mirror of
https://github.com/mvt-project/mvt.git
synced 2026-10-02 14:09:47 +02:00
Merge branch 'main' into codex/fix-windows-dumpsys-crlf
This commit is contained in:
3 files changed
+51
-1
No files matched your search
@@ -311,3 +311,31 @@ class TestIndicators:
|
||||
ind = Indicators(log=logging)
|
||||
ind.load_indicators_files([], load_default=False)
|
||||
assert ind.total_ioc_count == 9
|
||||
|
||||
def test_check_url_matches_w_prefixed_subdomain(self, tmp_path):
|
||||
import json
|
||||
|
||||
stix_file = tmp_path / "w-domain.stix2"
|
||||
stix_file.write_text(
|
||||
json.dumps(
|
||||
{
|
||||
"objects": [
|
||||
{
|
||||
"type": "indicator",
|
||||
"pattern": "[domain-name:value = 'web.evil.com']",
|
||||
}
|
||||
]
|
||||
}
|
||||
),
|
||||
encoding="utf-8",
|
||||
)
|
||||
ind = Indicators(log=logging)
|
||||
ind.load_indicators_files([str(stix_file)], load_default=False)
|
||||
|
||||
for url in (
|
||||
"https://web.evil.com/path",
|
||||
"https://www.web.evil.com/path",
|
||||
):
|
||||
match = ind.check_url(url)
|
||||
assert match is not None
|
||||
assert match.ioc.value == "web.evil.com"
|
||||
@@ -22,3 +22,23 @@ def test_google_maps_url_is_not_shortened(url):
|
||||
|
||||
def test_other_google_short_url_is_shortened():
|
||||
assert URL("https://goo.gl/example").check_if_shortened() is True
|
||||
|
||||
|
||||
@pytest.mark.parametrize(
|
||||
"url, domain",
|
||||
[
|
||||
("https://www.example.com/path", "example.com"),
|
||||
# Only the whole "www." prefix comes off, not any leading "w" or "." character.
|
||||
("https://web.example.com", "web.example.com"),
|
||||
("https://wow.com", "wow.com"),
|
||||
("https://wired.com", "wired.com"),
|
||||
("https://www.wow.com", "wow.com"),
|
||||
],
|
||||
)
|
||||
def test_get_domain_strips_only_a_whole_www_prefix(url, domain):
|
||||
assert URL(url).domain == domain
|
||||
|
||||
|
||||
def test_shortener_starting_with_w_is_detected():
|
||||
assert URL("https://w3t.org/example").check_if_shortened() is True
|
||||
assert URL("https://www.w3t.org/example").check_if_shortened() is True
|
||||
Reference in new issue
Block a user