From ec8956f575f3d267da163117826af71ecc510765 Mon Sep 17 00:00:00 2001 From: Siddharth Bharadwaj <45765901+SiddharthBharadwaj@users.noreply.github.com> Date: Mon, 16 Aug 2021 14:18:48 +0530 Subject: [PATCH 1/5] Fix double slash issue in directory urls This was achieved by removing the first character i.e. '/' from the path var. --- web/startScan/templates/startScan/detail_scan.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/web/startScan/templates/startScan/detail_scan.html b/web/startScan/templates/startScan/detail_scan.html index 9af1ba54..70f3c87d 100644 --- a/web/startScan/templates/startScan/detail_scan.html +++ b/web/startScan/templates/startScan/detail_scan.html @@ -1514,7 +1514,7 @@ $("#pills-directories-tab").click(function() { { if(json_obj[i].status==200) { - var path = json_obj[i].path; + var path = json_obj[i].path.substring(1); var contentlength = (json_obj[i]["content-length"]/1000).toFixed(2); // id path has / the its a directory else consider as file if (path.substr(path.length - 1) == '/') { From 81ed741d4038415a4f3b9b33c0c31a240ef2bb05 Mon Sep 17 00:00:00 2001 From: Siddharth Bharadwaj <45765901+SiddharthBharadwaj@users.noreply.github.com> Date: Mon, 16 Aug 2021 20:17:30 +0530 Subject: [PATCH 2/5] Fixed custom wordlist upload The server was throwing internal server error when trying to upload wordlists. After some observation, it was found that the wordlist path was creating problems. * Apart from current fix, an alternate fix also exists. Which is to use "/usr/src/app/tools/wordlist/" instead of "/app/tools/wordlist/" as the wordlist path. --- web/scanEngine/views.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/web/scanEngine/views.py b/web/scanEngine/views.py index d65b529a..24e5762a 100644 --- a/web/scanEngine/views.py +++ b/web/scanEngine/views.py @@ -98,9 +98,9 @@ def add_wordlist(request): txt_file = request.FILES['upload_file'] if txt_file.content_type == 'text/plain': wordlist_content = txt_file.read().decode('UTF-8') - wordlist_path = '/app/tools/wordlist/' wordlist_file = open( - wordlist_path + + settings.TOOL_LOCATION + + 'wordlist/' + form.cleaned_data['short_name'] + '.txt', 'w') wordlist_file.write(wordlist_content) From d7d95003ac3339cba618e654e332156b90a3604f Mon Sep 17 00:00:00 2001 From: Siddharth Bharadwaj <45765901+SiddharthBharadwaj@users.noreply.github.com> Date: Tue, 17 Aug 2021 11:02:45 +0530 Subject: [PATCH 3/5] Ignore bytes that are not decoded by UTF-8 decode Some wordlists were not getting uploaded due to decode issues and the server was throwing internal server error. Ignoring the affected bytes fixed the issue. --- web/scanEngine/views.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/web/scanEngine/views.py b/web/scanEngine/views.py index 24e5762a..fa0953b3 100644 --- a/web/scanEngine/views.py +++ b/web/scanEngine/views.py @@ -97,7 +97,7 @@ def add_wordlist(request): if form.is_valid() and 'upload_file' in request.FILES: txt_file = request.FILES['upload_file'] if txt_file.content_type == 'text/plain': - wordlist_content = txt_file.read().decode('UTF-8') + wordlist_content = txt_file.read().decode('UTF-8', "ignore") wordlist_file = open( settings.TOOL_LOCATION + 'wordlist/' + From 1b14bb1b4b12cffc5312b73f50411d12722097f9 Mon Sep 17 00:00:00 2001 From: Yogesh Ojha Date: Thu, 26 Aug 2021 11:03:38 +0530 Subject: [PATCH 4/5] fixed directory path --- web/startScan/templates/startScan/detail_scan.html | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/web/startScan/templates/startScan/detail_scan.html b/web/startScan/templates/startScan/detail_scan.html index 70f3c87d..b80d354c 100644 --- a/web/startScan/templates/startScan/detail_scan.html +++ b/web/startScan/templates/startScan/detail_scan.html @@ -1508,20 +1508,24 @@ $("#pills-directories-tab").click(function() { data = JSON.parse(data)['results']; var html_treeview = `