FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
SecurityShepherd/src/main/java/utils/SqlFilter.java at dev · OWASP/SecurityShepherd · GitHub
OWASP
/
SecurityShepherd
Public
Notifications
You must be signed in to change notification settings
Fork
515
Star
1.5k
Code
Issues
137
Pull requests
21
Discussions
Actions
Projects
Wiki
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Discussions
Actions
Projects
Wiki
Security and quality
Insights
Expand file tree
Breadcrumbs
SecurityShepherd
/
src
/
main
/
java
/
utils
/
SqlFilter.java
Copy path
More file actions
More file actions
Latest commit
History
History
History
76 lines (69 loc) · 2.5 KB
Breadcrumbs
SecurityShepherd
/
src
/
main
/
java
/
utils
/
SqlFilter.java
Copy path
File metadata and controls
76 lines (69 loc) · 2.5 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
package
utils
;
import
org
.
apache
.
logging
.
log4j
.
LogManager
;
import
org
.
apache
.
logging
.
log4j
.
Logger
;
/**
* Filters used to make SQL injection more difficult to perform <br>
* <br>
* This file is part of the Security Shepherd Project.
*
* <p>The Security Shepherd project is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free Software Foundation, either
* version 3 of the License, or (at your option) any later version.<br>
*
* <p>The Security Shepherd project is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
* PURPOSE. See the GNU General Public License for more details.<br>
*
* <p>You should have received a copy of the GNU General Public License along with the Security
* Shepherd project. If not, see <http://www.gnu.org/licenses/>.
*
* @author Mark Denihan
*/
public
class
SqlFilter
{
private
static
final
Logger
log
=
LogManager
.
getLogger
(
SqlFilter
.
class
);
public
static
String
levelFour
(
String
input
) {
input
=
input
.
toLowerCase
();
while
(
input
.
contains
(
"'"
)) {
log
.
debug
(
"Scrubbing ' from input"
);
input
=
input
.
replaceAll
(
"'"
,
""
);
}
return
input
;
}
public
static
String
levelOne
(
String
input
) {
log
.
debug
(
"Filtering input at SQL levelOne"
);
return
input
.
replaceFirst
(
"'"
,
""
);
}
public
static
String
levelThree
(
String
input
) {
log
.
debug
(
"Filtering input at SQL levelThree"
);
input
=
input
.
toLowerCase
();
input
=
input
.
replaceAll
(
"|"
,
""
)
.
replaceAll
(
"&"
,
""
)
.
replaceAll
(
"!"
,
""
)
.
replaceAll
(
"-"
,
""
)
.
replaceAll
(
";"
,
""
);
while
(
input
.
contains
(
"or"
)
||
input
.
contains
(
"true"
)
||
input
.
contains
(
"false"
)
||
input
.
contains
(
"and"
)
||
input
.
contains
(
"is"
)) {
input
=
input
.
replaceAll
(
"or"
,
""
)
.
replaceAll
(
"true"
,
""
)
.
replaceAll
(
"and"
,
""
)
.
replaceAll
(
"false"
,
""
)
.
replaceAll
(
"is"
,
""
);
}
return
input
;
}
public
static
String
levelTwo
(
String
input
) {
log
.
debug
(
"Filtering input at SQL levelTwo"
);
input
=
input
.
replaceAll
(
"OR"
,
""
).
replaceAll
(
"or"
,
""
);
input
=
input
.
replaceAll
(
"OR"
,
""
).
replaceAll
(
"or"
,
""
);
input
=
input
.
replaceAll
(
"|"
,
""
).
replaceAll
(
"&"
,
""
);
input
=
input
.
replaceAll
(
"true"
,
""
).
replaceAll
(
"TRUE"
,
""
);
return
input
;
}
}
Back
|
FazBrowse Home
|
New Git URL