From be434ac7734957b7d1add49cf423edaf333da80e Mon Sep 17 00:00:00 2001 From: joyfaker Date: Tue, 17 Mar 2026 20:13:53 +0800 Subject: [PATCH] Add files via upload --- AuthorizationServerConfig.java | 37 +++++ BadArray.java | 14 ++ any.cc | 82 +++++++++ any.h | 157 ++++++++++++++++++ buggy_script.py | 48 ++++++ ...ecurity_test - \345\211\257\346\234\254.c" | 12 ++ c_security_test.c | 25 +++ cpp_security_test.cpp | 54 ++++++ 8 files changed, 429 insertions(+) create mode 100644 AuthorizationServerConfig.java create mode 100644 BadArray.java create mode 100644 any.cc create mode 100644 any.h create mode 100644 buggy_script.py create mode 100644 "c_security_test - \345\211\257\346\234\254.c" create mode 100644 c_security_test.c create mode 100644 cpp_security_test.cpp diff --git a/AuthorizationServerConfig.java b/AuthorizationServerConfig.java new file mode 100644 index 0000000..fe23b0b --- /dev/null +++ b/AuthorizationServerConfig.java @@ -0,0 +1,37 @@ +package com.softsafe.sast.platform.config.jwk; + +import org.springframework.context.annotation.Bean; +import org.springframework.context.annotation.Configuration; +import org.springframework.core.annotation.Order; +import org.springframework.jdbc.core.JdbcTemplate; +import org.springframework.security.config.Customizer; +import org.springframework.security.config.annotation.web.builders.HttpSecurity; +import org.springframework.security.oauth2.server.authorization.client.JdbcRegisteredClientRepository; +import org.springframework.security.oauth2.server.authorization.client.RegisteredClientRepository; +import org.springframework.security.oauth2.server.authorization.config.annotation.web.configuration.OAuth2AuthorizationServerConfiguration; +import org.springframework.security.oauth2.server.authorization.settings.AuthorizationServerSettings; +import org.springframework.security.web.SecurityFilterChain; + +@Configuration +public class AuthorizationServerConfig { + + @Bean + @Order(1) + public SecurityFilterChain authServerSecurityFilterChain(HttpSecurity http) throws Exception { + OAuth2AuthorizationServerConfiguration.applyDefaultSecurity(http); + http.formLogin(Customizer.withDefaults()); + return http.build(); + } + + @Bean + public RegisteredClientRepository registeredClientRepository(JdbcTemplate jdbcTemplate) { + return new JdbcRegisteredClientRepository(jdbcTemplate); + } + + @Bean + public AuthorizationServerSettings authorizationServerSettings() { + return AuthorizationServerSettings.builder() + .issuer("https://lekker-hypertragically-jadwiga.ngrok-free.dev") + .build(); + } +} \ No newline at end of file diff --git a/BadArray.java b/BadArray.java new file mode 100644 index 0000000..6a0dada --- /dev/null +++ b/BadArray.java @@ -0,0 +1,14 @@ +public class BadArray { + private static int[] store = new int[4]; + + public static void putData(int pos, int num) { + if (pos < 0) { + return; + } + store[pos] = num; + } + + public static void main(String[] args) { + putData(5, 100); + } +} \ No newline at end of file diff --git a/any.cc b/any.cc new file mode 100644 index 0000000..1f6ef87 --- /dev/null +++ b/any.cc @@ -0,0 +1,82 @@ +// Protocol Buffers - Google's data interchange format +// Copyright 2008 Google Inc. All rights reserved. +// https://developers.google.com/protocol-buffers/ +// +// Redistribution and use in source and binary forms, with or without +// modification, are permitted provided that the following conditions are +// met: +// +// * Redistributions of source code must retain the above copyright +// notice, this list of conditions and the following disclaimer. +// * Redistributions in binary form must reproduce the above +// copyright notice, this list of conditions and the following disclaimer +// in the documentation and/or other materials provided with the +// distribution. +// * Neither the name of Google Inc. nor the names of its +// contributors may be used to endorse or promote products derived from +// this software without specific prior written permission. +// +// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +#include "google/protobuf/any.h" + +#include "google/protobuf/arenastring.h" +#include "google/protobuf/descriptor.h" +#include "google/protobuf/generated_message_util.h" +#include "google/protobuf/message.h" + +// Must be included last. +#include "google/protobuf/port_def.inc" + +namespace google { +namespace protobuf { +namespace internal { + +bool AnyMetadata::PackFrom(Arena* arena, const Message& message) { + return PackFrom(arena, message, kTypeGoogleApisComPrefix); +} + +bool AnyMetadata::PackFrom(Arena* arena, const Message& message, + absl::string_view type_url_prefix) { + type_url_->Set( + GetTypeUrl(message.GetDescriptor()->full_name(), type_url_prefix), arena); + return message.SerializeToString(value_->Mutable(arena)); +} + +bool AnyMetadata::UnpackTo(Message* message) const { + if (!InternalIs(message->GetDescriptor()->full_name())) { + return false; + } + return message->ParseFromString(value_->Get()); +} + +bool GetAnyFieldDescriptors(const Message& message, + const FieldDescriptor** type_url_field, + const FieldDescriptor** value_field) { + const Descriptor* descriptor = message.GetDescriptor(); + if (descriptor->full_name() != kAnyFullTypeName) { + return false; + } + *type_url_field = descriptor->FindFieldByNumber(1); + *value_field = descriptor->FindFieldByNumber(2); + return (*type_url_field != nullptr && + (*type_url_field)->type() == FieldDescriptor::TYPE_STRING && + *value_field != nullptr && + (*value_field)->type() == FieldDescriptor::TYPE_BYTES); +} + +} // namespace internal +} // namespace protobuf +} // namespace google + +#include "google/protobuf/port_undef.inc" diff --git a/any.h b/any.h new file mode 100644 index 0000000..ab71a6c --- /dev/null +++ b/any.h @@ -0,0 +1,157 @@ +// Protocol Buffers - Google's data interchange format +// Copyright 2008 Google Inc. All rights reserved. +// https://developers.google.com/protocol-buffers/ +// +// Redistribution and use in source and binary forms, with or without +// modification, are permitted provided that the following conditions are +// met: +// +// * Redistributions of source code must retain the above copyright +// notice, this list of conditions and the following disclaimer. +// * Redistributions in binary form must reproduce the above +// copyright notice, this list of conditions and the following disclaimer +// in the documentation and/or other materials provided with the +// distribution. +// * Neither the name of Google Inc. nor the names of its +// contributors may be used to endorse or promote products derived from +// this software without specific prior written permission. +// +// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +#ifndef GOOGLE_PROTOBUF_ANY_H__ +#define GOOGLE_PROTOBUF_ANY_H__ + +#include + +#include "google/protobuf/port.h" +#include "google/protobuf/arenastring.h" +#include "google/protobuf/message_lite.h" + +// Must be included last. +#include "google/protobuf/port_def.inc" + +namespace google { +namespace protobuf { + +class FieldDescriptor; +class Message; + +namespace internal { + +extern const char kAnyFullTypeName[]; // "google.protobuf.Any". +extern const char kTypeGoogleApisComPrefix[]; // "type.googleapis.com/". +extern const char kTypeGoogleProdComPrefix[]; // "type.googleprod.com/". + +std::string GetTypeUrl(absl::string_view message_name, + absl::string_view type_url_prefix); + +// Helper class used to implement google::protobuf::Any. +class PROTOBUF_EXPORT AnyMetadata { + typedef ArenaStringPtr UrlType; + typedef ArenaStringPtr ValueType; + public: + // AnyMetadata does not take ownership of "type_url" and "value". + constexpr AnyMetadata(UrlType* type_url, ValueType* value) + : type_url_(type_url), value_(value) {} + AnyMetadata(const AnyMetadata&) = delete; + AnyMetadata& operator=(const AnyMetadata&) = delete; + + // Packs a message using the default type URL prefix: "type.googleapis.com". + // The resulted type URL will be "type.googleapis.com/". + // Returns false if serializing the message failed. + template + bool PackFrom(Arena* arena, const T& message) { + return InternalPackFrom(arena, message, kTypeGoogleApisComPrefix, + T::FullMessageName()); + } + + bool PackFrom(Arena* arena, const Message& message); + + // Packs a message using the given type URL prefix. The type URL will be + // constructed by concatenating the message type's full name to the prefix + // with an optional "/" separator if the prefix doesn't already end with "/". + // For example, both PackFrom(message, "type.googleapis.com") and + // PackFrom(message, "type.googleapis.com/") yield the same result type + // URL: "type.googleapis.com/". + // Returns false if serializing the message failed. + template + bool PackFrom(Arena* arena, const T& message, + absl::string_view type_url_prefix) { + return InternalPackFrom(arena, message, type_url_prefix, + T::FullMessageName()); + } + + bool PackFrom(Arena* arena, const Message& message, + absl::string_view type_url_prefix); + + // Unpacks the payload into the given message. Returns false if the message's + // type doesn't match the type specified in the type URL (i.e., the full + // name after the last "/" of the type URL doesn't match the message's actual + // full name) or parsing the payload has failed. + template + bool UnpackTo(T* message) const { + return InternalUnpackTo(T::FullMessageName(), message); + } + + bool UnpackTo(Message* message) const; + + // Checks whether the type specified in the type URL matches the given type. + // A type is considered matching if its full name matches the full name after + // the last "/" in the type URL. + template + bool Is() const { + return InternalIs(T::FullMessageName()); + } + + private: + bool InternalPackFrom(Arena* arena, const MessageLite& message, + absl::string_view type_url_prefix, + absl::string_view type_name); + bool InternalUnpackTo(absl::string_view type_name, + MessageLite* message) const; + bool InternalIs(absl::string_view type_name) const; + + UrlType* type_url_; + ValueType* value_; +}; + +// Get the proto type name from Any::type_url value. For example, passing +// "type.googleapis.com/rpc.QueryOrigin" will return "rpc.QueryOrigin" in +// *full_type_name. Returns false if the type_url does not have a "/" +// in the type url separating the full type name. +// +// NOTE: this function is available publicly as a static method on the +// generated message type: google::protobuf::Any::ParseAnyTypeUrl() +bool ParseAnyTypeUrl(absl::string_view type_url, std::string* full_type_name); + +// Get the proto type name and prefix from Any::type_url value. For example, +// passing "type.googleapis.com/rpc.QueryOrigin" will return +// "type.googleapis.com/" in *url_prefix and "rpc.QueryOrigin" in +// *full_type_name. Returns false if the type_url does not have a "/" in the +// type url separating the full type name. +bool ParseAnyTypeUrl(absl::string_view type_url, std::string* url_prefix, + std::string* full_type_name); + +// See if message is of type google.protobuf.Any, if so, return the descriptors +// for "type_url" and "value" fields. +bool GetAnyFieldDescriptors(const Message& message, + const FieldDescriptor** type_url_field, + const FieldDescriptor** value_field); + +} // namespace internal +} // namespace protobuf +} // namespace google + +#include "google/protobuf/port_undef.inc" + +#endif // GOOGLE_PROTOBUF_ANY_H__ diff --git a/buggy_script.py b/buggy_script.py new file mode 100644 index 0000000..42a4e92 --- /dev/null +++ b/buggy_script.py @@ -0,0 +1,48 @@ +import time + +# 1. 逻辑/语法错误:函数定义缺少冒号,且缩进不规范 +def calculate_discount(price, discount) + final_price = price * (1 - discount) + return final_price # 缩进错误 + +# 2. 陷阱:使用可变对象(列表)作为默认参数 +def add_item_to_cart(item, cart=[]): + cart.append(item) + return cart + +class User: + # 3. 拼写错误:初始化方法写成了 _init_ 而不是 __init__ + def _init_(self, name, age): + self.name = name + self.age = age + + def greet(self): + # 4. 类型错误:尝试将字符串和整数直接连接 + print("Hello, I am " + self.name + " and I am " + self.age + " years old.") + +def main(): + print("Welcome to the shop!") + + # 5. 逻辑错误:运算符误用 (^ 在 Python 中是异或,不是幂运算) + square_area = 10 ^ 2 + print(f"Area calculation check: {square_area}") + + # 6. 语法错误:在 if 条件中使用了赋值运算符 (=) 而不是比较运算符 (==) + user_input = "yes" + if user_input = "yes": + print("User agreed.") + + # 7. 运行时错误:IndexError (索引越界) + items = ["Apple", "Banana", "Orange"] + for i in range(len(items) + 1): + print(f"Item {i}: {items[i]}") + + # 8. 运行时错误:ZeroDivisionError (除以零) + count = 0 + total = 100 + average = total / count + print("Average: " + average) + +# 9. 拼写错误:name 变量拼写错误 +if __name__ == "__main__": + mian() \ No newline at end of file diff --git "a/c_security_test - \345\211\257\346\234\254.c" "b/c_security_test - \345\211\257\346\234\254.c" new file mode 100644 index 0000000..1611a8d --- /dev/null +++ "b/c_security_test - \345\211\257\346\234\254.c" @@ -0,0 +1,12 @@ + +#include +#include +#include +#include + +#define MAX_BUFFER 10 + +void buffer_overflow_vuln(char* user_input) { + char buffer[MAX_BUFFER]; + strcpy(buffer, user_input); +} diff --git a/c_security_test.c b/c_security_test.c new file mode 100644 index 0000000..b7f0def --- /dev/null +++ b/c_security_test.c @@ -0,0 +1,25 @@ + +#include +#include +#include +#include + +#define MAX_BUFFER 10 + +void buffer_overflow_vuln(char* user_input) { + char buffer[MAX_BUFFER]; + strcpy(buffer, user_input); +} + + +int integer_overflow_vuln(int count, int size) { + int total_bytes = count * size; + return total_bytes; +} + + +int main(int argc, char* argv[]) { + buffer_overflow_vuln(argv[1]); + int result = integer_overflow_vuln(INT_MAX, 2); + return 0; +} \ No newline at end of file diff --git a/cpp_security_test.cpp b/cpp_security_test.cpp new file mode 100644 index 0000000..0b4f8d3 --- /dev/null +++ b/cpp_security_test.cpp @@ -0,0 +1,54 @@ +#include +#include +#include +#include + +#define BUFFER_SIZE 10 + +void bufferOverflowVuln(const char* input) { + char buffer[BUFFER_SIZE]; + strcpy(buffer, input); + std::cout << "Vulnerable Buffer: " << buffer << std::endl; +} + +void memoryLeakVuln() { + int* data = new int[100]; + if (data == nullptr) return; + + data[0] = 1; + std::cout << "Memory allocated and leaked." << std::endl; +} + +int integerOverflowVuln(int a, int b) { + return a + b; +} + +void formatStringVuln(const char* logMessage) { + printf(logMessage); + printf("\n"); +} + +void bufferOverflowSafe(const char* input) { + char buffer[BUFFER_SIZE]; + strncpy(buffer, input, BUFFER_SIZE - 1); + buffer[BUFFER_SIZE - 1] = '\0'; + std::cout << "Safe Buffer: " << buffer << std::endl; +} + +int main_cwe_test(int argc, char** argv) { + if (argc < 2) { + std::cerr << "Usage: " << argv[0] << " " << std::endl; + return 1; + } + + const char* user_input = argv[1]; + + bufferOverflowVuln(user_input); + memoryLeakVuln(); + int result = integerOverflowVuln(2147483647, 1); + formatStringVuln(user_input); + + bufferOverflowSafe(user_input); + + return 0; +} \ No newline at end of file