| [ Web Proxy ] |
| Viewing: https://raw.githubusercontent.com/OWASP/SecurityShepherd/dev/src/main/java/utils/Validate.java | [Back] [Original] |
The Security Shepherd project is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free Software Foundation, either
* version 3 of the License, or (at your option) any later version.
*
*
The Security Shepherd project is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
* PURPOSE. See the GNU General Public License for more details.
*
*
You should have received a copy of the GNU General Public License along with the Security * Shepherd project. If not, see . * * @author Mark Denihan */ public class Validate { private static final Logger log = LogManager.getLogger(Validate.class); /** * Finds JSession token from user's cookies[], validates and returns. * * @param userCookies Cookies from users browser * @return JSession Id */ public static Cookie getSessionId(Cookie[] userCookies) { int i = 0; Cookie theSessionId = null; for (i = 0; i < userCookies.length; i++) { if (userCookies[i].getName().compareTo("JSESSIONID") == 0) { theSessionId = userCookies[i]; break; // End Loop, because we found the theSessionId } } return theSessionId; } /** * Finds CSRF token from user's cookies[], validates. * * @param userCookies All of the user's cookies from their browser * @return csrfCookie */ public static Cookie getToken(Cookie[] userCookies) { int i = 0; Cookie theToken = null; for (i = 0; i < userCookies.length; i++) { if (userCookies[i].getName().compareTo("token") == 0) { theToken = userCookies[i]; break; // End Loop, because we found the token } } if (theToken != null) { // log.debug("Found Cookie " + theToken.getName() + " with value " + // theToken.getValue()); // The Token is currently designed to be a random Big Integer. If the Big // Integer Case does not work, the token has been modified. Potentially in a // malicious manner try { BigInteger theTokenCasted = new BigInteger(theToken.getValue()); BigInteger tenGrand = new BigInteger("10000"); BigInteger tenGrandNeg = new BigInteger("-10000"); if (!(theTokenCasted.compareTo(tenGrand) > 0 || theTokenCasted.compareTo(tenGrandNeg) < 0)) { log.error("CSRF Cookie Token was modified in some manor!"); theToken = null; } } catch (Exception e) { log.error("CSRF Cookie Token was modified in some manor: " + e.toString()); theToken = null; } } return theToken; } /** * Validates class year when creating classes. Class year should be YY/YY, e.g. 11/12. So the * first year must be less than the second. * * @param classYear Class Year in YY/YY format, e.g. 11/12. * @return Boolean value stating weather or not these supplied attributes make a valid class year */ public static boolean isValidClassYear(String classYear) { boolean result = false; result = classYear.length() == 4; if (result) { try { result = Integer.parseInt(classYear) > 2010; } catch (NumberFormatException e) { log.error("Could not parse classYear " + classYear); result = false; throw new RuntimeException(e); } } return result; } /** * Email validation * * @param email * @return Boolean reflect email validity */ public static boolean isValidEmailAddress(String email) { boolean result = true; try { log.debug("Validating email"); InternetAddress emailAddr = new InternetAddress(email); log.debug("Did we crash"); emailAddr.validate(); log.debug("Didn't crash"); } catch (AddressException ex) { result = false; } return result; } /** * Invalid password detecter * * @param passWord * @return */ public static boolean isValidPassword(String passWord) { boolean result = false; result = passWord.length() > 7 && passWord.length() 2 && userLength 7 && passLength 2 && passWord.length() >= 8 && userName.length()
| Web Proxy Viewer | New URL | Original Page |