diff --git a/lib/brakeman/checks/check_escape_function.rb b/lib/brakeman/checks/check_escape_function.rb index 381848aecdedcb014e72e58b43f4ce8460589587..e63e375504fc4c725bac2cde7cf0db82a1205d29 100644 --- a/lib/brakeman/checks/check_escape_function.rb +++ b/lib/brakeman/checks/check_escape_function.rb @@ -1,5 +1,4 @@ require 'brakeman/checks/base_check' -require 'brakeman/processors/lib/find_call' #Check for versions with vulnerable html escape method #http://groups.google.com/group/rubyonrails-security/browse_thread/thread/56bffb5923ab1195 diff --git a/lib/brakeman/checks/check_execute.rb b/lib/brakeman/checks/check_execute.rb index 7b605fe021c9bdbdea093484e94ffc261b17a147..b3f3c7627e88091e0b75b4818e9d0f44be403441 100644 --- a/lib/brakeman/checks/check_execute.rb +++ b/lib/brakeman/checks/check_execute.rb @@ -1,5 +1,4 @@ require 'brakeman/checks/base_check' -require 'brakeman/processors/lib/find_call' #Checks for string interpolation and parameters in calls to #Kernel#system, Kernel#exec, Kernel#syscall, and inside backticks. diff --git a/lib/brakeman/checks/check_filter_skipping.rb b/lib/brakeman/checks/check_filter_skipping.rb index 23740dc6d86b00d2890bab63568ba651838ca6ca..91ffc01b66c0afcb76fe5fd65b5f657ff5234aab 100644 --- a/lib/brakeman/checks/check_filter_skipping.rb +++ b/lib/brakeman/checks/check_filter_skipping.rb @@ -1,5 +1,4 @@ require 'brakeman/checks/base_check' -require 'brakeman/processors/lib/find_call' #Check for filter skipping vulnerability #http://groups.google.com/group/rubyonrails-security/browse_thread/thread/3420ac71aed312d6 diff --git a/lib/brakeman/checks/check_mail_to.rb b/lib/brakeman/checks/check_mail_to.rb index 3bb80b59cffb1645932fdf2696f7037e79446a3c..1f55b2d9e0abf26d858e6ad87118cde07ba04836 100644 --- a/lib/brakeman/checks/check_mail_to.rb +++ b/lib/brakeman/checks/check_mail_to.rb @@ -1,5 +1,4 @@ require 'brakeman/checks/base_check' -require 'brakeman/processors/lib/find_call' #Check for cross site scripting vulnerability in mail_to :encode => :javascript #with certain versions of Rails (< 2.3.11 or < 3.0.4). diff --git a/lib/brakeman/checks/check_nested_attributes.rb b/lib/brakeman/checks/check_nested_attributes.rb index f4d2f8e95e73146fbfbeb970dfa379eafd073352..1df79d25ba112c7183e39c659c9a2e507406321f 100644 --- a/lib/brakeman/checks/check_nested_attributes.rb +++ b/lib/brakeman/checks/check_nested_attributes.rb @@ -1,5 +1,4 @@ require 'brakeman/checks/base_check' -require 'brakeman/processors/lib/find_call' #Check for vulnerability in nested attributes in Rails 2.3.9 and 3.0.0 #http://groups.google.com/group/rubyonrails-security/browse_thread/thread/f9f913d328dafe0c diff --git a/lib/brakeman/checks/check_quote_table_name.rb b/lib/brakeman/checks/check_quote_table_name.rb index 09c33e4e5c35f6e19c270cfc01d240cca7d4b68e..5770e237dac4f0c817adefac47ce25c637c53141 100644 --- a/lib/brakeman/checks/check_quote_table_name.rb +++ b/lib/brakeman/checks/check_quote_table_name.rb @@ -1,5 +1,4 @@ require 'brakeman/checks/base_check' -require 'brakeman/processors/lib/find_call' #Check for uses of quote_table_name in Rails versions before 2.3.13 and 3.0.10 #http://groups.google.com/group/rubyonrails-security/browse_thread/thread/6a1e473744bc389b diff --git a/lib/brakeman/checks/check_redirect.rb b/lib/brakeman/checks/check_redirect.rb index c5bcb27cb9e8b080498f6c93119fca3ba843bea2..ef85598464e39dda9024aa7fea9dbd5b04cc1925 100644 --- a/lib/brakeman/checks/check_redirect.rb +++ b/lib/brakeman/checks/check_redirect.rb @@ -1,5 +1,4 @@ require 'brakeman/checks/base_check' -require 'brakeman/processors/lib/find_call' #Reports any calls to +redirect_to+ which include parameters in the arguments. # diff --git a/lib/brakeman/checks/check_response_splitting.rb b/lib/brakeman/checks/check_response_splitting.rb index ce91ff691a1e8ec88c44fa2362edc6932a2b2b51..408c9cce1bf60ff6f32146e32f14992e998085d9 100644 --- a/lib/brakeman/checks/check_response_splitting.rb +++ b/lib/brakeman/checks/check_response_splitting.rb @@ -1,5 +1,4 @@ require 'brakeman/checks/base_check' -require 'brakeman/processors/lib/find_call' #Warn about response splitting in Rails versions before 2.3.13 #http://groups.google.com/group/rubyonrails-security/browse_thread/thread/6ffc93bde0298768 diff --git a/lib/brakeman/checks/check_sql.rb b/lib/brakeman/checks/check_sql.rb index 838a7d535e26881eb5be041fc09d3e45ed4cf285..47295a36baeda8ec7d2cff552aeacabfca7f8b13 100644 --- a/lib/brakeman/checks/check_sql.rb +++ b/lib/brakeman/checks/check_sql.rb @@ -1,5 +1,4 @@ require 'brakeman/checks/base_check' -require 'brakeman/processors/lib/find_call' #This check tests for find calls which do not use Rails' auto SQL escaping # diff --git a/lib/brakeman/checks/check_strip_tags.rb b/lib/brakeman/checks/check_strip_tags.rb index f85a6ca362bb0d8cef892655c1890bf03ff39719..214eba787675b5e9ca8c7ac58b621c2bf03a6527 100644 --- a/lib/brakeman/checks/check_strip_tags.rb +++ b/lib/brakeman/checks/check_strip_tags.rb @@ -1,5 +1,4 @@ require 'brakeman/checks/base_check' -require 'brakeman/processors/lib/find_call' #Checks for uses of strip_tags in Rails versions before 2.3.13 and 3.0.10 #http://groups.google.com/group/rubyonrails-security/browse_thread/thread/2b9130749b74ea12 diff --git a/lib/brakeman/checks/check_translate_bug.rb b/lib/brakeman/checks/check_translate_bug.rb index 39d9567d0de82fb8fd8ebe8852a8048cf51fbacd..fa0040b4ad561924e77ce1edb7de5a252d37a1ca 100644 --- a/lib/brakeman/checks/check_translate_bug.rb +++ b/lib/brakeman/checks/check_translate_bug.rb @@ -1,5 +1,4 @@ require 'brakeman/checks/base_check' -require 'brakeman/processors/lib/find_call' #Check for vulnerability in translate() helper that allows cross-site scripting #http://groups.google.com/group/rubyonrails-security/browse_thread/thread/2b61d70fb73c7cc5