Update expected leaks - #52
L-Jubarah-upb wants to merge 73 commits into
Conversation
Removed expected info flows from JSON file.
Updated documentation to reflect changes in data flow and leak status.
Updated the number of leaks in the documentation and adjusted log statements to prevent leaks.
Removed expected info flows related to SMS and device ID.
Added new source and sink information for data flow.
Updated the number of leaks in the documentation and added a comment indicating the log statement as a sink.
Updated the number of leaks in the documentation from 1 to 2.
| }, | ||
| { | ||
| "Source": "android.app.Activity: android.view.View findViewById(int)", | ||
| "Source": "de.ecspride.PrivateDataLeak2: android.view.View findViewById(int)", |
There was a problem hiding this comment.
I'd keep android.app.Activity: android.view.View findViewById(int), even though the bytecode uses PrivateDataLeak2. Since this is a virtual call, referencing android.app.Activity isn't wrong.
| Intent in = new Intent("com.example.deviceid_orderedintent"); | ||
| in.putExtra("data", s); | ||
| sendOrderedBroadcast(in, null); //sink | ||
| sendOrderedBroadcast(in, null); |
There was a problem hiding this comment.
@number_of_leaks should be 0 in this file then
| }, | ||
| { | ||
| "Source": "android.app.Activity: android.content.Intent getIntent()", | ||
| "Method": "org.cert.echoer.MainActivity: void getDataFromIntent()", |
There was a problem hiding this comment.
Can you update the Java code there as well? The //sink comment and the expected flow count should be updated.
| if (resultCode == 0 && requestCode == 0 && data != null) { | ||
| if (data.hasExtra("secret")) { | ||
| if(data.getExtras().getString("secret") != null){ //sink | ||
| if(data.getExtras().getString("secret") != null){ //source |
| { | ||
| if (requestCode == 1) | ||
| { | ||
| Bundle b = data.getExtras(); // source |
There was a problem hiding this comment.
This should not be a source anymore.
| @Override | ||
| public void onClick(View arg0) { | ||
| cFuncDoTheMagic(getApplicationContext()); | ||
| cFuncDoTheMagic(getApplicationContext()); // source, sink |
There was a problem hiding this comment.
IMHO: The expressiveness of our specification does not allow to specify the source/sinks here accurately.
@StevenArzt Your opinion?
|
|
||
| try { | ||
| String string = "dIeciveDteg"; | ||
| String string = "dIeciveDteg"; // source |
There was a problem hiding this comment.
No, the source is:
id = (String) method.invoke(telephonyManager);
| "Line": 30 | ||
| "Source": "android.telephony.TelephonyManager: java.lang.String getDeviceId()", | ||
| "Method": "com.example.onlytelephony.MainActivity: void onCreate(android.os.Bundle)", | ||
| "Line": 54 |
There was a problem hiding this comment.
Line 63 (the one with the reflective method invoke)
| .getSystemService(Context.TELEPHONY_SERVICE); | ||
| method = c.getMethod(string, new Class<?>[0]); | ||
|
|
||
| id = (String) method.invoke(telephonyManager); |
| method = c.getMethod(reverse, new Class<?>[0]); | ||
| Toast.makeText(this, "tele manager is executed", Toast.LENGTH_SHORT) | ||
| .show(); | ||
| id = (String) method.invoke(telephonyManager); |
|
Thanks for you contribution! I've added a few comments on things that should be improved. |
No description provided.