|
|
|
|
|
|
if CHECK_OLD_RUBIES
|
|
|
|
require 'rvm'
|
|
|
|
warn "This is going to take a while, depending on the number of Rubies you have installed."
|
|
|
|
end
|
2011-10-16 15:53:19 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
class String
|
|
|
|
def red
|
|
|
|
"\e[1;31;40m#{self}\e[0m"
|
|
|
|
end
|
2010-11-05 00:05:34 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
def yellow
|
|
|
|
"\e[1;33;40m#{self}\e[0m"
|
|
|
|
end
|
2010-11-05 00:05:34 +00:00
|
|
|
end
|
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
class Msftidy
|
2011-12-12 21:12:01 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
LONG_LINE_LENGTH = 200 # From 100 to 200 which is stupidly long
|
|
|
|
|
|
|
|
def initialize(source_file)
|
|
|
|
@source = load_file(source_file)
|
|
|
|
@name = source_file
|
|
|
|
end
|
2010-11-05 00:05:34 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
public
|
2010-11-05 00:05:34 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
##
|
|
|
|
#
|
2012-12-12 17:41:36 +00:00
|
|
|
# The following two functions only print what you throw at them,
|
|
|
|
# with the option of displying the line number. error() is meant
|
|
|
|
# for mistakes that might actually break something.
|
2012-10-12 07:55:16 +00:00
|
|
|
#
|
|
|
|
##
|
2010-11-05 00:05:34 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
def warn(txt, line=0)
|
|
|
|
line_msg = (line>0) ? ":#{line.to_s}" : ''
|
|
|
|
puts "#{@name}#{line_msg} - [#{'WARNING'.yellow}] #{txt}"
|
|
|
|
end
|
2010-11-05 00:05:34 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
def error(txt, line=0)
|
|
|
|
line_msg = (line>0) ? ":#{line.to_s}" : ''
|
|
|
|
puts "#{@name}#{line_msg} - [#{'ERROR'.red}] #{txt}"
|
|
|
|
end
|
2011-12-12 21:12:01 +00:00
|
|
|
|
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
##
|
|
|
|
#
|
|
|
|
# The functions below are actually the ones checking the source code
|
|
|
|
#
|
|
|
|
##
|
2010-11-05 00:05:34 +00:00
|
|
|
|
2012-12-12 20:27:08 +00:00
|
|
|
def check_old_keywords
|
|
|
|
max_count = 10
|
|
|
|
counter = 0
|
|
|
|
if @source =~ /^##/
|
|
|
|
@source.each_line do |line|
|
|
|
|
# If exists, the $Id$ keyword should appear at the top of the code.
|
|
|
|
# If not (within the first 10 lines), then we assume there's no
|
|
|
|
# $Id$, and then bail.
|
|
|
|
break if counter >= max_count
|
|
|
|
|
|
|
|
if line =~ /^#[[:space:]]*\$Id\$/i
|
|
|
|
warn("Keyword $Id$ is no longer needed.")
|
|
|
|
break
|
|
|
|
end
|
|
|
|
|
|
|
|
counter += 1
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-12-12 21:47:04 +00:00
|
|
|
if @source =~ /'Version'[[:space:]]*=>[[:space:]]*['"]\$Revision\$['"]/
|
2012-12-12 20:27:08 +00:00
|
|
|
warn("Keyword $Revision$ is no longer needed.")
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-12-11 22:17:29 +00:00
|
|
|
def check_badchars
|
|
|
|
badchars = %Q|&<=>|
|
|
|
|
|
2012-12-12 17:41:36 +00:00
|
|
|
in_super = false
|
|
|
|
in_author = false
|
2012-12-11 22:17:29 +00:00
|
|
|
|
|
|
|
@source.each_line do |line|
|
|
|
|
#
|
|
|
|
# Mark our "super" code block
|
|
|
|
#
|
2012-12-12 17:57:28 +00:00
|
|
|
if !in_super and line =~ /[\n\t]+super\(/
|
2012-12-11 22:17:29 +00:00
|
|
|
in_super = true
|
2012-12-12 17:41:36 +00:00
|
|
|
elsif in_super and line =~ /[[:space:]]*def \w+[\(\w+\)]*/
|
|
|
|
in_super = false
|
|
|
|
break
|
2012-12-11 22:17:29 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
#
|
|
|
|
# While in super() code block
|
|
|
|
#
|
|
|
|
if in_super and line =~ /'Name'[[:space:]]*=>[[:space:]]*['|"](.+)['|"]/
|
|
|
|
# Now we're checking the module titlee
|
|
|
|
mod_title = $1
|
|
|
|
mod_title.each_char do |c|
|
|
|
|
if badchars.include?(c)
|
|
|
|
error("'#{c}' is a bad character in module title.")
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
if not mod_title.ascii_only?
|
|
|
|
error("Please avoid unicode in module title.")
|
|
|
|
end
|
|
|
|
|
|
|
|
# Since we're looking at the module title, this line clearly cannot be
|
|
|
|
# the author block, so no point to run more code below.
|
|
|
|
next
|
|
|
|
end
|
|
|
|
|
|
|
|
#
|
|
|
|
# Mark our 'Author' block
|
|
|
|
#
|
|
|
|
if in_super and !in_author and line =~ /'Author'[[:space:]]*=>/
|
|
|
|
in_author = true
|
|
|
|
elsif in_super and in_author and line =~ /\],*\n/
|
|
|
|
in_author = false
|
|
|
|
end
|
|
|
|
|
|
|
|
|
|
|
|
#
|
|
|
|
# While in 'Author' block, check for Twitter handles
|
|
|
|
#
|
|
|
|
if in_super and in_author and line =~ /['|"](.+)['|"]/
|
|
|
|
author_name = $1
|
|
|
|
if author_name =~ /^@.+$/
|
|
|
|
error("No Twitter handle, please. Try leaving it in a comment instead.")
|
|
|
|
end
|
|
|
|
|
|
|
|
if not author_name.ascii_only?
|
|
|
|
error("Please avoid unicode in Author")
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-10-12 19:37:42 +00:00
|
|
|
def check_extname
|
|
|
|
if File.extname(@name) != '.rb'
|
|
|
|
error("Module should be a '.rb' file, or it won't load.")
|
2012-10-12 14:33:18 +00:00
|
|
|
end
|
2012-10-12 07:55:16 +00:00
|
|
|
end
|
2010-11-16 20:17:03 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
def test_old_rubies(f_rel)
|
|
|
|
return true unless CHECK_OLD_RUBIES
|
|
|
|
return true unless Object.const_defined? :RVM
|
|
|
|
puts "Checking syntax for #{f_rel}."
|
|
|
|
rubies ||= RVM.list_strings
|
|
|
|
res = %x{rvm all do ruby -c #{f_rel}}.split("\n").select {|msg| msg =~ /Syntax OK/}
|
|
|
|
rubies.size == res.size
|
2010-11-16 20:17:03 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
error("Fails alternate Ruby version check") if rubies.size
|
2010-11-14 19:00:47 +00:00
|
|
|
end
|
2010-11-16 20:17:03 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
def check_ranking
|
2012-10-12 08:01:48 +00:00
|
|
|
return if @source !~ / \< Msf::Exploit/
|
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
available_ranks = [
|
|
|
|
'ManualRanking',
|
|
|
|
'LowRanking',
|
|
|
|
'AverageRanking',
|
|
|
|
'NormalRanking',
|
|
|
|
'GoodRanking',
|
|
|
|
'GreatRanking',
|
|
|
|
'ExcellentRanking'
|
|
|
|
]
|
|
|
|
|
|
|
|
if @source =~ /Rank \= (\w+)/
|
|
|
|
if not available_ranks.include?($1)
|
2012-10-12 14:11:34 +00:00
|
|
|
error("Invalid ranking. You have '#{$1}'")
|
2012-02-05 21:39:36 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
def check_disclosure_date
|
2012-10-15 00:06:36 +00:00
|
|
|
return if @source =~ /Generic Payload Handler/ or @source !~ / \< Msf::Exploit/
|
2012-10-12 07:55:16 +00:00
|
|
|
|
|
|
|
# Check disclosure date format
|
2012-10-15 00:06:36 +00:00
|
|
|
if @source =~ /'DisclosureDate'.*\=\>[\x0d|\x20]*['|\"](.+)['|\"]/
|
2012-10-12 07:55:16 +00:00
|
|
|
d = $1 #Captured date
|
|
|
|
# Flag if overall format is wrong
|
2012-10-15 00:06:36 +00:00
|
|
|
if d =~ /^... \d{1,2}\,* \d{4}/
|
2012-10-12 07:55:16 +00:00
|
|
|
# Flag if month format is wrong
|
|
|
|
m = d.split[0]
|
|
|
|
months = [
|
|
|
|
'Jan', 'Feb', 'Mar', 'Apr', 'May', 'Jun',
|
|
|
|
'Jul', 'Aug', 'Sep', 'Oct', 'Nov', 'Dec'
|
|
|
|
]
|
|
|
|
|
2012-10-12 14:11:34 +00:00
|
|
|
error('Incorrect disclosure month format') if months.index(m).nil?
|
2012-10-12 07:55:16 +00:00
|
|
|
else
|
2012-10-12 14:11:34 +00:00
|
|
|
error('Incorrect disclosure date format')
|
2012-03-15 21:37:34 +00:00
|
|
|
end
|
2012-10-15 00:06:36 +00:00
|
|
|
else
|
|
|
|
error('Exploit is missing a disclosure date')
|
2012-03-15 21:37:34 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
def check_title_format
|
2012-12-13 18:11:27 +00:00
|
|
|
if @source =~ /'Name'[[:space:]]*=>[[:space:]]*['|"](.+)['|"],*$/
|
2012-10-12 07:55:16 +00:00
|
|
|
words = $1.split
|
2012-12-13 18:11:27 +00:00
|
|
|
words.each do |word|
|
2012-12-13 18:47:36 +00:00
|
|
|
if word =~ /^['"].+['"]$/ or word =~ /^[a-z].*[A-Z].+$/ or word =~ /^.+\(\)$/ or word =~ /^[vb][\d\.\-r]+$/
|
2012-12-13 18:11:27 +00:00
|
|
|
next
|
2012-12-13 18:26:32 +00:00
|
|
|
elsif %w{and or the for via to}.include?(word)
|
2012-12-13 18:21:22 +00:00
|
|
|
next
|
2012-12-13 18:44:15 +00:00
|
|
|
elsif word[0, 1] != word[0, 1].capitalize
|
2012-10-12 14:11:34 +00:00
|
|
|
warn("Improper capitalization in module title: '#{word}...'")
|
2012-10-12 07:55:16 +00:00
|
|
|
end
|
|
|
|
end
|
2012-02-18 23:29:14 +00:00
|
|
|
end
|
2012-10-12 07:55:16 +00:00
|
|
|
end
|
2012-02-18 23:29:14 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
def check_bad_terms
|
|
|
|
# "Stack overflow" vs "Stack buffer overflow" - See explanation:
|
|
|
|
# http://blogs.technet.com/b/srd/archive/2009/01/28/stack-overflow-stack-exhaustion-not-the-same-as-stack-buffer-overflow.aspx
|
|
|
|
if @source =~ /class Metasploit\d < Msf::Exploit::Remote/ and @source.gsub("\n", "") =~ /stack[[:space:]]+overflow/i
|
|
|
|
warn('Contains "stack overflow" You mean "stack buffer overflow"?')
|
|
|
|
elsif @source =~ /class Metasploit\d < Msf::Auxiliary/ and @source.gsub("\n", "") =~ /stack[[:space:]]+overflow/i
|
|
|
|
warn('Contains "stack overflow" You mean "stack exhaustion"?')
|
2012-02-14 03:03:13 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
def check_function_basics
|
|
|
|
functions = @source.scan(/def (\w+)\(*(.+)\)*/)
|
|
|
|
|
|
|
|
functions.each do |func_name, args|
|
|
|
|
# Check argument length
|
|
|
|
args_length = args.split(",").length
|
2012-10-12 14:11:34 +00:00
|
|
|
warn("Poorly designed argument list in '#{func_name}()'. Try a hash.") if args_length > 6
|
2012-02-18 23:29:14 +00:00
|
|
|
end
|
|
|
|
end
|
2010-11-05 00:05:34 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
def check_lines
|
|
|
|
url_ok = true
|
|
|
|
no_stdio = true
|
|
|
|
in_comment = false
|
|
|
|
in_literal = false
|
|
|
|
src_ended = false
|
|
|
|
idx = 0
|
|
|
|
|
|
|
|
@source.each_line { |ln|
|
|
|
|
idx += 1
|
|
|
|
|
|
|
|
# block comment awareness
|
|
|
|
if ln =~ /^=end$/
|
|
|
|
in_comment = false
|
|
|
|
next
|
|
|
|
end
|
|
|
|
in_comment = true if ln =~ /^=begin$/
|
|
|
|
next if in_comment
|
|
|
|
|
|
|
|
# block string awareness (ignore indentation in these)
|
|
|
|
in_literal = false if ln =~ /^EOS$/
|
|
|
|
next if in_literal
|
|
|
|
in_literal = true if ln =~ /\<\<-EOS$/
|
2011-10-23 11:56:07 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
# ignore stuff after an __END__ line
|
|
|
|
src_ended = true if ln =~ /^__END__$/
|
|
|
|
next if src_ended
|
2011-10-23 11:56:07 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
if ln =~ /[\x00-\x08\x0b\x0c\x0e-\x19\x7f-\xff]/
|
|
|
|
error("Unicode detected: #{ln.inspect}", idx)
|
|
|
|
end
|
2011-10-23 11:56:07 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
if (ln.length > LONG_LINE_LENGTH)
|
|
|
|
warn("Line exceeding #{LONG_LINE_LENGTH.to_s} bytes", idx)
|
|
|
|
end
|
2011-02-23 20:20:29 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
if ln =~ /[ \t]$/
|
|
|
|
warn("Spaces at EOL", idx)
|
2010-11-05 00:05:34 +00:00
|
|
|
end
|
2011-02-23 20:20:29 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
if (ln.length > 1) and (ln =~ /^([\t ]*)/) and ($1.include?(' '))
|
|
|
|
warn("Bad indent: #{ln.inspect}", idx)
|
|
|
|
end
|
2011-02-23 20:20:29 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
if ln =~ /\r$/
|
|
|
|
warn("Carriage return EOL", idx)
|
|
|
|
end
|
2011-10-23 11:56:07 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
url_ok = false if ln =~ /\.com\/projects\/Framework/
|
|
|
|
if ln =~ /File\.open/ and ln =~ /[\"\'][arw]/
|
|
|
|
if not ln =~ /[\"\'][wra]\+?b\+?[\"\']/
|
|
|
|
warn("File.open without binary mode", idx)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-10-29 13:27:22 +00:00
|
|
|
if ln =~/^[ \t]*load[ \t]+[\x22\x27]/
|
|
|
|
error("Loading (not requiring) a file: #{ln.inspect}", idx)
|
|
|
|
end
|
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
# The rest of these only count if it's not a comment line
|
|
|
|
next if ln =~ /[[:space:]]*#/
|
2011-10-23 11:56:07 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
if ln =~ /\$std(?:out|err)/i or ln =~ /[[:space:]]puts/
|
|
|
|
no_stdio = false
|
|
|
|
error("Writes to stdout", idx)
|
|
|
|
end
|
2012-01-10 20:53:20 +00:00
|
|
|
}
|
|
|
|
end
|
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
private
|
2010-11-05 00:05:34 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
def load_file(file)
|
|
|
|
f = open(file, 'rb')
|
|
|
|
buf = f.read(f.stat.size)
|
|
|
|
f.close
|
|
|
|
return buf
|
|
|
|
end
|
|
|
|
end
|
2010-11-05 00:05:34 +00:00
|
|
|
|
2012-10-12 07:55:16 +00:00
|
|
|
def run_checks(f_rel)
|
|
|
|
tidy = Msftidy.new(f_rel)
|
2012-12-13 18:31:03 +00:00
|
|
|
tidy.check_old_keywords
|
|
|
|
tidy.check_badchars
|
|
|
|
tidy.check_extname
|
|
|
|
tidy.test_old_rubies(f_rel)
|
|
|
|
tidy.check_ranking
|
|
|
|
tidy.check_disclosure_date
|
2012-10-12 07:55:16 +00:00
|
|
|
tidy.check_title_format
|
2012-12-13 18:31:03 +00:00
|
|
|
tidy.check_bad_terms
|
|
|
|
tidy.check_function_basics
|
|
|
|
tidy.check_lines
|
2012-10-12 07:55:16 +00:00
|
|
|
end
|
2010-11-05 00:05:34 +00:00
|
|
|
|
|
|
|
##
|
|
|
|
#
|
|
|
|
# Main program
|
|
|
|
#
|
|
|
|
##
|
|
|
|
|
|
|
|
dirs = ARGV
|
|
|
|
|
|
|
|
if dirs.length < 1
|
2012-10-12 07:55:16 +00:00
|
|
|
$stderr.puts "Usage: #{File.basename(__FILE__)} <directory or file>"
|
2010-11-05 00:05:34 +00:00
|
|
|
exit(1)
|
|
|
|
end
|
|
|
|
|
|
|
|
dirs.each { |dir|
|
|
|
|
f = nil
|
|
|
|
old_dir = nil
|
|
|
|
|
|
|
|
if dir
|
|
|
|
if File.file?(dir)
|
|
|
|
# whoa, a single file!
|
|
|
|
f = File.basename(dir)
|
|
|
|
dir = File.dirname(dir)
|
|
|
|
end
|
|
|
|
|
|
|
|
old_dir = Dir.getwd
|
|
|
|
Dir.chdir(dir)
|
|
|
|
dparts = dir.split('/')
|
|
|
|
else
|
|
|
|
dparts = []
|
|
|
|
end
|
|
|
|
|
|
|
|
# Only one file?
|
|
|
|
if f
|
2012-10-12 07:55:16 +00:00
|
|
|
run_checks(f)
|
2010-11-05 00:05:34 +00:00
|
|
|
else
|
|
|
|
# Do a recursive check of the specified directory
|
|
|
|
Dir.glob('**/*.rb') { |f|
|
2012-10-12 07:55:16 +00:00
|
|
|
run_checks(f)
|
2010-11-05 00:05:34 +00:00
|
|
|
}
|
|
|
|
end
|
|
|
|
|
|
|
|
Dir.chdir(old_dir)
|
|
|
|
}
|