T03 · Remote Payload Retrieval and Execution
- Location
scripts/extract_tongcheng_state.js:6- Finding
Remote Provider Content Is Executed as JavaScript
- Content
View full analysis
str: request = Request(url, headers={"User-Agent": USER_AGENT}) with urlopen(request, timeout=timeout) as response: return response.read().decode("utf-8", "ignore") def extract_state_from_html(html: str) -> dict[str, Any]: script_path = ROOT / "scripts" / "extract_tongcheng_state.js" completed = subprocess.run( ["node", str(script_path)], input=html, capture_output=True, text=True, check=False, ) if completed.returncode != 0: error = completed.stderr.strip() or completed.stdout.strip() or "unknown extractor error" raise RuntimeError(f"公开页面解析失败: {error}") return json.loads(completed.stdout) ``` `scripts/extract_tongcheng_state.js:6-18`: ```javascript const match = html.match(/window\.__NUXT__=(.*?);<\/script>/s) || html.match(/window\.__NUXT__=(.*?)<\/script>/s); if (!match) { console.error("Could not find window.__NUXT__ payload in HTML."); process.exit(1); } let nuxt; try { nuxt = eval(match[1]); } catch (error) { console.error(`Failed to evaluate Nuxt payload: ${error.message}`); process.exit(1); } ``` ### Technical Analysis The flight provider downloads an HTML document from a mutable external service and sends the complete response to a Node.js subprocess. The extractor uses a regular expression to capture the value assigned to `window.__NUXT__`, then executes that captured text with `eval()`. The captured value is not constrained to JSON. It may contain arbitrary JavaScript expressions, immediately invoked functions, calls t ...[truncated 2083 chars]- Remediation
View remediation
