xss.js 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307
  1. /*global mock, converse */
  2. const $pres = converse.env.$pres;
  3. const sizzle = converse.env.sizzle;
  4. const u = converse.env.utils;
  5. describe("XSS", function () {
  6. describe("A Chat Message", function () {
  7. it("will escape IMG payload XSS attempts", mock.initConverse(['chatBoxesFetched'], {}, async function (done, _converse) {
  8. spyOn(window, 'alert').and.callThrough();
  9. await mock.waitForRoster(_converse, 'current');
  10. await mock.openControlBox(_converse);
  11. const contact_jid = mock.cur_names[0].replace(/ /g,'.').toLowerCase() + '@montague.lit';
  12. await mock.openChatBoxFor(_converse, contact_jid)
  13. const view = _converse.api.chatviews.get(contact_jid);
  14. let message = "<img src=x onerror=alert('XSS');>";
  15. await mock.sendMessage(view, message);
  16. let msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  17. expect(msg.textContent).toEqual(message);
  18. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual("&lt;img src=x onerror=alert('XSS');&gt;");
  19. expect(window.alert).not.toHaveBeenCalled();
  20. message = "<img src=x onerror=alert('XSS')//";
  21. await mock.sendMessage(view, message);
  22. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  23. expect(msg.textContent).toEqual(message);
  24. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual("&lt;img src=x onerror=alert('XSS')//");
  25. message = "<img src=x onerror=alert(String.fromCharCode(88,83,83));>";
  26. await mock.sendMessage(view, message);
  27. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  28. expect(msg.textContent).toEqual(message);
  29. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual("&lt;img src=x onerror=alert(String.fromCharCode(88,83,83));&gt;");
  30. message = "<img src=x oneonerrorrror=alert(String.fromCharCode(88,83,83));>";
  31. await mock.sendMessage(view, message);
  32. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  33. expect(msg.textContent).toEqual(message);
  34. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual("&lt;img src=x oneonerrorrror=alert(String.fromCharCode(88,83,83));&gt;");
  35. message = "<img src=x:alert(alt) onerror=eval(src) alt=xss>";
  36. await mock.sendMessage(view, message);
  37. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  38. expect(msg.textContent).toEqual(message);
  39. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual("&lt;img src=x:alert(alt) onerror=eval(src) alt=xss&gt;");
  40. message = "><img src=x onerror=alert('XSS');>";
  41. await mock.sendMessage(view, message);
  42. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  43. expect(msg.textContent).toEqual(message);
  44. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual("&gt;&lt;img src=x onerror=alert('XSS');&gt;");
  45. message = "><img src=x onerror=alert(String.fromCharCode(88,83,83));>";
  46. await mock.sendMessage(view, message);
  47. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  48. expect(msg.textContent).toEqual(message);
  49. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual("&gt;&lt;img src=x onerror=alert(String.fromCharCode(88,83,83));&gt;");
  50. expect(window.alert).not.toHaveBeenCalled();
  51. done();
  52. }));
  53. it("will escape SVG payload XSS attempts", mock.initConverse(['chatBoxesFetched'], {}, async function (done, _converse) {
  54. spyOn(window, 'alert').and.callThrough();
  55. await mock.waitForRoster(_converse, 'current');
  56. await mock.openControlBox(_converse);
  57. const contact_jid = mock.cur_names[0].replace(/ /g,'.').toLowerCase() + '@montague.lit';
  58. await mock.openChatBoxFor(_converse, contact_jid)
  59. const view = _converse.api.chatviews.get(contact_jid);
  60. let message = "<svg onload=alert(1)>";
  61. await mock.sendMessage(view, message);
  62. let msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  63. expect(msg.textContent).toEqual(message);
  64. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual('&lt;svg onload=alert(1)&gt;');
  65. message = "<svg/onload=alert('XSS')>";
  66. await mock.sendMessage(view, message);
  67. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  68. expect(msg.textContent).toEqual(message);
  69. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual("&lt;svg/onload=alert('XSS')&gt;");
  70. message = "<svg onload=alert(1)//";
  71. await mock.sendMessage(view, message);
  72. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  73. expect(msg.textContent).toEqual(message);
  74. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual("&lt;svg onload=alert(1)//");
  75. message = "<svg/onload=alert(String.fromCharCode(88,83,83))>";
  76. await mock.sendMessage(view, message);
  77. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  78. expect(msg.textContent).toEqual(message);
  79. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual("&lt;svg/onload=alert(String.fromCharCode(88,83,83))&gt;");
  80. message = "<svg id=alert(1) onload=eval(id)>";
  81. await mock.sendMessage(view, message);
  82. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  83. expect(msg.textContent).toEqual(message);
  84. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual("&lt;svg id=alert(1) onload=eval(id)&gt;");
  85. message = '"><svg/onload=alert(String.fromCharCode(88,83,83))>';
  86. await mock.sendMessage(view, message);
  87. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  88. expect(msg.textContent).toEqual(message);
  89. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual('"&gt;&lt;svg/onload=alert(String.fromCharCode(88,83,83))&gt;');
  90. message = '"><svg/onload=alert(/XSS/)';
  91. await mock.sendMessage(view, message);
  92. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  93. expect(msg.textContent).toEqual(message);
  94. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual('"&gt;&lt;svg/onload=alert(/XSS/)');
  95. expect(window.alert).not.toHaveBeenCalled();
  96. done();
  97. }));
  98. it("will have properly escaped URLs",
  99. mock.initConverse(['chatBoxesFetched'], {}, async function (done, _converse) {
  100. await mock.waitForRoster(_converse, 'current');
  101. await mock.openControlBox(_converse);
  102. const contact_jid = mock.cur_names[0].replace(/ /g,'.').toLowerCase() + '@montague.lit';
  103. await mock.openChatBoxFor(_converse, contact_jid)
  104. const view = _converse.api.chatviews.get(contact_jid);
  105. let message = "http://www.opkode.com/'onmouseover='alert(1)'whatever";
  106. await mock.sendMessage(view, message);
  107. let msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  108. expect(msg.textContent).toEqual(message);
  109. expect(msg.innerHTML.replace(/<!---->/g, ''))
  110. .toEqual('http://www.opkode.com/\'onmouseover=\'alert(1)\'whatever');
  111. await u.waitUntil(() => msg.innerHTML.replace(/<!---->/g, '') ===
  112. '<a target="_blank" rel="noopener" href="http://www.opkode.com/%27onmouseover=%27alert%281%29%27whatever">http://www.opkode.com/\'onmouseover=\'alert(1)\'whatever</a>');
  113. message = 'http://www.opkode.com/"onmouseover="alert(1)"whatever';
  114. await mock.sendMessage(view, message);
  115. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  116. expect(msg.textContent).toEqual(message);
  117. await u.waitUntil(() => msg.innerHTML.replace(/<!---->/g, '') ===
  118. '<a target="_blank" rel="noopener" href="http://www.opkode.com/%22onmouseover=%22alert%281%29%22whatever">http://www.opkode.com/"onmouseover="alert(1)"whatever</a>');
  119. message = "https://en.wikipedia.org/wiki/Ender's_Game";
  120. await mock.sendMessage(view, message);
  121. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  122. expect(msg.textContent).toEqual(message);
  123. await u.waitUntil(() => msg.innerHTML.replace(/<!---->/g, '') === '<a target="_blank" rel="noopener" href="https://en.wikipedia.org/wiki/Ender%27s_Game">'+message+'</a>');
  124. message = "<https://bugs.documentfoundation.org/show_bug.cgi?id=123737>";
  125. await mock.sendMessage(view, message);
  126. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  127. expect(msg.textContent).toEqual(message);
  128. await u.waitUntil(() => msg.innerHTML.replace(/<!---->/g, '') ===
  129. `&lt;<a target="_blank" rel="noopener" href="https://bugs.documentfoundation.org/show_bug.cgi?id=123737">https://bugs.documentfoundation.org/show_bug.cgi?id=123737</a>&gt;`);
  130. message = '<http://www.opkode.com/"onmouseover="alert(1)"whatever>';
  131. await mock.sendMessage(view, message);
  132. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  133. expect(msg.textContent).toEqual(message);
  134. await u.waitUntil(() => msg.innerHTML.replace(/<!---->/g, '') ===
  135. '&lt;<a target="_blank" rel="noopener" href="http://www.opkode.com/%22onmouseover=%22alert%281%29%22whatever">http://www.opkode.com/"onmouseover="alert(1)"whatever</a>&gt;');
  136. message = `https://www.google.com/maps/place/Kochstraat+6,+2041+CE+Zandvoort/@52.3775999,4.548971,3a,15y,170.85h,88.39t/data=!3m6!1e1!3m4!1sQ7SdHo_bPLPlLlU8GSGWaQ!2e0!7i13312!8i6656!4m5!3m4!1s0x47c5ec1e56f845ad:0x1de0bc4a5771fb08!8m2!3d52.3773668!4d4.5489388!5m1!1e2`
  137. await mock.sendMessage(view, message);
  138. msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  139. expect(msg.textContent).toEqual(message);
  140. await u.waitUntil(() => msg.innerHTML.replace(/<!---->/g, '') ===
  141. `<a target="_blank" rel="noopener" href="https://www.google.com/maps/place/Kochstraat+6,+2041+CE+Zandvoort/@52.3775999,4.548971,3a,15y,170.85h,88.39t/data=%213m6%211e1%213m4%211sQ7SdHo_bPLPlLlU8GSGWaQ%212e0%217i13312%218i6656%214m5%213m4%211s0x47c5ec1e56f845ad:0x1de0bc4a5771fb08%218m2%213d52.3773668%214d4.5489388%215m1%211e2">https://www.google.com/maps/place/Kochstraat+6,+2041+CE+Zandvoort/@52.3775999,4.548971,3a,15y,170.85h,88.39t/data=!3m6!1e1!3m4!1sQ7SdHo_bPLPlLlU8GSGWaQ!2e0!7i13312!8i6656!4m5!3m4!1s0x47c5ec1e56f845ad:0x1de0bc4a5771fb08!8m2!3d52.3773668!4d4.5489388!5m1!1e2</a>`);
  142. done();
  143. }));
  144. it("will avoid malformed and unsafe urls urls from rendering as anchors",
  145. mock.initConverse(['chatBoxesFetched'], {}, async function (done, _converse) {
  146. await mock.waitForRoster(_converse, 'current');
  147. await mock.openControlBox(_converse);
  148. const contact_jid = mock.cur_names[0].replace(/ /g,'.').toLowerCase() + '@montague.lit';
  149. await mock.openChatBoxFor(_converse, contact_jid)
  150. const view = _converse.api.chatviews.get(contact_jid);
  151. const bad_urls =[
  152. 'http://^$^(*^#$%^_1*(',
  153. 'file://devili.sh'
  154. ];
  155. const good_urls =[{
  156. entered: 'http://www.google.com',
  157. href: 'http://www.google.com/'
  158. }, {
  159. entered: 'https://www.google.com/',
  160. href: 'https://www.google.com/'
  161. }, {
  162. entered: 'www.url.com/something?else=1',
  163. href: 'http://www.url.com/something?else=1',
  164. }, {
  165. entered: 'xmpp://anything/?join',
  166. href: 'xmpp://anything/?join',
  167. }, {
  168. entered: 'WWW.SOMETHING.COM/?x=dKasdDAsd4JAsd3OAJSD23osajAidj',
  169. href: 'http://WWW.SOMETHING.COM/?x=dKasdDAsd4JAsd3OAJSD23osajAidj',
  170. }, {
  171. entered: 'mailto:test@mail.org',
  172. href: 'mailto:test@mail.org',
  173. }];
  174. function checkNonParsedURL (url) {
  175. const msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  176. expect(msg.textContent).toEqual(url);
  177. expect(msg.innerHTML.replace(/<!---->/g, '')).toEqual(url);
  178. }
  179. async function checkParsedURL ({ entered, href }) {
  180. const msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  181. expect(msg.textContent).toEqual(entered);
  182. await u.waitUntil(() => msg.innerHTML.replace(/<!---->/g, '') === `<a target="_blank" rel="noopener" href="${href}">${entered}</a>`);
  183. }
  184. async function checkParsedXMPPURL ({ entered, href }) {
  185. const msg = sizzle('.chat-content .chat-msg:last .chat-msg__text', view.el).pop();
  186. expect(msg.textContent.trim()).toEqual(entered);
  187. await u.waitUntil(() => msg.innerHTML.replace(/<!---->/g, '').trim() === `<a target="_blank" rel="noopener" href="${href}">${entered}</a>`);
  188. }
  189. await mock.sendMessage(view, bad_urls[0]);
  190. checkNonParsedURL(bad_urls[0]);
  191. await mock.sendMessage(view, bad_urls[1]);
  192. checkNonParsedURL(bad_urls[1]);
  193. await mock.sendMessage(view, good_urls[0].entered);
  194. await checkParsedURL(good_urls[0]);
  195. await mock.sendMessage(view, good_urls[1].entered);
  196. await checkParsedURL(good_urls[1]);
  197. await mock.sendMessage(view, good_urls[2].entered);
  198. await checkParsedURL(good_urls[2]);
  199. await mock.sendMessage(view, good_urls[3].entered);
  200. await checkParsedXMPPURL(good_urls[3]);
  201. await mock.sendMessage(view, good_urls[4].entered);
  202. await checkParsedURL(good_urls[4]);
  203. await mock.sendMessage(view, good_urls[5].entered);
  204. await checkParsedURL(good_urls[5]);
  205. done();
  206. }));
  207. });
  208. describe("A Groupchat", function () {
  209. it("escapes occupant nicknames when rendering them, to avoid JS-injection attacks",
  210. mock.initConverse([], {}, async function (done, _converse) {
  211. await mock.openAndEnterChatRoom(_converse, 'lounge@montague.lit', 'romeo');
  212. /* <presence xmlns="jabber:client" to="jc@chat.example.org/converse.js-17184538"
  213. * from="oo@conference.chat.example.org/&lt;img src=&quot;x&quot; onerror=&quot;alert(123)&quot;/&gt;">
  214. * <x xmlns="http://jabber.org/protocol/muc#user">
  215. * <item jid="jc@chat.example.org/converse.js-17184538" affiliation="owner" role="moderator"/>
  216. * <status code="110"/>
  217. * </x>
  218. * </presence>"
  219. */
  220. const presence = $pres({
  221. to:'romeo@montague.lit/pda',
  222. from:"lounge@montague.lit/&lt;img src=&quot;x&quot; onerror=&quot;alert(123)&quot;/&gt;"
  223. }).c('x').attrs({xmlns:'http://jabber.org/protocol/muc#user'})
  224. .c('item').attrs({
  225. jid: 'someone@montague.lit',
  226. role: 'moderator',
  227. }).up()
  228. .c('status').attrs({code:'110'}).nodeTree;
  229. _converse.connection._dataRecv(mock.createRequest(presence));
  230. const view = _converse.chatboxviews.get('lounge@montague.lit');
  231. await u.waitUntil(() => view.querySelectorAll('.occupant-list .occupant-nick').length === 2);
  232. const occupants = view.querySelectorAll('.occupant-list li .occupant-nick');
  233. expect(occupants.length).toBe(2);
  234. expect(occupants[0].textContent.trim()).toBe("&lt;img src=&quot;x&quot; onerror=&quot;alert(123)&quot;/&gt;");
  235. done();
  236. }));
  237. it("escapes the subject before rendering it, to avoid JS-injection attacks",
  238. mock.initConverse([], {}, async function (done, _converse) {
  239. await mock.openAndEnterChatRoom(_converse, 'jdev@conference.jabber.org', 'jc');
  240. spyOn(window, 'alert');
  241. const subject = '<img src="x" onerror="alert(\'XSS\');"/>';
  242. const view = _converse.chatboxviews.get('jdev@conference.jabber.org');
  243. view.model.set({'subject': {
  244. 'text': subject,
  245. 'author': 'ralphm'
  246. }});
  247. const text = await u.waitUntil(() => view.querySelector('.chat-head__desc')?.textContent.trim());
  248. expect(text).toBe(subject);
  249. done();
  250. }));
  251. });
  252. });