-
Notifications
You must be signed in to change notification settings - Fork 169
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
在规则文件中增加permission字段来检查权限滥用 #57
Comments
已合并 |
好像被误关了QAQ |
对于输出结果的影响呢?文档描述,解释一下? |
结果像这样,UsePermissions从数组改成了字典,每个权限标记为"used""unused""unknown"这三种。其中最重要的工作就是维护API-Permission的映射关系
|
这个映射关系不需要appshark来维护?规则里面明确指明api关联的权限? 感觉这样意义不大。 |
不需要,appshark只是引擎,因为还有些是自定义权限,不好公开,放在规则里就行。 |
如果是这样,直接对appshark的结果进行二次处理可能更合适 |
APIMode现在只是单纯的找API,是不是可以根据API-Permission的映射关系,如果扫描结果为空,但权限清单中包含该permission,就判断存在权限滥用
The text was updated successfully, but these errors were encountered: