Skip to content

Commit a9b10a1

Browse files
authored
Merge pull request #1234 from cyw3/main
🎨 update rules
2 parents 39090ed + 6025edb commit a9b10a1

File tree

7 files changed

+74
-153
lines changed

7 files changed

+74
-153
lines changed

server/projects/main/apps/scan_conf/management/commands/open_source/jafc.json

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@
3939
"severity": "warning",
4040
"category": "correctness",
4141
"rule_title": "查找android.net.ConnectivityManager相关API",
42-
"rule_params": "class = android.net.ConnectivityManager\nmethod = getNetworkInfo;getAllNetworks\nmsg = 查找android.net.ConnectivityManager相关API",
42+
"rule_params": "",
4343
"custom": true,
4444
"languages": [
4545
"java"
@@ -56,7 +56,7 @@
5656
"severity": "warning",
5757
"category": "correctness",
5858
"rule_title": "动态权限API检测 - CameraManager",
59-
"rule_params": "class = CameraManager\nmethod = openCamera\nmsg = 该API会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
59+
"rule_params": "",
6060
"custom": true,
6161
"languages": [
6262
"java"
@@ -73,7 +73,7 @@
7373
"severity": "warning",
7474
"category": "correctness",
7575
"rule_title": "动态权限API检测 - Environment.getExternalStorageDirectory",
76-
"rule_params": "class = Environment\nmethod = getExternalStorageDirectory\nmsg = 该API会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
76+
"rule_params": "",
7777
"custom": true,
7878
"languages": [
7979
"java"
@@ -90,7 +90,7 @@
9090
"severity": "warning",
9191
"category": "correctness",
9292
"rule_title": "动态权限API检测 - LocationManager",
93-
"rule_params": "class = android.location.LocationManager\nmsg = android.location.LocationManager的API可能会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
93+
"rule_params": "",
9494
"custom": true,
9595
"languages": [
9696
"java"
@@ -107,7 +107,7 @@
107107
"severity": "warning",
108108
"category": "correctness",
109109
"rule_title": "动态权限API检测 - SubscriptionManager",
110-
"rule_params": "class = SubscriptionManager\nmethod = getActiveSubscriptionInfo;getActiveSubscriptionInfoForSimSlotIndex;getActiveSubscriptionInfoList;getActiveSubscriptionInfoCount\nmsg = 该API会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
110+
"rule_params": "",
111111
"custom": true,
112112
"languages": [
113113
"java"
@@ -124,7 +124,7 @@
124124
"severity": "warning",
125125
"category": "correctness",
126126
"rule_title": "动态权限API检测 - TelephonyManager",
127-
"rule_params": "class = TelephonyManager\nmsg = TelephonyManager的API可能会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
127+
"rule_params": "",
128128
"custom": true,
129129
"languages": [
130130
"java"
@@ -141,7 +141,7 @@
141141
"severity": "warning",
142142
"category": "correctness",
143143
"rule_title": "动态权限API检测 - TwilightManager",
144-
"rule_params": "class = TwilightManager\nmethod = getLastKnownLocationForProvider\nmsg = 该API会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
144+
"rule_params": "",
145145
"custom": true,
146146
"languages": [
147147
"java"
@@ -158,7 +158,7 @@
158158
"severity": "warning",
159159
"category": "correctness",
160160
"rule_title": "动态权限API检测 - WallpaperManager",
161-
"rule_params": "class = WallpaperManager\nmethod = getFastDrawable;peekFastDrawable;getWallpaperFile\nmsg = 该API会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
161+
"rule_params": "",
162162
"custom": true,
163163
"languages": [
164164
"java"
@@ -175,7 +175,7 @@
175175
"severity": "warning",
176176
"category": "correctness",
177177
"rule_title": "动态权限API检测 - WifiRttManager",
178-
"rule_params": "class = WifiRttManager\nmethod = startRanging\nmsg = 该API会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
178+
"rule_params": "",
179179
"custom": true,
180180
"languages": [
181181
"java"
@@ -192,7 +192,7 @@
192192
"severity": "fatal",
193193
"category": "security",
194194
"rule_title": "fight_IMEI使用监控",
195-
"rule_params": "class=android.telephony.TelephonyManager\nmethod=getDeviceId;getImei\nmsg=Android Q 系统禁止使用IMEI,请按邮件申请备案。",
195+
"rule_params": "",
196196
"custom": true,
197197
"languages": [
198198
"java"
@@ -262,7 +262,7 @@
262262
"severity": "error",
263263
"category": "security",
264264
"rule_title": "扫描log4j api调用位置,辅助升级log4j",
265-
"rule_params": "class = org.apache.logging.log4j.Logger\nmethod = error;warn;info;debug;fatal;trace;log\nmsg = 扫描log4j api调用位置,辅助升级log4j",
265+
"rule_params": "",
266266
"custom": true,
267267
"languages": [
268268
"java"
@@ -279,7 +279,7 @@
279279
"severity": "error",
280280
"category": "security",
281281
"rule_title": "扫描log4j LogManager api调用位置,辅助升级log4j",
282-
"rule_params": "class = org.apache.logging.log4j.LogManager\nmethod = getLogger\nmsg = 扫描log4j api调用位置,辅助升级log4j",
282+
"rule_params": "",
283283
"custom": true,
284284
"languages": [
285285
"java"
@@ -296,7 +296,7 @@
296296
"severity": "warning",
297297
"category": "correctness",
298298
"rule_title": "查找android.net.NetworkInfo相关API",
299-
"rule_params": "class = android.net. NetworkInfo\nmethod = getExtraInfo\nmsg = 查找android.net.NetworkInfo相关API",
299+
"rule_params": "",
300300
"custom": true,
301301
"languages": [
302302
"java"

server/projects/main/apps/scan_conf/management/commands/open_source/jafc_beta.json

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@
2222
"severity": "warning",
2323
"category": "correctness",
2424
"rule_title": "动态权限API检测 - CameraManager",
25-
"rule_params": "class = CameraManager\nmethod = openCamera\nmsg = 该API会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
25+
"rule_params": "",
2626
"custom": true,
2727
"languages": [
2828
"java"
@@ -39,7 +39,7 @@
3939
"severity": "warning",
4040
"category": "correctness",
4141
"rule_title": "动态权限API检测 - Environment.getExternalStorageDirectory",
42-
"rule_params": "class = Environment\nmethod = getExternalStorageDirectory\nmsg = 该API会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
42+
"rule_params": "",
4343
"custom": true,
4444
"languages": [
4545
"java"
@@ -56,7 +56,7 @@
5656
"severity": "warning",
5757
"category": "correctness",
5858
"rule_title": "动态权限API检测 - LocationManager",
59-
"rule_params": "class = android.location.LocationManager\nmsg = android.location.LocationManager的API可能会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
59+
"rule_params": "",
6060
"custom": true,
6161
"languages": [
6262
"java"
@@ -73,7 +73,7 @@
7373
"severity": "warning",
7474
"category": "correctness",
7575
"rule_title": "动态权限API检测 - SubscriptionManager",
76-
"rule_params": "class = SubscriptionManager\nmethod = getActiveSubscriptionInfo;getActiveSubscriptionInfoForSimSlotIndex;getActiveSubscriptionInfoList;getActiveSubscriptionInfoCount\nmsg = 该API会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
76+
"rule_params": "",
7777
"custom": true,
7878
"languages": [
7979
"java"
@@ -107,7 +107,7 @@
107107
"severity": "warning",
108108
"category": "correctness",
109109
"rule_title": "动态权限API检测 - TwilightManager",
110-
"rule_params": "class = TwilightManager\nmethod = getLastKnownLocationForProvider\nmsg = 该API会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
110+
"rule_params": "",
111111
"custom": true,
112112
"languages": [
113113
"java"
@@ -124,7 +124,7 @@
124124
"severity": "warning",
125125
"category": "correctness",
126126
"rule_title": "动态权限API检测 - WallpaperManager",
127-
"rule_params": "class = WallpaperManager\nmethod = getFastDrawable;peekFastDrawable;getWallpaperFile\nmsg = 该API会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
127+
"rule_params": "",
128128
"custom": true,
129129
"languages": [
130130
"java"
@@ -141,7 +141,7 @@
141141
"severity": "warning",
142142
"category": "correctness",
143143
"rule_title": "动态权限API检测 - WifiRttManager",
144-
"rule_params": "class = WifiRttManager\nmethod = startRanging\nmsg = 该API会触发动态权限申请,请检查代码逻辑是否在拒绝权限后正常运行。",
144+
"rule_params": "",
145145
"custom": true,
146146
"languages": [
147147
"java"
@@ -158,7 +158,7 @@
158158
"severity": "error",
159159
"category": "security",
160160
"rule_title": "扫描log4j api调用位置,辅助升级log4j",
161-
"rule_params": "class = org.apache.logging.log4j.Logger\nmethod = error;warn;info;debug;fatal;trace;log\nmsg = 扫描log4j api调用位置,辅助升级log4j",
161+
"rule_params": "",
162162
"custom": true,
163163
"languages": [
164164
"java"
@@ -175,7 +175,7 @@
175175
"severity": "error",
176176
"category": "security",
177177
"rule_title": "扫描log4j LogManager api调用位置,辅助升级log4j",
178-
"rule_params": "class = org.apache.logging.log4j.LogManager\nmethod = getLogger\nmsg = 扫描log4j api调用位置,辅助升级log4j",
178+
"rule_params": "",
179179
"custom": true,
180180
"languages": [
181181
"java"

0 commit comments

Comments
 (0)