utils to common func

This commit is contained in:
Yogesh Ojha
2021-04-25 23:45:17 +05:30
parent db2d4992e3
commit 1917cbd0b1
8 changed files with 60 additions and 177 deletions
+16
View File
@@ -1,3 +1,5 @@
import whois
import json
from django.db.models import Q
from functools import reduce
@@ -107,3 +109,17 @@ def get_interesting_endpoint(scan_history=None, target=None):
url_of__id=scan_history).filter(page_title_lookup_query)
return url_lookup | title_lookup
def check_keyword_exists(keyword_list, subdomain):
return any(sub in subdomain for sub in keyword_list)
def get_whois(domain_name):
whois_data = whois.whois(domain_name)
whois_json = {}
for data in whois_data:
if data == 'expiration_date' or data == 'updated_date' or data == 'created_date':
if type
whois_json[data] = whois_data
whois_json[data] = whois_data[data]
print(json.dumps(whois_json))
return json.loads(whois_json)
+2 -2
View File
@@ -7,7 +7,6 @@ import requests
import logging
import tldextract
from celery import shared_task
from discord_webhook import DiscordWebhook
from reNgine.celery import app
@@ -35,7 +34,7 @@ from targetApp.models import Domain
from notification.models import NotificationHooks
from scanEngine.models import EngineType, Configuration, Wordlist
from .utils import *
from .common_func import *
'''
task for background scan
@@ -71,6 +70,7 @@ def doScan(domain_id, scan_history_id, scan_type, engine_type):
# once the celery task starts, change the task status to Started
task.scan_status = 1
task.last_scan_date = current_scan_time
task.whois = get_whois(domain.domain_name)
task.save()
activity_id = create_scan_activity(task, "Scanning Started", 2)
-2
View File
@@ -1,2 +0,0 @@
def check_keyword_exists(keyword_list, subdomain):
return any(sub in subdomain for sub in keyword_list)
+1
View File
@@ -51,3 +51,4 @@ validators==0.18.1
vine==5.0.0
wcwidth==0.2.5
discord-webhook==0.11.0
python-whois
@@ -0,0 +1,18 @@
# Generated by Django 3.1.6 on 2021-04-17 16:04
from django.db import migrations, models
class Migration(migrations.Migration):
dependencies = [
('startScan', '0001_initial'),
]
operations = [
migrations.AddField(
model_name='scanhistory',
name='whois_json',
field=models.JSONField(null=True),
),
]
+1
View File
@@ -10,6 +10,7 @@ class ScanHistory(models.Model):
domain_name = models.ForeignKey(Domain, on_delete=models.CASCADE)
scan_type = models.ForeignKey(EngineType, on_delete=models.CASCADE)
celery_id = models.CharField(max_length=100, blank=True)
whois_json = JSONField(null=True)
def __str__(self):
# debug purpose remove scan type and id in prod
+16 -173
View File
@@ -49,11 +49,7 @@ All Subdomains
</div>
<div class="col-xl-12 col-lg-12 col-md-12 col-sm-12 col-12">
<div class="widget widget-one">
<div class="widget-heading">
<h6 class="">Statistics</h6>
</div>
<div class="w-chart">
<div class="w-chart-section primary-card">
<div class="w-detail">
<p class="w-stats">{{subdomain_count|intcomma}} <span class="float-right"><span class="badge badge-pills badge-success">+5</span>&nbsp;<span class="badge badge-pills badge-danger">-10</span></span></p>
@@ -76,181 +72,19 @@ All Subdomains
<div class="w-detail">
<p class="w-stats">{{total_vulnerability_count|intcomma}}<span class="float-right"><span class="badge badge-pills badge-success">+5</span>&nbsp;<span class="badge badge-pills badge-danger">-10</span></span></p>
<p class="w-title">Vulnerabilities Discovered</p>
{% if history.scan_type.vulnerability_scan %}
<p class="w-title text-muted"><small><b>{{critical_count}} Critical, {{high_count}} High</b></small></p>
<p class="w-title text-muted"><small><b>{{medium_count}} Medium Vulnerabilities</b></small></p>
<a href="vuln/{{scan_history_id}}" class="text-info float-right">View all Vulnerabilities</a>
{% else %}
<small class="text-muted">Vulnerability scan hasn't been performed.</small>
<br>
<small class="text-muted">Please perform vulnerability scan to identify the vulnerabilities.</small>
{% endif %}
</div>
</div>
</div>
</div>
</div>
<div class="col-xl-12 col-lg-12 col-md-12 col-sm-12 col-12 layout-px-spacing">
{% if scan_history_id %}
<div class="row layout-top-spacing">
<div class="col-xl-3 col-lg-3 col-md-6 col-sm-6 col-12 mt-2">
<div class="widget widget-activity-four">
<div class="widget-heading">
<h5>Recent Activities</h5>
</div>
<div class="widget-content">
<div class="mt-container mx-auto">
<div class="timeline-line">
{% for activity in scan_activity %}
<div class="item-timeline {% if activity.status == 0 %}timeline-danger {% elif activity.status == 1 %}timeline-warning{% elif activity.status == 2 %}timeline-success{% endif %}">
<div class="t-dot" data-original-title="" title="">
</div>
<div class="t-text">
<b>{{activity.title}}</b>
<span class="badge {% if activity.status == 0 %}badge-danger {% elif activity.status == 1 %}badge-warning{% elif activity.status == 2 %}badge-success{% endif %}">
{% if activity.status == 0 %}&nbsp;Failed&nbsp;
{% elif activity.status == 1 %}&nbsp;In progress&nbsp;
{% elif activity.status == 2 %}&nbsp;Completed&nbsp;
{% endif %}
</span>
<p class="t-time">{{activity.time|naturaltime}}</p>
</div>
</div>
{% endfor %}
</div>
</div>
<br>
</div>
</div>
</div>
<div class="col-xl-3 col-lg-3 col-md-6 col-sm-6 col-12 mt-2">
<div class="widget widget-one_hybrid">
<div class="widget-heading">
<div class="w-icon text-info">
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-globe">
<circle cx="12" cy="12" r="10"></circle>
<line x1="2" y1="12" x2="22" y2="12"></line>
<path d="M12 2a15.3 15.3 0 0 1 4 10 15.3 15.3 0 0 1-4 10 15.3 15.3 0 0 1-4-10 15.3 15.3 0 0 1 4-10z"></path>
</svg>
</div>
&nbsp;
<h2 class="text-warning">{{subdomain_count}}</h2>
<h6 class="">Subdomains Discovered</h6>
</div>
<div class="widget-content">
Total Alive Subdomains: <b class="text-info">{{alive_count}}</b>
<br>
<a href="#subdomainDiscovered" class="text-info">View all subdomains</a>
</div>
</div>
</div>
<div class="col-xl-3 col-lg-3 col-md-6 col-sm-6 col-12 mt-2">
<div class="widget widget-one_hybrid">
<div class="widget-heading">
<div class="w-icon text-info">
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-link">
<path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path>
<path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path>
</svg>
</div>
&nbsp;
<h2 class="text-warning">{{endpoint_count}}</h2>
<h6 class="">Endpoints</h6>
</div>
<div class="widget-content">
Total Alive Endpoints: <b class="text-info">{{endpoint_alive_count}}</b>
<br>
<a href="endpoint/{{scan_history_id}}" class="text-info">View all Endpoints</a>
</div>
</div>
</div>
{% if history.scan_type.vulnerability_scan %}
<div class="col-xl-3 col-lg-3 col-md-6 col-sm-6 col-12 mt-2">
<div class="widget widget-one_hybrid">
<div class="widget-heading">
<div class="w-icon text-danger">
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-compass">
<circle cx="12" cy="12" r="10"></circle><polygon points="16.24 7.76 14.12 14.12 7.76 16.24 9.88 9.88 16.24 7.76"></polygon>
</svg>
</div>
&nbsp;
<h2 class="text-danger">{{total_vulnerability_count}}</h2>
<h6 class="">Vulnerabilities Discovered</h6>
</div>
<div class="widget-content">
<span class="text-danger">{{critical_count}} Critical and {{high_count}} High</span>
<br>
<a href="vuln/{{scan_history_id}}" class="text-info">View all Vulnerabilities</a>
</div>
</div>
</div>
{% else %}
<div class="col-xl-3 col-lg-3 col-md-6 col-sm-6 col-12 mt-2">
<div class="widget widget-one_hybrid">
<div class="widget-heading">
<div class="w-icon text-danger">
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-compass">
<circle cx="12" cy="12" r="10"></circle><polygon points="16.24 7.76 14.12 14.12 7.76 16.24 9.88 9.88 16.24 7.76"></polygon>
</svg>
</div>
&nbsp;
<h2 class="text-danger">0</h2>
<h6 class="">Vulnerabilities Discovered</h6>
</div>
<div class="widget-content">
<small class="text-info">Vulnerability scan hasn't been performed.</small>
<br>
<small class="text-muted">Please perform vulnerability scan to identify the vulnerabilities.</small>
<br>
</div>
</div>
</div>
{% endif %}
</div>
{% endif %}
{% if history.scan_type.vulnerability_scan %}
{% if info_count > 0 or low_count > 0 or medium_count > 0 or high_count > 0 or critical_count > 0 %}
<div class="row layout-top-spacing mb-4">
<div class="col-xl-12 col-lg-12 col-md-12 col-sm-12 col-12 layout-spacing">
<div class="widget widget-chart-two">
<div class="widget-heading">
<h5 class="">Vulnerability Scan Summary</h5>
</div>
<div class="widget-content">
<div id="vulnerability-chart" class=""></div>
</div>
</div>
</div>
</div>
{% endif %}
{% endif %}
{% include 'base/_items/interesting_recon.html' %}
<div class="row layout-top-spacing mb-4" id="subdomainDiscovered">
<div class="col-xl-12 col-lg-12 col-md-12 col-sm-12 col-12">
<div class="widget-content widget-content-area br-6">
<h5 class="text-info">{% if scan_history_id %}Subdomains Discovered {% else %}All Discovered Subdomains{% endif %}</h5>
{% if subdomain_count and scan_history_id %}
<a href="../export/subdomains/{{scan_history_id}}" class="btn btn-info mb-2 mt-4">Export Subdomains(txt format)</a>
<a href="../export/urls/{{scan_history_id}}" class="btn btn-info mb-2 mt-4">Export URLs(txt format)</a>
{% endif %}
<div class="table-responsive mb-4 mt-4">
<table id="subdomain_scan_results" class="multi-table table table-striped table-bordered table-hover" style="width:100%">
<thead>
<tr>
<th class="checkbox-column">Status</th>
<th>Subdomain</th>
<th>IP Address</th>
<th>HTTP Status</th>
<th>Ports</th>
<th>Content Length</th>
<th>Page Title</th>
<th>Technology</th>
<th>Screenshot</th>
<th>Directories</th>
</tr>
</thead>
</table>
</div>
</div>
</div>
</div>
<br>
</div>
{% endblock main_content %}
@@ -264,10 +98,19 @@ All Subdomains
<script src="{% static 'custom/custom.js' %}"></script>
<script src="//cdn.datatables.net/1.10.16/js/dataTables.bootstrap4.min.js"></script>
<script type="text/javascript">
// whois raw json
// https://stackoverflow.com/a/54487295
var x = { "data": { "x": "1", "y": "1", "url": "http://url.com" }, "event": "start", "show": 1, "id": 50 };
document.querySelector('#whois-json').innerHTML = JSON.stringify(x, null, 6).replace(/\n( *)/g, function (match, p1) {
return '<br>' + '&nbsp;'.repeat(p1.length);
});
</script>
<script type="text/javascript">
document.getElementsByClassName('full-search')[0].addEventListener('click', function() {
this.classList.add("input-focused");
document.getElementsByClassName('demo-search-overlay')[0].classList.add("show");
this.classList.add("input-focused");
document.getElementsByClassName('demo-search-overlay')[0].classList.add("show");
})
function fetch_http_headers(id, http_header_path, screenshot_path){
$('#screenshot'+id).attr('src', '/media/'+screenshot_path);
+6
View File
@@ -193,6 +193,9 @@
.widget.widget-one .w-chart .w-chart-section.purple-card {
background-color: #f3effc; }
.widget.widget-one .w-chart .w-chart-section.dark-card {
background-color: #1b2e4b; }
.widget.widget-one .w-chart .w-chart-section.warning-card .w-title, .widget.widget-one .w-chart .w-chart-section.warning-card .w-stats, .widget.widget-one .w-chart .w-chart-section.warning-card a {
color: #e2a03f; }
@@ -205,6 +208,9 @@
.widget.widget-one .w-chart .w-chart-section.danger-card .w-title, .widget.widget-one .w-chart .w-chart-section.danger-card .w-stats, .widget.widget-one .w-chart .w-chart-section.danger-card a {
color: #e7515a; }
.widget.widget-one .w-chart .w-chart-section.dark-card .w-title, .widget.widget-one .w-chart .w-chart-section.dark-card .w-stats, .widget.widget-one .w-chart .w-chart-section.dark-card a {
color: #fff; }
.widget-three .widget-content .summary-list.summary-success {
background: #ddf5f0; }