Skip to main content

How to Identify Call Chains

In addition to data flows, call chains can be identified using scripts and the REPL. This ability is illustrated using commons-io

Before proceeding, generate a CPG for commons-io:

/.shiftleft/ocular/ -f protobufzip -o commons-io-2.5.jar -nb

Start Ocular and load the CPG you created:

sl ocular

You can search for methods of interest (one of which is java.lang.Runtime.exec):


To answer the questions "Where is the data coming from?" and "Can the data be controlled?, find the call stack by using the keyword caller:







[no results]

Even within a small JAR, seven steps are required to find the "beginning" of the call stack, where no caller is present. Though it is clear that the data is coming from somewhere along the call stack, it is unknown if the data can be controlled.

Looking into every method in the call stack, and checking if it consumes the right parameter, is very time consuming. Therefore the steps repeat, until and emit are introduced. The following query starts from a method named exec and repeats the method.caller step until it finds a method that is public and consumes a parameter of type java.lang.String."exec").repeat(_.caller)(_.until(_.isPublic.parameter.evalType("java.lang.String")).emitAllButFirst).fullName.p[])<java.lang.String>(java.lang.String[],int,long),boolean,boolean,long),long),int,boolean,long),int,boolean,long),int,boolean,long),int,boolean,long),long),long),long),long)

This query answers the question "Where is the data coming from?" And because the methods are public, the data is potentially controllable. Still, it is unclear if the data actually flows from the parameter of the methods to the exec method. In order to mark the results of the above query as source, exchange .fullName.p with .parameter, while the sink is our exec method.

def source ="exec").repeat(m=>m.caller).until(m=> m.isPublic.parameter.evalType("java.lang.String")).emit().parameter
def sink ="exec").parameter

You can see that is found to be publically available and there is data flow between this parameter and exec.

------ Flow with 15 elements ------
path 142 freeSpace org/apache/commons/io/
path 143 freeSpace org/apache/commons/io/
path 259 freeSpaceOS org/apache/commons/io/
path 269 freeSpaceOS org/apache/commons/io/
path 381 freeSpaceUnix org/apache/commons/io/
path 401 freeSpaceUnix org/apache/commons/io/
param1 <operator>.assignment N/A
param0 <operator>.assignment N/A
cmdAttribs[2] 401 freeSpaceUnix org/apache/commons/io/
cmdAttribs 398 freeSpaceUnix org/apache/commons/io/
cmdAttribs 473 performCommand org/apache/commons/io/
cmdAttribs 484 performCommand org/apache/commons/io/
cmdAttribs 537 openProcess org/apache/commons/io/
cmdAttribs 538 openProcess org/apache/commons/io/
param0 exec java/lang/