
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
burp-brightscript
Advanced tools
Burp is an independent open-source project, maintained exclusively by volunteers.
You might want to help! Get in touch via the slack group, or raise issues.
It's a simple tool for executing regex replacements on source code files, a bit like awk. The killer feature is that it understands brightscript syntax, so it knows what line and function it's in. It can be used from command line, or from a js environment (such as when using gulp for building)
The following working gulpfile can be found in my roku MVVM spike; but the process is as follows.
npm install burp-brightscript --save-dev
export function addDevLogs(cb) {
let config: BurpConfig = {
"sourcePath": "build/.roku-deploy-staging",
"globPattern": ["**/*.brs","**/*.bs"],
"replacements": [
{
"regex": "(^.*(logInfo|logError|logVerbose|logDebug)\\((\\s*\"))",
"replacement": "$1#FullPath# "
},
{
"regex": "(^.*(logMethod)\\((\\s*\"))",
"replacement": "$1#FullPath# "
}
]
}
const processor = new BurpProcessor(config);
processor.processFiles();
cb();
}
npm install -g burp-brightscript
burpConfig.json
containing:{
"sourcePath": "build/.roku-deploy-staging",
"globPattern": ["**/*.brs"],
"replacements": [
{
"regex": "(^.*(logInfo|logError|logVerbose|logDebug)\\((\\s*\"))",
"replacement": "$1#FullPath# "
},
{
"regex": "(^.*(logMethod)\\((\\s*\"))",
"replacement": "$1#FullPath# "
}
]
}
burp burpConfig.json
You can use the following constants in your regex replacements:
#FullPath#
- full path of file#LineNumber#
- line number of replacement#FileName#
- filename of replacement#FunctionName#
- function name of replacement#CommentLine#
- will result in the line being commented outI like the name. It doesn't mean anything.
Note, you should invoke burp BEFORE you transpile, until further notice - this is because the line numbers will be completely wrong in your transpiled code. Burp will rename all file paths in the output from .bs to .brs Here's a gulp example of how you can achieve this (please feel free to put up a pr with docs improvements, for a better suggestion) - the following is for mac/linux:
export async function compile(cb) {
// copy all sources to tmp folder
// so we can add the line numbers to them prior to transpiling
await copyFiles();
await sleep(100);
await applyBurpPreprocessing();
let builder = new ProgramBuilder();
await builder.run({
stagingFolderPath: outDir,
createPackage: false,
"rootDir": tmpBuildDir,
"autoImportComponentScript": true,
});
}
public async copyFiles() {
let oldPath = path.resolve(process.cwd());
try {
let outPath = path.resolve(this.config.outputPath);
fs.mkdirSync(this.config.outputPath);
let sourcePaths = this.config.sourcePaths.map((p) => {
p = path.resolve(p);
p = p.endsWith('/') ? p : p + '/';
if (!fs.existsSync(p)) {
feedbackError(new File(p, '', '', ''), `cannot find source path ${p}`, true);
}
return p;
}).join(' ');
await exec(`rsync -az ${sourcePaths} ${outPath}`);
console.log(`files copied to ${outPath} dir is now ${process.cwd()}`);
} catch (err) {
console.error(err);
}
process.chdir(oldPath);
}
I also made rLog and needed a tool that could process source files to insert the line number and function name. I figured this is a more generally useful way of doing it, which other's might leverage in their own tool-chains and build processes.
FAQs
lightweight processor for roku brightscript projects
We found that burp-brightscript demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.