Download find sec bugs Free Java Code
Description
Plugin for FindBugs that aim to help security audit on Java web application.
Icons
Source Files
The download file find-sec-bugs-master.zip has the following entries.
.gitignore//from w w w . ja v a 2s . co m
.travis.yml
LGPL-3.0-header.txt
LGPL-3.0.txt
README.md
findbugs-test-util/pom.xml
findbugs-test-util/src/test/java/com/h3xstream/findbugs/test/BaseDetectorTest.java
findbugs-test-util/src/test/java/com/h3xstream/findbugs/test/DummyProgress.java
findbugs-test-util/src/test/java/com/h3xstream/findbugs/test/EasyBugReporter.java
findbugs-test-util/src/test/java/com/h3xstream/findbugs/test/matcher/BugInstanceMatcher.java
findbugs-test-util/src/test/java/com/h3xstream/findbugs/test/matcher/BugInstanceMatcherBuilder.java
findbugs-test-util/src/test/java/com/h3xstream/findbugs/test/package-info.java
findbugs-test-util/src/test/java/com/h3xstream/findbugs/test/service/ClassFileLocator.java
findbugs-test-util/src/test/java/com/h3xstream/findbugs/test/service/FindBugsLauncher.java
findbugs-test-util/src/test/java/com/h3xstream/testng/VerboseTestListener.java
plugin-deps/pom.xml
plugin-deps/src/main/java/com/hazelcast/config/Config.java
plugin-deps/src/main/java/com/hazelcast/config/MapConfig.java
plugin-deps/src/main/java/com/hazelcast/config/NetworkConfig.java
plugin-deps/src/main/java/com/hazelcast/config/SymmetricEncryptionConfig.java
plugin-deps/src/main/java/com/hazelcast/core/Hazelcast.java
plugin-deps/src/main/java/com/hazelcast/core/IMap.java
plugin-deps/src/main/java/com/unboundid/ldap/sdk/DereferencePolicy.java
plugin-deps/src/main/java/com/unboundid/ldap/sdk/Entry.java
plugin-deps/src/main/java/com/unboundid/ldap/sdk/LDAPConnection.java
plugin-deps/src/main/java/com/unboundid/ldap/sdk/LDAPException.java
plugin-deps/src/main/java/com/unboundid/ldap/sdk/LDAPInterface.java
plugin-deps/src/main/java/com/unboundid/ldap/sdk/ReadOnlyEntry.java
plugin-deps/src/main/java/com/unboundid/ldap/sdk/ResultCode.java
plugin-deps/src/main/java/com/unboundid/ldap/sdk/SearchResult.java
plugin-deps/src/main/java/com/unboundid/ldap/sdk/SearchResultEntry.java
plugin-deps/src/main/java/com/unboundid/ldap/sdk/SearchScope.java
plugin-deps/src/main/java/javax/jdo/JDOHelper.java
plugin-deps/src/main/java/javax/jdo/PersistenceManager.java
plugin-deps/src/main/java/javax/jdo/PersistenceManagerFactory.java
plugin-deps/src/main/java/javax/jdo/Query.java
plugin-deps/src/main/java/javax/persistence/Entity.java
plugin-deps/src/main/java/javax/persistence/EntityManager.java
plugin-deps/src/main/java/javax/persistence/Id.java
plugin-deps/src/main/java/javax/persistence/Query.java
plugin-deps/src/main/java/javax/persistence/TypedQuery.java
plugin-deps/src/main/java/javax/persistence/criteria/CriteriaQuery.java
plugin-deps/src/main/java/javax/servlet/ServletException.java
plugin-deps/src/main/java/javax/servlet/ServletRequest.java
plugin-deps/src/main/java/javax/servlet/ServletRequestWrapper.java
plugin-deps/src/main/java/javax/servlet/ServletResponse.java
plugin-deps/src/main/java/javax/servlet/http/Cookie.java
plugin-deps/src/main/java/javax/servlet/http/HttpServlet.java
plugin-deps/src/main/java/javax/servlet/http/HttpServletRequest.java
plugin-deps/src/main/java/javax/servlet/http/HttpServletRequestWrapper.java
plugin-deps/src/main/java/javax/servlet/http/HttpServletResponse.java
plugin-deps/src/main/java/javax/servlet/http/HttpSession.java
plugin-deps/src/main/java/javax/ws/rs/Path.java
plugin-deps/src/main/java/org/apache/commons/fileupload/FileItem.java
plugin-deps/src/main/java/org/apache/commons/fileupload/FileUploadException.java
plugin-deps/src/main/java/org/apache/commons/fileupload/disk/DiskFileItemFactory.java
plugin-deps/src/main/java/org/apache/commons/fileupload/servlet/ServletFileUpload.java
plugin-deps/src/main/java/org/apache/commons/lang/StringEscapeUtils.java
plugin-deps/src/main/java/org/apache/commons/lang3/StringEscapeUtils.java
plugin-deps/src/main/java/org/apache/struts/action/Action.java
plugin-deps/src/main/java/org/apache/struts/action/ActionErrors.java
plugin-deps/src/main/java/org/apache/struts/action/ActionForm.java
plugin-deps/src/main/java/org/apache/struts/action/ActionForward.java
plugin-deps/src/main/java/org/apache/struts/action/ActionMapping.java
plugin-deps/src/main/java/org/apache/struts/action/ActionMessage.java
plugin-deps/src/main/java/org/apache/struts/action/ActionMessages.java
plugin-deps/src/main/java/org/apache/struts/validator/ValidatorForm.java
plugin-deps/src/main/java/org/apache/tapestry5/annotations/OnEvent.java
plugin-deps/src/main/java/org/apache/tapestry5/annotations/Persist.java
plugin-deps/src/main/java/org/apache/tapestry5/corelib/components/Form.java
plugin-deps/src/main/java/org/apache/wicket/markup/html/WebPage.java
plugin-deps/src/main/java/org/apache/wicket/request/mapper/parameter/PageParameters.java
plugin-deps/src/main/java/org/apache/wicket/util/upload/FileItem.java
plugin-deps/src/main/java/org/apache/wicket/util/upload/FileUploadException.java
plugin-deps/src/main/java/org/apache/wicket/util/upload/ServletFileUpload.java
plugin-deps/src/main/java/org/bouncycastle/jce/provider/BouncyCastleProvider.java
plugin-deps/src/main/java/org/hibernate/Criteria.java
plugin-deps/src/main/java/org/hibernate/Query.java
plugin-deps/src/main/java/org/hibernate/SQLQuery.java
plugin-deps/src/main/java/org/hibernate/Session.java
plugin-deps/src/main/java/org/hibernate/SessionFactory.java
plugin-deps/src/main/java/org/hibernate/criterion/Criterion.java
plugin-deps/src/main/java/org/hibernate/criterion/Restrictions.java
plugin-deps/src/main/java/org/owasp/esapi/ESAPI.java
plugin-deps/src/main/java/org/owasp/esapi/Encoder.java
plugin-deps/src/main/java/org/owasp/esapi/Validator.java
plugin-deps/src/main/java/org/owasp/esapi/errors/IntrusionException.java
plugin-deps/src/main/java/org/owasp/esapi/errors/ValidationException.java
plugin-deps/src/main/java/org/springframework/stereotype/Controller.java
plugin-deps/src/main/java/org/springframework/web/bind/annotation/PathVariable.java
plugin-deps/src/main/java/org/springframework/web/bind/annotation/RequestMapping.java
plugin-deps/src/main/java/org/springframework/web/bind/annotation/RequestMethod.java
plugin/pom.xml
plugin/src/main/java/com/h3xstream/findsecbugs/CommandInjectionDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/FileUploadFilenameDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/PathTraversalDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/PredictableRandomDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/ReDosDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/StrutsValidatorFormDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/WeakFilenameUtilsMethodDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/common/ByteCode.java
plugin/src/main/java/com/h3xstream/findsecbugs/common/InterfaceUtils.java
plugin/src/main/java/com/h3xstream/findsecbugs/common/StringTracer.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/BadHexadecimalConversionDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/CustomMessageDigestDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/DesUsageDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/EcbModeDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/HazelcastSymmetricEncryptionDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/InsufficientKeySizeBlowfishDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/InsufficientKeySizeRsaDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/NullCipherDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/OraclePaddingAttackDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/RsaNoPaddingDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/StaticIvDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/UnencryptedSocketDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/WeakMessageDigestDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/crypto/WeakTrustManagerDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/endpoint/CookieDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/endpoint/JaxRsEndpointDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/endpoint/JaxWsEndpointDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/endpoint/ServletEndpointDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/endpoint/SpringMvcEndpointDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/endpoint/Struts1EndpointDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/endpoint/Struts2EndpointDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/endpoint/TapestryEndpointDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/endpoint/WicketEndpointDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/injection/InjectionDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/injection/InjectionSource.java
plugin/src/main/java/com/h3xstream/findsecbugs/injection/ldap/JndiLdapInjectionSource.java
plugin/src/main/java/com/h3xstream/findsecbugs/injection/ldap/LdapInjectionDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/injection/ldap/UnboundIdLdapInjectionSource.java
plugin/src/main/java/com/h3xstream/findsecbugs/injection/redirect/RedirectionSource.java
plugin/src/main/java/com/h3xstream/findsecbugs/injection/redirect/UnvalidatedRedirectDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/injection/sql/HibernateInjectionSource.java
plugin/src/main/java/com/h3xstream/findsecbugs/injection/sql/JdoInjectionSource.java
plugin/src/main/java/com/h3xstream/findsecbugs/injection/sql/JpaInjectionSource.java
plugin/src/main/java/com/h3xstream/findsecbugs/injection/sql/SqlInjectionDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/jsp/JspXssDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/password/GoogleApiKeyDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/password/JndiCredentialsDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/xpath/XPathInjectionApacheXPathApiDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/xpath/XPathInjectionJavaxDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/xpath/package-info.java
plugin/src/main/java/com/h3xstream/findsecbugs/xss/XSSRequestWrapperDetector.java
plugin/src/main/java/com/h3xstream/findsecbugs/xxe/SaxParserXxeDetector.java
plugin/src/main/resources/metadata/META-INF/MANIFEST.MF
plugin/src/main/resources/metadata/findbugs.xml
plugin/src/main/resources/metadata/messages.xml
plugin/src/test/java/com/h3xstream/findsecbugs/CommandInjectionDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/FileUploadFilenameDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/PathTraversalDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/PredictableRandomDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/ReDosDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/StrutsValidatorFormDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/UnvalidatedRedirectDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/WeakFilenameUtilsMethodDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/common/ByteCodeTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/BadHexadecimalConversionDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/CustomMessageDigestDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/DesUsageDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/EcbModeDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/HazelcastSymmetricEncryptionDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/InsufficientKeySizeBlowfishDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/InsufficientKeySizeRsaDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/NullCipherDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/RsaNoPaddingDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/StaticIvDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/UnencryptedSocketDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/WeakMessageDigestDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/crypto/WeakTrustManagerDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/endpoint/CookieDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/endpoint/JaxRsEndpointDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/endpoint/JaxWsEndpointDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/endpoint/ServletEndpointDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/endpoint/SpringMvcEndpointDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/endpoint/Struts1EndpointDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/endpoint/Struts2EndpointDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/endpoint/TapestryEndpointDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/endpoint/WicketEndpointDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/injection/ldap/JndiLdapInjectionSourceTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/injection/ldap/UnboundIdLdapInjectionSourceTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/injection/sql/HibernateInjectionSourceTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/injection/sql/JdoInjectionSourceTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/injection/sql/JpaInjectionSourceTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/jsp/JspXssDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/password/GoogleApiKeyDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/password/JndiCredentialsDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/xpath/XPathInjectionApacheXPathApiDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/xpath/XPathInjectionJavaxDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/xss/XSSRequestWrapperDetectorTest.java
plugin/src/test/java/com/h3xstream/findsecbugs/xxe/SaxParserXxeDetectorTest.java
plugin/src/test/java/testcode/BasicServlet.java
plugin/src/test/java/testcode/CommandInjection.java
plugin/src/test/java/testcode/CookieUsage.java
plugin/src/test/java/testcode/FileUploadCommon.java
plugin/src/test/java/testcode/FileUploadWicket.java
plugin/src/test/java/testcode/InsecureRandom.java
plugin/src/test/java/testcode/JaxRsService.java
plugin/src/test/java/testcode/JaxWsService.java
plugin/src/test/java/testcode/PathTraversal.java
plugin/src/test/java/testcode/PermissiveCORS.java
plugin/src/test/java/testcode/PersistantCookie.java
plugin/src/test/java/testcode/ScriptingCodeInjection.java
plugin/src/test/java/testcode/SpringTestController.java
plugin/src/test/java/testcode/UnvalidatedRedirectServlet.java
plugin/src/test/java/testcode/VariousRedos.java
plugin/src/test/java/testcode/WeakFilenameUtils.java
plugin/src/test/java/testcode/WicketWebPage.java
plugin/src/test/java/testcode/crypto/BadHexa.java
plugin/src/test/java/testcode/crypto/BlockCipherList.java
plugin/src/test/java/testcode/crypto/CustomMessageDigest.java
plugin/src/test/java/testcode/crypto/HazelcastSymmetric.java
plugin/src/test/java/testcode/crypto/InsufficientKeySizeBlowfish.java
plugin/src/test/java/testcode/crypto/InsufficientKeySizeRsa.java
plugin/src/test/java/testcode/crypto/NullCipherUse.java
plugin/src/test/java/testcode/crypto/RsaNoPadding.java
plugin/src/test/java/testcode/crypto/StaticIv.java
plugin/src/test/java/testcode/crypto/UnencryptedSocket.java
plugin/src/test/java/testcode/crypto/WeakMessageDigest.java
plugin/src/test/java/testcode/googlemaps/Base64.java
plugin/src/test/java/testcode/googlemaps/GoogleMapsSigUtil.java
plugin/src/test/java/testcode/googlemaps/UrlSigner.java
plugin/src/test/java/testcode/ldap/JndiLdap.java
plugin/src/test/java/testcode/ldap/UnboundIdLdap.java
plugin/src/test/java/testcode/logging/SensitiveLogging.java
plugin/src/test/java/testcode/pages/Index.java
plugin/src/test/java/testcode/pages/sub/TapestryPage.java
plugin/src/test/java/testcode/password/JdbcDriverConnection.java
plugin/src/test/java/testcode/password/JndiProperties.java
plugin/src/test/java/testcode/servlet/XssServlet1.java
plugin/src/test/java/testcode/sqli/HibernateSql.java
plugin/src/test/java/testcode/sqli/JdoSql.java
plugin/src/test/java/testcode/sqli/JpaSql.java
plugin/src/test/java/testcode/sqli/UserEntity.java
plugin/src/test/java/testcode/struts1/FormWithValidation.java
plugin/src/test/java/testcode/struts1/FormWithoutValidation1.java
plugin/src/test/java/testcode/struts1/FormWithoutValidation2.java
plugin/src/test/java/testcode/struts1/StrutsV1Action.java
plugin/src/test/java/testcode/struts1/TestForm.java
plugin/src/test/java/testcode/struts2/StrutsV2Endpoint.java
plugin/src/test/java/testcode/trustmanager/KeyStoresTrustManager.java
plugin/src/test/java/testcode/trustmanager/WeakTrustManager.java
plugin/src/test/java/testcode/util/HexUtil.java
plugin/src/test/java/testcode/xpath/XPathApacheXPathApi.java
plugin/src/test/java/testcode/xpath/XPathJavax.java
plugin/src/test/java/testcode/xpath/XmlUtils.java
plugin/src/test/java/testcode/xpath/data.xml
plugin/src/test/java/testcode/xss/ByPassExamplePoc.java
plugin/src/test/java/testcode/xss/FalsePositiveRequestWrapper.java
plugin/src/test/java/testcode/xss/XSSRequestWrapper.java
plugin/src/test/java/testcode/xss/XSSRequestWrapper2.java
plugin/src/test/java/testcode/xxe/SaxParserSafeEntityResolver.java
plugin/src/test/java/testcode/xxe/SaxParserSafePrivilegedExceptionAction.java
plugin/src/test/java/testcode/xxe/SaxParserVulnerable.java
plugin/src/test/resources/logback-test.xml
plugin/src/test/webapp/WEB-INF/web.xml
plugin/src/test/webapp/xss_1_direct_use.jsp
plugin/src/test/webapp/xss_2_transfer_local.jsp
plugin/src/test/webapp/xss_3_false_positive_static_function.jsp
plugin/src/test/webapp/xss_4_false_positive_overwrite_local.jsp
plugin/src/test/webapp/xss_5_multiple_transfer_local.jsp
plugin/src/test/webapp/xss_6_get_parameter.jsp
plugin/test-dependencies.xml
pom.xml
website/pom.xml
website/src/main/groovy/BuildWebPage.groovy
website/src/main/java/ReadMe.java
website/src/main/resources/bugs.htm
website/src/main/resources/common_footer.htm
website/src/main/resources/common_header.htm
website/src/main/resources/down.png
website/src/main/resources/download.htm
website/src/main/resources/home.htm
website/src/main/resources/lgplv3.png
website/src/main/resources/license.htm
website/src/main/resources/link.png
website/src/main/resources/social.htm
website/src/main/resources/styles.css
website/src/main/resources/tutorials.htm
Download
Click the following link to download find-sec-bugs-master.zip.
find-sec-bugs-master.zip