1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
|
<html>
<head>
<title></title>
<script type="text/javascript">
var scriptItem = "untouched";
function checkLoads() {
var title = document.getElementById("title");
title.innerHTML = window.parent.shouldLoad ?
"The following should be hidden:" :
"The following should not be hidden:"
if (window.parent.shouldLoad) {
window.parent.is(scriptItem, "loaded malware javascript!", "Should load bad javascript");
} else {
window.parent.is(scriptItem, "untouched", "Should not load bad javascript");
}
var elt = document.getElementById("styleImport");
var style = document.defaultView.getComputedStyle(elt, "");
window.parent.isnot(style.visibility, "visible", "Should load clean css");
// Make sure the css did not load.
elt = document.getElementById("styleCheck");
style = document.defaultView.getComputedStyle(elt, "");
if (window.parent.shouldLoad) {
window.parent.isnot(style.visibility, "visible", "Should load bad css");
} else {
window.parent.isnot(style.visibility, "hidden", "Should not load bad css");
}
elt = document.getElementById("styleBad");
style = document.defaultView.getComputedStyle(elt, "");
if (window.parent.shouldLoad) {
window.parent.isnot(style.visibility, "visible", "Should import bad css");
} else {
window.parent.isnot(style.visibility, "hidden", "Should not import bad css");
}
}
</script>
<!-- Try loading from a malware javascript URI -->
<script type="text/javascript" src="http://malware.example.com/tests/toolkit/components/url-classifier/tests/mochitest/evil.js"></script>
<!-- Try loading from an uwanted software css URI -->
<link rel="stylesheet" type="text/css" href="http://unwanted.example.com/tests/toolkit/components/url-classifier/tests/mochitest/evil.css"></link>
<!-- Try loading a marked-as-malware css through an @import from a clean URI -->
<link rel="stylesheet" type="text/css" href="import.css"></link>
</head>
<body onload="checkLoads()">
<div id="title"></div>
<div id="styleCheck">STYLE EVIL</div>
<div id="styleBad">STYLE BAD</div>
<div id="styleImport">STYLE IMPORT</div>
</body>
</html>
|