Deeps-2005/java-ssl-scanner
0
1import javax.net.ssl.*;
2import java.security.*;
3import java.security.cert.X509Certificate;
4import java.net.URL;
5import javax.net.ssl.SSLSocketFactory;
6import java.io.FileInputStream;
7import java.util.Arrays;
8import javax.xml.parsers.DocumentBuilderFactory;
9
10public class SSLVulnerabilityTest {
11
12 // 1. Insecure TrustManager
13 public static class InsecureTrustManager implements X509TrustManager {
14 public void checkClientTrusted(X509Certificate[] chain, String authType) {} // Empty implementation
15 public void checkServerTrusted(X509Certificate[] chain, String authType) {
16 // 2. No certificate pinning
17 System.out.println("Accepting all certificates");
18 }
19 public X509Certificate[] getAcceptedIssuers() { return null; }
20 }
21
22 // 3. Insecure HostnameVerifier
23 public static class InsecureHostnameVerifier implements HostnameVerifier {
24 public boolean verify(String hostname, SSLSession session) {
25 return true; // Always accept
26 }
27 }
28
29 public static void main(String[] args) throws Exception {
30 // 4. Debug logging enabled
31 System.setProperty("javax.net.debug", "all");
32
33 // 5. Hardcoded password
34 char[] password = "secret123".toCharArray();
35
36 // 6. Weak protocols
37 SSLContext ctx = SSLContext.getInstance("TLSv1.0");
38
39 // 7. Non-PFS ciphers
40 String[] weakCiphers = {"SSL_RSA_WITH_RC4_128_SHA", "TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA"};
41
42 // 8. Unseeded SecureRandom
43 SecureRandom random = new SecureRandom();
44
45 // 9. Weak hashing
46 MessageDigest md = MessageDigest.getInstance("MD5");
47
48 // 10. HTTP URL
49 URL insecureUrl = new URL("http://example.com/api");
50
51 // 11. No HSTS header
52 // (Simulated in code - would normally be in HTTP response)
53
54 // 12. Disabled revocation checking
55 PKIXBuilderParameters pkixParams = new PKIXBuilderParameters(null, null);
56 pkixParams.setRevocationEnabled(false);
57
58 // 13. No SNI configuration
59 SSLParameters params = new SSLParameters();
60 params.setServerNames(null);
61
62 // 14. Non-FIPS provider
63 Security.addProvider(new com.sun.net.ssl.internal.ssl.Provider());
64
65 // 15. No HTTP/2 support
66 String[] protocols = {"http/1.1"};
67
68 // 16. XML parser without XXE protection
69 DocumentBuilderFactory dbf = DocumentBuilderFactory.newInstance();
70
71 // 17. Insecure TrustManager usage
72 ctx.init(null, new TrustManager[]{new InsecureTrustManager()}, random);
73
74 // 18. Insecure HostnameVerifier usage
75 HttpsURLConnection.setDefaultHostnameVerifier(new InsecureHostnameVerifier());
76
77 // 19. Hardcoded cryptographic key
78 byte[] keyBytes = "supersecretkey".getBytes();
79 SecretKeySpec key = new SecretKeySpec(keyBytes, "AES");
80
81 // 20. Object deserialization
82 ObjectInputStream ois = new ObjectInputStream(new FileInputStream("data.ser"));
83
84 // 21. Overly broad catch
85 try {
86 SSLSocketFactory factory = ctx.getSocketFactory();
87 } catch (Exception e) {
88 // Swallow exception
89 }
90
91 // 22. Infinite loop
92 while (true) {
93 // Do something
94 break; // Just to prevent actual infinite loop in test
95 }
96
97 // 23. No Certificate Transparency
98 // (Missing CTVerifier usage)
99 }
100}