Jquery Vulnerability Finder - Retire.js

There is a plenty of JavaScript libraries for use on the web and in node.js apps out there. This greatly simplifies, but we need to stay update on security fixes. "Using Components with Known Vulnerabilities" is now a part of the OWASP Top 10 and insecure libraries can pose a huge risk for your webapp.

Configure Retire.js for Chrome Browser:

Step#1: Download the Retire.js libraries form "https://github.com/RetireJS/retire.js" in zip format.


Step#2: Extract the zip to folder.



Step#3: Now use Bash terminal (Cygwin for Windows) and executes build_chrome.sh file.



Step#4: Open Chrome and Go to Extensions tab.




Step#5: Click "Load unpacked extensions" and browse for chrome folder located in Retire.js libraries folder.



Step#6: Click Ok button, Retire.js extension got installed and listed in tab. Now you can use this extension for finding vulnerabilities in Jquery.



Step#7: Now open application having vulnerable Jquery, chrome extension will notify you about the vulnerabilities.



Note: Please verify the vulnerable Jquery version  from CVE database.

Comments

Popular posts from this blog

Location.Hash exploit || JQuery 1.11.3/1.7.2/1.6.1 Cross Site Scripting

JQuery UI 1.11.4 Cross Site Scripting

Bypass Mod_Security