github / github/codeql

How to make the codeql aware a function called between the path.

Ouverte
#13,865 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub
question
Langage dominant
CodeQL
Étoiles
10.1k
Forks
2.1k
Merge moyen
2 j 15 h
PR mergées (30 j)
141

Description

Hey, If I am a code like this:

``` c++
void pure_alloc(){
void * o = malloc(0x20); // [+] @a
printf("[+] I have been called between the path\n"); // [+] @c
*(int *)(o + 0) = 0x44; // [+] @b
}
```

I Could easily find the path from `|@a->@b||` by this query(Thanks for @smowton help me understand this):

``` c++
/**
* @name bad malloc
* @kind path-problem
* @id cpp/workshop/unsecure-malloc
*/

import cpp
import DataFlow::PathGraph
import semmle.code.cpp.controlflow.Guards
import semmle.code.cpp.dataflow.new.TaintTracking

class BadMallocCall extends FunctionCall{
BadMallocCall(){
this.getTarget().hasGlobalName("malloc")
}
}

class BadMallocConfiguration extends TaintTracking::Configuration{
BadMallocConfiguration() { this = "BadMallocConfiguration" }

// [+] source
override predicate isSource(DataFlow::Node source) {
//source.asExpr().(FunctionCall).getTarget().hasGlobalName("malloc")
exists( BadMallocCall call |
call = source.asExpr()
)
}

// [+] sink
override predicate isSink(DataFlow::Node sink) { // [+] Ensure it has been deference
dereferenced(sink.asExpr())
}
}

from BadMallocConfiguration config, DataFlow::PathNode source, DataFlow::PathNode sink
where config.hasFlowPath(source, sink)
select sink, source, sink, "[+] this pointer is $@ and $@, causing a potential vulnerability.", source, "freed here", sink, "used here"
```

Is there are anyway to make me know "printf" has been called between in the path a->b?

I have query the [document](https://codeql.github.com/docs/codeql-language-guides/analyzing-data-flow-in-cpp-new/), seems isAdditionalTaintStep is the most related choice. But If I don't misunderstand anything, It just build path from source to sink.

``` c++
override predicate isAdditionalTaintStep(DataFlow::Node pred, DataFlow::Node succ) {
exists(Loop loop, LoopCounter lc |
loop = lc.getALoop() and
loop.getControllingExpr().(RelationalOperation).getGreaterOperand() = pred.asExpr()
|
succ.asExpr() = lc.getVariableAccessInLoop(loop)
)
}
```

So any tips? Thank u very much.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.