Deeps-2005/java-ssl-scanner
0
1import javax.net.ssl.*;
2import java.security.KeyStore;
3import java.security.SecureRandom;
4import java.security.cert.X509Certificate;
5import java.io.FileInputStream;
6import java.io.IOException;
7import java.net.URL;
8import java.security.KeyManagementException; // Added for the specific exception
9
10public class AllVulnerabilitiesTest {
11 public static void main(String[] args) throws Exception {
12
13 System.out.println("--- Testing Insecure TrustManager ---");
14 // 1. ❌ Insecure TrustManager (Empty methods, unconditional return true, swallowing exceptions)
15 TrustManager[] trustAllEmpty = new TrustManager[] {
16 new X509TrustManager() {
17 public X509Certificate[] getAcceptedIssuers() { return null; }
18 public void checkClientTrusted(X509Certificate[] certs, String authType) { /* Insecure: Empty body */ }
19 public void checkServerTrusted(X509Certificate[] certs, String authType) { } // Insecure: Empty body variant
20 }
21 };
22 SSLContext sslContextEmpty = SSLContext.getInstance("TLS");
23 sslContextEmpty.init(null, trustAllEmpty, new SecureRandom());
24
25 TrustManager[] trustAllTrue = new TrustManager[] {
26 new X509TrustManager() {
27 public X509Certificate[] getAcceptedIssuers() { return null; }
28 public void checkClientTrusted(X509Certificate[] certs, String authType) { } // Empty body
29 public void checkServerTrusted(X509Certificate[] certs, String authType) {
30 System.out.println("Always trusting server certs.");
31 return true; // Insecure: Unconditional true
32 }
33 }
34 };
35 SSLContext sslContextTrue = SSLContext.getInstance("TLS");
36 sslContextTrue.init(null, trustAllTrue, new SecureRandom());
37
38 TrustManager[] trustAllSwallow = new TrustManager[] {
39 new X509TrustManager() {
40 public X509Certificate[] getAcceptedIssuers() { return null; }
41 public void checkClientTrusted(X509Certificate[] certs, String authType) {
42 try { /* Some validation logic */ if (certs == null) throw new IOException("No certs"); }
43 catch (IOException e) { e.printStackTrace(); } // Insecure: Catches specific but prints stack trace
44 }
45 public void checkServerTrusted(X509Certificate[] certs, String authType) {
46 try { /* Some validation logic */ if (certs == null) throw new KeyManagementException("No certs"); }
47 catch (KeyManagementException e) { /* Insecure: Swallowing specific exception */ }
48 }
49 }
50 };
51 SSLContext sslContextSwallow = SSLContext.getInstance("TLS");
52 sslContextSwallow.init(null, trustAllSwallow, new SecureRandom());
53
54
55 System.out.println("\n--- Testing Insecure HostnameVerifier ---");
56 // 2. ❌ Insecure HostnameVerifier (lambda always returns true)
57 HttpsURLConnection.setDefaultHostnameVerifier((hostname, session) -> true);
58
59 // 2. ❌ Insecure HostnameVerifier (anonymous class always returns true)
60 HostnameVerifier customVerifier = new HostnameVerifier() {
61 @Override
62 public boolean verify(String hostname, SSLSession session) {
63 return true; // Vulnerable: always trusts
64 }
65 };
66 HttpsURLConnection.setDefaultHostnameVerifier(customVerifier);
67
68
69 System.out.println("\n--- Testing Weak Cipher Suites & Protocols ---");
70 SSLSocket socket = (SSLSocket) SSLSocketFactory.getDefault().createSocket();
71
72 // 3. ❌ Weak Cipher Suites via setEnabledCipherSuites()
73 socket.setEnabledCipherSuites(new String[]{"TLS_RSA_WITH_NULL_MD5", "TLS_ECDHE_RSA_WITH_RC4_128_SHA", "TLS_DES_WITH_3DES_EDE_CBC_SHA"});
74
75 // 4. ❌ Outdated SSLContext Protocol
76 SSLContext sslContextOldProtocol = SSLContext.getInstance("SSLv3");
77 sslContextOldProtocol.init(null, null, null);
78
79 SSLContext sslContextTLS10 = SSLContext.getInstance("TLSv1");
80 sslContextTLS10.init(null, null, null);
81
82 // 5. ❌ Weak Enabled Protocols (via setEnabledProtocols)
83 SSLSocket socketWeakProtocols = (SSLSocket) SSLSocketFactory.getDefault().createSocket();
84 socketWeakProtocols.setEnabledProtocols(new String[]{"SSLv2Hello", "TLSv1.2", "TLSv1.3"});
85
86
87 System.out.println("\n--- Testing System Property & Resource Usage ---");
88 // 6. ❌ Debug Logging Enabled
89 System.setProperty("javax.net.debug", "ssl:handshake");
90
91 // 7. ❌ TLS Renegotiation Not Disabled
92 System.setProperty("com.ibm.jsse2.renegotiate", "ALLOW");
93
94 // 8. ❌ Unseeded SecureRandom
95 SecureRandom unseededRandom = new SecureRandom();
96 SecureRandom anotherUnseeded = new SecureRandom(); // Another instance
97
98 // 9. ❌ Hardcoded KeyStore Password
99 try {
100 KeyStore ks = KeyStore.getInstance("JKS");
101 char[] passwordArray = "mysecretpassword123".toCharArray();
102 ks.load(new FileInputStream("mykeystore.jks"), passwordArray);
103 } catch (Exception e) {
104 // Ignore for test
105 }
106
107 // 10. ❌ Hardcoded Sensitive Variable
108 String apiKey = "my_hardcoded_api_key_abc123";
109 String adminPass = "super_admin_pass";
110 String secretToken = "token_xyz_secret";
111
112
113 System.out.println("\n--- Testing Loop and Exception Handling ---");
114 // 11. ❌ Potential DoS via Infinite Loop (Handshake Flooding)
115 SSLServerSocketFactory ssf = (SSLServerSocketFactory) SSLServerSocketFactory.getDefault();
116 SSLServerSocket sss = (SSLServerSocket) ssf.createServerSocket(8443);
117 while (true) {
118 sss.accept(); // Simulates endless handshake/connection acceptance
119 // In a real test, you might add a break or counter to prevent actual hanging
120 if (System.currentTimeMillis() % 10000 == 0) break; // Example to break out
121 }
122
123 // 12. ❌ Overly Broad Catch for Exception
124 try {
125 if (true) throw new KeyManagementException("Simulated SSL error");
126 } catch (Exception e) { // Vulnerable: Catches generic Exception
127 System.err.println("Caught generic exception: " + e.getMessage());
128 // No specific handling, just logging.
129 }
130
131 // 13. ❌ Overly Broad Catch for Throwable (empty block)
132 try {
133 if (true) throw new RuntimeException("Another runtime issue");
134 } catch (Throwable t) { // Vulnerable: Catches Throwable
135 // Empty catch block - completely swallows
136 }
137
138
139 System.out.println("\n--- Testing URL Usage & Cipher Array Declaration ---");
140 // 14. ❌ HTTP URL Usage
141 try {
142 URL insecureUrl = new URL("http://www.insecure-api.com/data");
143 insecureUrl.openConnection(); // Just to trigger URL usage
144 URL localhostUrl = new URL("http://localhost:8080/api"); // Should NOT be flagged (localhost exclusion)
145 } catch (IOException e) {
146 // Ignore for test
147 }
148
149 // 15. ❌ Weak Cipher Suites Array (Variable Declaration)
150 String[] weakCiphersArray = {
151 "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384", // Strong
152 "SSL_RSA_WITH_NULL_SHA", // Weak
153 "TLS_DHE_RSA_WITH_DES_CBC_SHA" // Weak
154 };
155 System.out.println("Defined weak cipher suites array variable.");
156
157 System.out.println("\n--- All vulnerability patterns included in this test file ---");
158 }
159}