From 1917cbd0b1deecda74e7d0bfc95eaddbf927b7d7 Mon Sep 17 00:00:00 2001 From: Yogesh Ojha Date: Sun, 18 Apr 2021 20:30:21 +0530 Subject: [PATCH] utils to common func --- reNgine/common_func.py | 16 ++ reNgine/tasks.py | 4 +- reNgine/utils.py | 2 - requirements.txt | 1 + .../migrations/0002_scanhistory_whois_json.py | 18 ++ startScan/models.py | 1 + .../templates/startScan/detail_scan.html | 189 ++---------------- static/assets/css/custom.css | 6 + 8 files changed, 60 insertions(+), 177 deletions(-) delete mode 100644 reNgine/utils.py create mode 100644 startScan/migrations/0002_scanhistory_whois_json.py diff --git a/reNgine/common_func.py b/reNgine/common_func.py index 1e2cc39c..604f656a 100644 --- a/reNgine/common_func.py +++ b/reNgine/common_func.py @@ -1,3 +1,5 @@ +import whois +import json from django.db.models import Q from functools import reduce @@ -107,3 +109,17 @@ def get_interesting_endpoint(scan_history=None, target=None): url_of__id=scan_history).filter(page_title_lookup_query) return url_lookup | title_lookup + +def check_keyword_exists(keyword_list, subdomain): + return any(sub in subdomain for sub in keyword_list) + +def get_whois(domain_name): + whois_data = whois.whois(domain_name) + whois_json = {} + for data in whois_data: + if data == 'expiration_date' or data == 'updated_date' or data == 'created_date': + if type + whois_json[data] = whois_data + whois_json[data] = whois_data[data] + print(json.dumps(whois_json)) + return json.loads(whois_json) diff --git a/reNgine/tasks.py b/reNgine/tasks.py index 232f859d..a2b43e56 100644 --- a/reNgine/tasks.py +++ b/reNgine/tasks.py @@ -7,7 +7,6 @@ import requests import logging import tldextract - from celery import shared_task from discord_webhook import DiscordWebhook from reNgine.celery import app @@ -35,7 +34,7 @@ from targetApp.models import Domain from notification.models import NotificationHooks from scanEngine.models import EngineType, Configuration, Wordlist -from .utils import * +from .common_func import * ''' task for background scan @@ -71,6 +70,7 @@ def doScan(domain_id, scan_history_id, scan_type, engine_type): # once the celery task starts, change the task status to Started task.scan_status = 1 task.last_scan_date = current_scan_time + task.whois = get_whois(domain.domain_name) task.save() activity_id = create_scan_activity(task, "Scanning Started", 2) diff --git a/reNgine/utils.py b/reNgine/utils.py deleted file mode 100644 index 1cd975ca..00000000 --- a/reNgine/utils.py +++ /dev/null @@ -1,2 +0,0 @@ -def check_keyword_exists(keyword_list, subdomain): - return any(sub in subdomain for sub in keyword_list) diff --git a/requirements.txt b/requirements.txt index 0ebbc557..ca1dce2a 100644 --- a/requirements.txt +++ b/requirements.txt @@ -51,3 +51,4 @@ validators==0.18.1 vine==5.0.0 wcwidth==0.2.5 discord-webhook==0.11.0 +python-whois diff --git a/startScan/migrations/0002_scanhistory_whois_json.py b/startScan/migrations/0002_scanhistory_whois_json.py new file mode 100644 index 00000000..73111fe7 --- /dev/null +++ b/startScan/migrations/0002_scanhistory_whois_json.py @@ -0,0 +1,18 @@ +# Generated by Django 3.1.6 on 2021-04-17 16:04 + +from django.db import migrations, models + + +class Migration(migrations.Migration): + + dependencies = [ + ('startScan', '0001_initial'), + ] + + operations = [ + migrations.AddField( + model_name='scanhistory', + name='whois_json', + field=models.JSONField(null=True), + ), + ] diff --git a/startScan/models.py b/startScan/models.py index bd21872c..bf4dc561 100644 --- a/startScan/models.py +++ b/startScan/models.py @@ -10,6 +10,7 @@ class ScanHistory(models.Model): domain_name = models.ForeignKey(Domain, on_delete=models.CASCADE) scan_type = models.ForeignKey(EngineType, on_delete=models.CASCADE) celery_id = models.CharField(max_length=100, blank=True) + whois_json = JSONField(null=True) def __str__(self): # debug purpose remove scan type and id in prod diff --git a/startScan/templates/startScan/detail_scan.html b/startScan/templates/startScan/detail_scan.html index 2d4feef7..1952f8b5 100644 --- a/startScan/templates/startScan/detail_scan.html +++ b/startScan/templates/startScan/detail_scan.html @@ -49,11 +49,7 @@ All Subdomains
-
-
Statistics
-
-

{{subdomain_count|intcomma}} +5 -10

@@ -76,181 +72,19 @@ All Subdomains

{{total_vulnerability_count|intcomma}}+5 -10

Vulnerabilities Discovered

+ {% if history.scan_type.vulnerability_scan %}

{{critical_count}} Critical, {{high_count}} High

{{medium_count}} Medium Vulnerabilities

View all Vulnerabilities + {% else %} Vulnerability scan hasn't been performed. -
Please perform vulnerability scan to identify the vulnerabilities. + {% endif %}
-
-
-
- {% if scan_history_id %} -
-
-
-
-
Recent Activities
-
-
-
-
- {% for activity in scan_activity %} -
-
-
-
- {{activity.title}} - - {% if activity.status == 0 %} Failed  - {% elif activity.status == 1 %} In progress  - {% elif activity.status == 2 %} Completed  - {% endif %} - -

{{activity.time|naturaltime}}

-
-
- {% endfor %} -
-
-
-
-
-
-
-
-
-
- - - - - -
-   -

{{subdomain_count}}

-
Subdomains Discovered
-
-
- Total Alive Subdomains: {{alive_count}} -
- View all subdomains -
-
-
-
-
-
-
- - - - -
-   -

{{endpoint_count}}

-
Endpoints
-
-
- Total Alive Endpoints: {{endpoint_alive_count}} -
- View all Endpoints -
-
-
- {% if history.scan_type.vulnerability_scan %} -
-
-
-
- - - -
-   -

{{total_vulnerability_count}}

-
Vulnerabilities Discovered
-
-
- {{critical_count}} Critical and {{high_count}} High -
- View all Vulnerabilities -
-
-
- {% else %} -
-
-
-
- - - -
-   -

0

-
Vulnerabilities Discovered
-
-
- Vulnerability scan hasn't been performed. -
- Please perform vulnerability scan to identify the vulnerabilities. -
-
-
-
- {% endif %} -
- {% endif %} - {% if history.scan_type.vulnerability_scan %} - {% if info_count > 0 or low_count > 0 or medium_count > 0 or high_count > 0 or critical_count > 0 %} -
-
-
-
-
Vulnerability Scan Summary
-
-
-
-
-
-
-
- {% endif %} - {% endif %} - {% include 'base/_items/interesting_recon.html' %} -
-
-
-
{% if scan_history_id %}Subdomains Discovered {% else %}All Discovered Subdomains{% endif %}
- {% if subdomain_count and scan_history_id %} - Export Subdomains(txt format) - Export URLs(txt format) - {% endif %} -
- - - - - - - - - - - - - - - -
StatusSubdomainIP AddressHTTP StatusPortsContent LengthPage TitleTechnologyScreenshotDirectories
-
-
-
-
+
+
{% endblock main_content %} @@ -264,10 +98,19 @@ All Subdomains + +