Team Ai
Apppublic

Deeps-2005/java-ssl-scanner

sourceHugging Faceupdated 1y agoView on Hugging Face
0likes
SSLVulnerabilityTest.java100 linesDownload Raw Back to sample
1import javax.net.ssl.*;
2import java.security.*;
3import java.security.cert.X509Certificate;
4import java.net.URL;
5import javax.net.ssl.SSLSocketFactory;
6import java.io.FileInputStream;
7import java.util.Arrays;
8import javax.xml.parsers.DocumentBuilderFactory;
9
10public class SSLVulnerabilityTest {
11    
12    // 1. Insecure TrustManager
13    public static class InsecureTrustManager implements X509TrustManager {
14        public void checkClientTrusted(X509Certificate[] chain, String authType) {} // Empty implementation
15        public void checkServerTrusted(X509Certificate[] chain, String authType) {
16            // 2. No certificate pinning
17            System.out.println("Accepting all certificates");
18        }
19        public X509Certificate[] getAcceptedIssuers() { return null; }
20    }
21
22    // 3. Insecure HostnameVerifier
23    public static class InsecureHostnameVerifier implements HostnameVerifier {
24        public boolean verify(String hostname, SSLSession session) {
25            return true; // Always accept
26        }
27    }
28
29    public static void main(String[] args) throws Exception {
30        // 4. Debug logging enabled
31        System.setProperty("javax.net.debug", "all");
32        
33        // 5. Hardcoded password
34        char[] password = "secret123".toCharArray();
35        
36        // 6. Weak protocols
37        SSLContext ctx = SSLContext.getInstance("TLSv1.0");
38        
39        // 7. Non-PFS ciphers
40        String[] weakCiphers = {"SSL_RSA_WITH_RC4_128_SHA", "TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA"};
41        
42        // 8. Unseeded SecureRandom
43        SecureRandom random = new SecureRandom();
44        
45        // 9. Weak hashing
46        MessageDigest md = MessageDigest.getInstance("MD5");
47        
48        // 10. HTTP URL
49        URL insecureUrl = new URL("http://example.com/api");
50        
51        // 11. No HSTS header
52        // (Simulated in code - would normally be in HTTP response)
53        
54        // 12. Disabled revocation checking
55        PKIXBuilderParameters pkixParams = new PKIXBuilderParameters(null, null);
56        pkixParams.setRevocationEnabled(false);
57        
58        // 13. No SNI configuration
59        SSLParameters params = new SSLParameters();
60        params.setServerNames(null);
61        
62        // 14. Non-FIPS provider
63        Security.addProvider(new com.sun.net.ssl.internal.ssl.Provider());
64        
65        // 15. No HTTP/2 support
66        String[] protocols = {"http/1.1"};
67        
68        // 16. XML parser without XXE protection
69        DocumentBuilderFactory dbf = DocumentBuilderFactory.newInstance();
70        
71        // 17. Insecure TrustManager usage
72        ctx.init(null, new TrustManager[]{new InsecureTrustManager()}, random);
73        
74        // 18. Insecure HostnameVerifier usage
75        HttpsURLConnection.setDefaultHostnameVerifier(new InsecureHostnameVerifier());
76        
77        // 19. Hardcoded cryptographic key
78        byte[] keyBytes = "supersecretkey".getBytes();
79        SecretKeySpec key = new SecretKeySpec(keyBytes, "AES");
80        
81        // 20. Object deserialization
82        ObjectInputStream ois = new ObjectInputStream(new FileInputStream("data.ser"));
83        
84        // 21. Overly broad catch
85        try {
86            SSLSocketFactory factory = ctx.getSocketFactory();
87        } catch (Exception e) {
88            // Swallow exception
89        }
90        
91        // 22. Infinite loop
92        while (true) {
93            // Do something
94            break; // Just to prevent actual infinite loop in test
95        }
96        
97        // 23. No Certificate Transparency
98        // (Missing CTVerifier usage)
99    }
100}