Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 66486b0

Browse files
committed
Password models
1 parent 4aec302 commit 66486b0

30 files changed

Lines changed: 246 additions & 1 deletion
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/java-all
4+
extensible: sinkModel
5+
data:
6+
- ["com.sun.crypto.provider", "JceKeyStore", False, "engineGetKey", "(String, char[])", "credential-password", "Argument[1]", "manual"]
7+
- ["com.sun.crypto.provider", "JceKeyStore", False, "engineLoad", "(InputStream, char[])", "credential-password", "Argument[1]", "manual"]
8+
- ["com.sun.crypto.provider", "JceKeyStore", False, "engineSetKeyEntry", "(String, Key, char[], Certificate[])", "credential-password", "Argument[2]", "manual"]
9+
- ["com.sun.crypto.provider", "JceKeyStore", False, "engineStore", "(OutputStream, char[])", "credential-password", "Argument[1]", "manual"]
10+
- ["com.sun.crypto.provider", "JceKeyStore", False, "getPreKeyedHash", "(char[])", "credential-password", "Argument[0]", "manual"]
11+
- ["com.sun.crypto.provider", "KeyProtector", False, "KeyProtector", "(char[])", "credential-password", "Argument[0]", "manual"]
12+
- ["com.sun.crypto.provider", "PBKDF2KeyImpl", False, "deriveKey", "(Mac, byte[], byte[], int, int)", "credential-password", "Argument[1]", "manual"]
13+
- ["com.sun.crypto.provider", "PBKDF2KeyImpl", False, "getPasswordBytes", "(char[])", "credential-password", "Argument[0]", "manual"]
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/java-all
4+
extensible: sinkModel
5+
data:
6+
- ["com.sun.istack.internal.tools", "DefaultAuthenticator$AuthInfo", False, "AuthInfo", "(URL, String, String)", "credential-password", "Argument[2]", "manual"]
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/java-all
4+
extensible: sinkModel
5+
data:
6+
- ["com.sun.net.httpserver", "BasicAuthenticator", False, "checkCredentials", "(String, String)", "credential-password", "Argument[1]", "manual"]
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/java-all
4+
extensible: sinkModel
5+
data:
6+
- ["com.sun.net.ssl", "KeyManagerFactory", False, "init", "(KeyStore, char[])", "credential-password", "Argument[1]", "manual"]
7+
- ["com.sun.net.ssl", "KeyManagerFactorySpi", False, "engineInit", "(KeyStore, char[])", "credential-password", "Argument[1]", "manual"]
8+
- ["com.sun.net.ssl", "KeyManagerFactorySpiWrapper", False, "engineInit", "(KeyStore, char[])", "credential-password", "Argument[1]", "manual"]
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/java-all
4+
extensible: sinkModel
5+
data:
6+
- ["com.sun.org.apache.xml.internal.security.keys.keyresolver.implementations", "PrivateKeyResolver", False, "PrivateKeyResolver", "(KeyStore, char[])", "credential-password", "Argument[1]", "manual"]
7+
- ["com.sun.org.apache.xml.internal.security.keys.keyresolver.implementations", "SecretKeyResolver", False, "SecretKeyResolver", "(KeyStore, char[])", "credential-password", "Argument[1]", "manual"]
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/java-all
4+
extensible: sinkModel
5+
data:
6+
- ["com.sun.rowset", "JdbcRowSetImpl", False, "JdbcRowSetImpl", "(String, String, String)", "credential-password", "Argument[2]", "manual"]
7+
- ["com.sun.rowset", "JdbcRowSetImpl", False, "setPassword", "(String)", "credential-password", "Argument[0]", "manual"]
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/java-all
4+
extensible: sinkModel
5+
data:
6+
- ["com.sun.security.auth.module", "JndiLoginModule", False, "verifyPassword", "(String, String)", "credential-password", "Argument[0]", "manual"]
7+
- ["com.sun.security.auth.module", "JndiLoginModule", False, "verifyPassword", "(String, String)", "credential-password", "Argument[1]", "manual"]
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/java-all
4+
extensible: sinkModel
5+
data:
6+
- ["com.sun.security.ntlm", "Client", False, "Client", "(String, String, String, String, char[])", "credential-password", "Argument[4]", "manual"]
7+
- ["com.sun.security.ntlm", "NTLM", False, "getP1", "(char[])", "credential-password", "Argument[0]", "manual"]
8+
- ["com.sun.security.ntlm", "NTLM", False, "getP2", "(char[])", "credential-password", "Argument[0]", "manual"]
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/java-all
4+
extensible: sinkModel
5+
data:
6+
- ["com.sun.security.sasl.digest", "DigestMD5Base", False, "generateResponseValue", "(String, String, String, String, String, char[], byte[], byte[], int, byte[])", "credential-password", "Argument[5]", "manual"]
7+
- ["com.sun.security.sasl.digest", "DigestMD5Server", False, "generateResponseAuth", "(String, char[], byte[], int, byte[])", "credential-password", "Argument[1]", "manual"]
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/java-all
4+
extensible: sinkModel
5+
data:
6+
- ["com.sun.tools.internal.ws.wscompile", "AuthInfo", False, "AuthInfo", "(URL, String, String)", "credential-password", "Argument[2]", "manual"]

0 commit comments

Comments
 (0)