diff --git a/docker-compose.dev.yml b/docker-compose.dev.yml index 3a6b0475..30785609 100644 --- a/docker-compose.dev.yml +++ b/docker-compose.dev.yml @@ -31,6 +31,7 @@ services: volumes: - ./web:/usr/src/app - github_repos:/usr/src/github + - wordlist:/usr/src/wordlist - scan_results:/usr/src/scan_results - gf_patterns:/root/.gf - nuclei_templates:/root/nuclei-templates @@ -62,6 +63,7 @@ services: volumes: - ./web:/usr/src/app - github_repos:/usr/src/github + - wordlist:/usr/src/wordlist - scan_results:/usr/src/scan_results - gf_patterns:/root/.gf - nuclei_templates:/root/nuclei-templates @@ -87,6 +89,7 @@ services: volumes: - ./web:/usr/src/app - github_repos:/usr/src/github + - wordlist:/usr/src/wordlist - scan_results:/usr/src/scan_results - gf_patterns:/root/.gf - nuclei_templates:/root/nuclei-templates @@ -116,4 +119,5 @@ volumes: gf_patterns: nuclei_templates: github_repos: + wordlist: scan_results: diff --git a/docker-compose.yml b/docker-compose.yml index de43691a..c0601829 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -31,6 +31,7 @@ services: volumes: - ./web:/usr/src/app - github_repos:/usr/src/github + - wordlist:/usr/src/wordlist - scan_results:/usr/src/scan_results - gf_patterns:/root/.gf - nuclei_templates:/root/nuclei-templates @@ -66,6 +67,7 @@ services: volumes: - ./web:/usr/src/app - github_repos:/usr/src/github + - wordlist:/usr/src/wordlist - scan_results:/usr/src/scan_results - gf_patterns:/root/.gf - nuclei_templates:/root/nuclei-templates @@ -91,6 +93,7 @@ services: volumes: - ./web:/usr/src/app - github_repos:/usr/src/github + - wordlist:/usr/src/wordlist - scan_results:/usr/src/scan_results - gf_patterns:/root/.gf - nuclei_templates:/root/nuclei-templates @@ -150,6 +153,7 @@ volumes: gf_patterns: nuclei_templates: github_repos: + wordlist: scan_results: static_volume: diff --git a/web/celery-entrypoint.sh b/web/celery-entrypoint.sh index 01487688..d8697c58 100755 --- a/web/celery-entrypoint.sh +++ b/web/celery-entrypoint.sh @@ -85,7 +85,12 @@ fi # store scan_results if [ ! -d "/usr/src/scan_results" ] then - mkdir /usr/src/scan_results + mkdir /usr/src/scan_results +fi + +# check if default wordlist for amass exists +if [ ! -f /usr/src/wordlist/deepmagic.com-prefixes-top50000.txt ]; then + wget https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/DNS/deepmagic.com-prefixes-top50000.txt -O /usr/src/wordlist/deepmagic.com-prefixes-top50000.txt fi # test tools, required for configuration diff --git a/web/reNgine/tasks.py b/web/reNgine/tasks.py index cb6b2580..64992c54 100644 --- a/web/reNgine/tasks.py +++ b/web/reNgine/tasks.py @@ -382,17 +382,16 @@ def subdomain_scan(task, domain, yaml_configuration, results_dir, activity_id, o if AMASS_WORDLIST in yaml_configuration[SUBDOMAIN_DISCOVERY]: wordlist = yaml_configuration[SUBDOMAIN_DISCOVERY][AMASS_WORDLIST] if wordlist == 'default': - wordlist_path = settings.TOOL_LOCATION + AMASS_DEFAULT_WORDLIST_PATH + wordlist_path = '/usr/src/wordlist/deepmagic.com-prefixes-top50000.txt' else: - wordlist_path = settings.TOOL_LOCATION + 'wordlist/' + wordlist + '.txt' + wordlist_path = '/usr/src/wordlist/' + wordlist + '.txt' if not os.path.exists(wordlist_path): - wordlist_path = settings.TOOL_LOCATION + AMASS_WORDLIST + wordlist_path = '/usr/src/' + AMASS_WORDLIST amass_command = amass_command + \ ' -brute -w {}'.format(wordlist_path) if amass_config_path: amass_command = amass_command + \ - ' -config {}'.format(settings.TOOL_LOCATION + - 'scan_results/' + amass_config_path) + ' -config {}'.format('/usr/src/scan_results/' + amass_config_path) # Run Amass Active logging.info(amass_command) @@ -878,7 +877,7 @@ def directory_brute(task, domain, yaml_configuration, results_dir, activity_id): 'default' in yaml_configuration[DIR_FILE_SEARCH][WORDLIST]): wordlist_location = '/usr/src/github/dirsearch/db/dicc.txt' else: - wordlist_location = settings.TOOL_LOCATION + 'wordlist/' + \ + wordlist_location = '/usr/src/wordlist/' + \ yaml_configuration[DIR_FILE_SEARCH][WORDLIST] + '.txt' dirsearch_command += ' -w {}'.format(wordlist_location) diff --git a/web/scanEngine/views.py b/web/scanEngine/views.py index c5ecca4a..c54ea2e2 100644 --- a/web/scanEngine/views.py +++ b/web/scanEngine/views.py @@ -97,10 +97,10 @@ def add_wordlist(request): if form.is_valid() and 'upload_file' in request.FILES: txt_file = request.FILES['upload_file'] if txt_file.content_type == 'text/plain': - wordlist_content = txt_file.read().decode('UTF-8') - wordlist_path = '/app/tools/wordlist/' + wordlist_content = txt_file.read().decode('UTF-8', "ignore") wordlist_file = open( - wordlist_path + + '/usr/src/' + + 'wordlist/' + form.cleaned_data['short_name'] + '.txt', 'w') wordlist_file.write(wordlist_content) diff --git a/web/startScan/templates/startScan/detail_scan.html b/web/startScan/templates/startScan/detail_scan.html index 9af1ba54..b80d354c 100644 --- a/web/startScan/templates/startScan/detail_scan.html +++ b/web/startScan/templates/startScan/detail_scan.html @@ -1508,8 +1508,12 @@ $("#pills-directories-tab").click(function() { data = JSON.parse(data)['results']; var html_treeview = `