diff --git a/web/startScan/views.py b/web/startScan/views.py index 74542a1c..dac0b207 100644 --- a/web/startScan/views.py +++ b/web/startScan/views.py @@ -3,7 +3,6 @@ import logging import requests import itertools import tempfile -import markdown from datetime import datetime @@ -639,9 +638,6 @@ def customize_report(request, id): def create_report(request, id): - primary_color = '#FFB74D' - secondary_color = '#212121' - scan_object = ScanHistory.objects.get(id=id) unique_vulnerabilities = Vulnerability.objects.filter(scan_history=scan_object).values("name", "severity").annotate(count=Count('name')).order_by('-severity', '-count') all_vulnerabilities = Vulnerability.objects.filter(scan_history=scan_object).order_by('-severity') @@ -653,7 +649,6 @@ def create_report(request, id): ip_addresses = IpAddress.objects.filter( ip_addresses__in=Subdomain.objects.filter( scan_history__id=id)).distinct() - data = { 'scan_object': scan_object, 'unique_vulnerabilities': unique_vulnerabilities, @@ -661,46 +656,8 @@ def create_report(request, id): 'subdomain_alive_count': subdomain_alive_count, 'interesting_subdomains': interesting_subdomains, 'subdomains': subdomains, - 'ip_addresses': ip_addresses, + 'ip_addresses': ip_addresses } - - # get report related config - if VulnerabilityReportSetting.objects.all().exists(): - report = VulnerabilityReportSetting.objects.all()[0] - data['company_name'] = report.company_name - data['company_address'] = report.company_address - data['company_email'] = report.company_email - data['company_website'] = report.company_website - data['show_rengine_banner'] = report.show_rengine_banner - data['show_footer'] = report.show_footer - data['footer_text'] = report.footer_text - data['show_executive_summary'] = report.show_executive_summary - - primary_color = report.primary_color - secondary_color = report.secondary_color - - description = report.executive_summary_description - - # replace executive_summary_description with template syntax! - description = description.replace('{scan_date}', scan_object.start_scan_date.strftime('%d %B, %Y')) - description = description.replace('{company_name}', report.company_name) - description = description.replace('{target_name}', scan_object.domain.name) - if scan_object.domain.description: - description = description.replace('{target_description}', scan_object.domain.description) - description = description.replace('{subdomain_count}', str(subdomains.count())) - description = description.replace('{vulnerability_count}', str(all_vulnerabilities.count())) - description = description.replace('{critical_count}', str(all_vulnerabilities.filter(severity=4).count())) - description = description.replace('{high_count}', str(all_vulnerabilities.filter(severity=3).count())) - description = description.replace('{medium_count}', str(all_vulnerabilities.filter(severity=2).count())) - description = description.replace('{low_count}', str(all_vulnerabilities.filter(severity=1).count())) - description = description.replace('{info_count}', str(all_vulnerabilities.filter(severity=0).count())) - - # convert to html - data['executive_summary_description'] = markdown.markdown(description) - - data['primary_color'] = primary_color - data['secondary_color'] = secondary_color - template = get_template('report/template.html') html = template.render(data) pdf = HTML(string=html).write_pdf() diff --git a/web/static/reports/Roboto-Bold.ttf b/web/static/reports/Roboto-Bold.ttf deleted file mode 100644 index d3f01ad2..00000000 Binary files a/web/static/reports/Roboto-Bold.ttf and /dev/null differ diff --git a/web/static/reports/Roboto-Italic.ttf b/web/static/reports/Roboto-Italic.ttf deleted file mode 100644 index 6a1cee5b..00000000 Binary files a/web/static/reports/Roboto-Italic.ttf and /dev/null differ diff --git a/web/static/reports/Roboto-Light.ttf b/web/static/reports/Roboto-Light.ttf deleted file mode 100644 index 219063a5..00000000 Binary files a/web/static/reports/Roboto-Light.ttf and /dev/null differ diff --git a/web/static/reports/Roboto-LightItalic.ttf b/web/static/reports/Roboto-LightItalic.ttf deleted file mode 100644 index 0e81e876..00000000 Binary files a/web/static/reports/Roboto-LightItalic.ttf and /dev/null differ diff --git a/web/static/reports/Roboto-Regular.ttf b/web/static/reports/Roboto-Regular.ttf deleted file mode 100644 index 2c97eead..00000000 Binary files a/web/static/reports/Roboto-Regular.ttf and /dev/null differ diff --git a/web/static/reports/Roboto-Thin.ttf b/web/static/reports/Roboto-Thin.ttf deleted file mode 100644 index b74a4fd1..00000000 Binary files a/web/static/reports/Roboto-Thin.ttf and /dev/null differ diff --git a/web/static/reports/heading.svg b/web/static/reports/heading.svg deleted file mode 100644 index 7e6bbb79..00000000 --- a/web/static/reports/heading.svg +++ /dev/null @@ -1,26 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - diff --git a/web/static/reports/report.css b/web/static/reports/report.css deleted file mode 100644 index b3e3683d..00000000 --- a/web/static/reports/report.css +++ /dev/null @@ -1,459 +0,0 @@ -@font-face { - font-family: roboto-regular; - font-weight: 300; - src: url(Roboto-Regular.ttf); -} -@font-face { - font-family: roboto-italic; - font-style: italic; - font-weight: 400; - src: url(Roboto-Ialic.ttf); -} -@font-face { - font-family: roboto-light; - font-weight: 300; - src: url(Roboto-Light.ttf); -} -@font-face { - font-family: roboto-lightitalic; - font-style: italic; - font-weight: 300; - src: url(Roboto-LightItalic.ttf); -} -@font-face { - font-family: roboto-bold; - font-weight: 700; - src: url(Roboto-Bold.ttf); -} - -@page { - size: A4; - @top-left { - background: #FF7043; - content: counter(page); - height: 1cm; - text-align: center; - width: 1cm; - } - @top-center { - background: #FF7043; - content: ''; - display: block; - height: .05cm; - opacity: .5; - width: 100%; - } - @top-right { - content: string(heading); - font-size: 9pt; - height: 1cm; - vertical-align: middle; - width: 100%; - } -} -@page :blank { - @top-left { background: none; content: '' } - @top-center { content: none } - @top-right { content: none } -} -@page no-chapter { - @top-left { background: none; content: none } - @top-center { content: none } - @top-right { content: none } -} - -@page :first { - background-color: #424242; - background-size: cover; - margin: 0; -} -@page chapter { - background: #FF7043; - margin: 0; - @top-left { content: none } - @top-center { content: none } - @top-right { content: none } -} - -html { - color: #393939; - font-family: roboto-regular; - font-size: 11pt; - font-weight: 300; - line-height: 1.5; -} - -h1 { - font-family: roboto-light; - font-size: 38pt; - margin: 5cm 2cm 0 2cm; - page: no-chapter; - width: 100%; - line-height: normal; -} - -.subheading { - font-family: roboto-light; - font-size: 22pt; - width: 100%; -} - -h2, h3, h4 { - font-family: roboto-regular; - color: black; - font-weight: 400; - line-height: normal; -} - -h2 { - font-size: 28pt; - string-set: heading content(); -} - -h3 { - font-family: roboto-light; - font-weight: 100; - font-size: 15pt; -} - -h4 { - font-size: 13pt; -} - -#cover { - align-content: space-between; - display: flex; - flex-wrap: wrap; - height: 297mm; -} - -#cover footer { - background: #FF7043; - flex: 1 33%; - margin: 0 -2cm; - padding: 1cm 0; - white-space: pre-wrap; -} - -#cover footer:first-of-type { - padding-left: 3cm; -} - -#summary { - display: flex; - flex-wrap: wrap; - justify-content: space-between; -} - -#summary h2, #summary h3 { - width: 100%; -} - -#summary section { - width: 30%; -} - -#summary section h4 { - margin-bottom: 0; -} -#summary section ul { - list-style: none; - margin: 0; - padding-left: 0; -} -#summary section ul li:not(:last-of-type) { - margin: .5cm 0; -} -#summary section p { - background: #FF7043; - display: block; - font-size: 15pt; - font-weight: 700; - margin-bottom: 0; - padding: .25cm 0; - text-align: center; -} - -#vulnerability-boxes { - display: flex; - flex-wrap: wrap; - justify-content: space-between; -} - -#vulnerability-boxes section { - width: 24%; -} - -#vulnerability-boxes section h4 { - margin-bottom: 0; -} - -#vulnerability-boxes section p { - background: #FF7043; - display: block; - font-size: 15pt; - font-weight: 700; - margin-bottom: 0; - padding: .25cm 0; - text-align: center; - height: 85px; - color: #37474F; -} - -.critical{ - background: #EF9A9A !important; -} -.high{ - background: #FFAB91 !important; -} -.medium{ - background: #FFCC80 !important; -} -.low{ - background: #FFE082 !important; -} -.success{ - background-color: #A5D6A7 !important; -} -.grey{ - background-color: #B0BEC5 !important; -} -.info{ - background-color: #90CAF9 !important; -} - -.badge{ - display:inline-block; - padding-left:8px; - padding-right:8px; - text-align:center -} - -.dark-text{ - color: #424242; -} - -.critical-border{ - border-style:solid; - border-width: 1px; - border-color: #EF9A9A !important; -} -.high-border{ - border-style:solid; - border-width: 1px; - border-color: #FFAB91 !important; -} -.medium-border{ - border-style:solid; - border-width: 1px; - border-color: #FFCC80 !important; -} -.low-border{ - border-style:solid; - border-width: 1px; - border-color: #FFE082 !important; -} -.success-border{ - border-style:solid; - border-width: 1px; - border-color: #A5D6A7 !important; -} -.grey-border{ - border-style:solid; - border-width: 1px; - border-color: #B0BEC5 !important; -} -.info-border{ - border-style:solid; - border-width: 1px; - border-color: #90CAF9 !important; -} - -.critical-text{ - color: #EF9A9A !important; -} -.high-text{ - color: #FFAB91 !important; -} -.medium-text{ - color: #FFCC80 !important; -} -.low-text{ - color: #FFE082 !important; -} -.info-text{ - color: #29B6F6 !important; -} - -.critical-line{ - border-bottom: 3px solid #EF9A9A !important; -} -.high-line{ - border-bottom: 3px solid #FFAB91 !important; -} -.medium-line{ - border-bottom: 3px solid #FFCC80 !important; -} -.low-line{ - border-bottom: 3px solid #FFE082 !important; -} -.info-line{ - border-bottom: 3px solid #90CAF9 !important; -} - - -#vulnerability-count{ - font-size: 30pt; -} - -#info_title{ - font-size: 13pt; - color: #29B6F6; -} - -.bold-h3{ - font-family: roboto-medium; - font-size: 18pt; -} - -.small_text{ - font-size: 9pt; -} - -.bold{ - font-weight: bold; -} - -.line { - border-bottom: 1px double #FF7043; -} - -.light-title{ - font-family: roboto-light; -} - -#primary-title{ - color: #FF7043; -} - -#mini-text{ - font-size: 11px; -} - -.table{ - margin: 0 0 40px 0; - width: 100%; - box-shadow: 0 1px 3px rgba(0,0,0,0.2); - display: table; - border-spacing: 0 0.4em; -} - -.row{ - display: table-row; - background: #f6f6f6; -} - -.cell{ - padding: 6px 6px 6px 6px; - display: table-cell; -} - -.header{ - font-weight: 900; - color: #ffffff; -} - -.red-header{ - background: #ea6153; -} - -.blue-header{ - background: #1E88E5; -} - -.green-header{ - background: #66BB6A; -} - -.info-cell{ - background: #42A5F5; -} - -.severity-title-box{ - color: #37474F; -} - - -#contents { - page: no-chapter; -} -#contents h2 { - font-size: 20pt; - font-weight: 400; - margin-bottom: 3cm; -} -#contents h3 { - font-weight: 500; - margin: 3em 0 1em; -} -#contents h3::before { - background: #FF7043; - content: ''; - display: block; - height: .08cm; - margin-bottom: .25cm; - width: 2cm; -} -#contents ul { - list-style: none; - padding-left: 0; -} -#contents ul li { - border-top: .25pt solid #c1c1c1; - margin: .25cm 0; - padding-top: .25cm; -} -#contents ul li::before { - color: #FF7043; - content: '• '; - font-size: 30pt; - line-height: 16pt; - vertical-align: bottom; -} -#contents ul li a { - color: inherit; - text-decoration-line: inherit; -} -#contents ul li a::before { - content: target-text(attr(href)); -} -#contents ul li a::after { - color: #FF7043; - content: target-counter(attr(href), page); - float: right; -} - -#columns section { - columns: 2; - column-gap: 1cm; - padding-top: 1cm; -} -#columns section p { - text-align: justify; -} -#columns section p:first-of-type { - font-weight: 700; -} - - -.line-break{ - display: block; -} - -#chapter { - align-items: center; - display: flex; - height: 297mm; - justify-content: center; - page: chapter; -} diff --git a/web/static/reports/style.svg b/web/static/reports/style.svg deleted file mode 100644 index 3930090f..00000000 --- a/web/static/reports/style.svg +++ /dev/null @@ -1,29 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - diff --git a/web/static/reports/table-content.svg b/web/static/reports/table-content.svg deleted file mode 100644 index 9961a203..00000000 --- a/web/static/reports/table-content.svg +++ /dev/null @@ -1,21 +0,0 @@ - - - - - - - - - - - - - - - - - - diff --git a/web/templates/report/full.html b/web/templates/report/full.html deleted file mode 100644 index 507b90b2..00000000 --- a/web/templates/report/full.html +++ /dev/null @@ -1,503 +0,0 @@ - - - - - Report - - - - - -
-

Full Scan Report -
- {{scan_object.domain.name}} -
- {# generated date #} - {% now "F j, Y" %} -

- - - -
-
-

 

-

Table of contents

- -
- -
-

Quick Summary

-

This section contains quick summary of scan performed on {{scan_object.domain.name}}

-

Reconnaissance

-
-
-
-

Subdomains -
- - {{scan_object.get_subdomain_count}} - -

-
-
-

Endpoints -
- - {{scan_object.get_endpoint_count}} - -

-
-
-

Vulnerabilities -
- - {{scan_object.get_vulnerability_count}} - -

-
-
-
-
-

Vulnerability Summary

-
-
-

Critical -
- - {{scan_object.get_critical_vulnerability_count}} - -

-
-
-

High -
- - {{scan_object.get_high_vulnerability_count}} - -

-
-
-

Medium -
- - {{scan_object.get_medium_vulnerability_count}} - -

-
-
-

Low -
- - {{scan_object.get_low_vulnerability_count}} - -

-
-
- * {{scan_object.get_info_vulnerability_count}} Informational Vulnerabilities Identified -
-
-

Timeline of the Assessment

-

- Scan started on: {{scan_object.start_scan_date|date:"F j, Y h:i"}} -
- Total time taken: - {% if scan_object.scan_status == 0 %} - {{ scan_object.start_scan_date|timesince:scan_object.stop_scan_date }} - {% elif scan_object.scan_status == 1 %} - {{ scan_object.get_elapsed_time }} - {% elif scan_object.scan_status == 2 %} - {% if scan_object.get_completed_time_in_sec < 60 %} - Completed in < 1 minutes {% else %} Completed in {{ scan_object.start_scan_date|timesince:scan_object.stop_scan_date }} {% endif %} {% elif scan_object.scan_status == 3 %} Aborted in - {{ scan_object.start_scan_date|timesince:scan_object.stop_scan_date }} {% endif %}
- Report Generated on: {% now "F j, Y" %} -

-
- {% if interesting_subdomains %} -
-

Interesting Recon Data

-

Listed below are the {{interesting_subdomains.count}} interesting subdomains identified on {{scan_object.domain.name}}

-
-
-
- # -
-
- Subdomain -
-
- Page title -
-
- HTTP Status -
-
- {% for subdomain in interesting_subdomains %} -
-
- {{ forloop.counter }} -
-
- {{subdomain.name}} -
-
- {% if subdomain.page_title %} - {{subdomain.page_title}} - {% else %} -     - {% endif %} -
-
- {% if subdomain.http_status %} - {{subdomain.http_status}} - {% else %} -     - {% endif %} -
-
- {% endfor %} -
-
- {% endif %} - {% if all_vulnerabilities.count > 0 %} -
-

Summary of Vulnerabilities Identified

-

Listed below are the vulnerabilities identified on {{scan_object.domain.name}}

-
-
-
- # -
-
- Vulnerability Name -
-
- Times Identified -
-
- Severity -
-
- {% for vulnerability in unique_vulnerabilities %} -
-
- {{ forloop.counter }} -
-
- {{vulnerability.name}} -
-
- {{vulnerability.count}} -
- {% if vulnerability.severity == 0 %} -
- Informational - {% elif vulnerability.severity == 1 %} -
- Low - {% elif vulnerability.severity == 2 %} -
- Medium - {% elif vulnerability.severity == 3 %} -
- High - {% elif vulnerability.severity == 4 %} -
- Critical - {% endif %} -
-
- {% endfor %} -
-
- {% endif %} -
-

Discovered Assets

-

Subdomains

-

- During the reconnaissance phase, {{scan_object.get_subdomain_count}} subdomains were discovered. - Out of {{scan_object.get_subdomain_count}} subdomains, {{subdomain_alive_count}} returned HTTP status 200. - {{interesting_subdomains.count}} interesting subdomains were also identified based on the interesting keywords used. -

-

{{scan_object.get_subdomain_count}} subdomains identified on {{scan_object.domain.name}}

-
-
-
- Subdomain -
-
- Page title -
-
- HTTP Status -
-
- {% for subdomain in subdomains %} -
-
- {{subdomain.name}} -
-
- {% if subdomain.page_title %} - {{subdomain.page_title}} - {% endif %} -
-
- {{subdomain.http_status}} -
-
- {% endfor %} -
- {% if ip_addresses.count %} -

IP Addresses

-

{{ip_addresses.count}} IP Addresses were identified on {{scan_object.domain.name}}

-
-
-
- IP -
-
- Open Ports -
-
- Remarks -
-
- {% for ip in ip_addresses %} -
-
- {{ip.address}} -
-
- {% for port in ip.ports.all %} - {{port.number}}/{{port.service_name}}{% if not forloop.last %},{% endif %} - {% endfor %} -
- {% if ip.is_cdn %} -
- CDN IP Address - {% else %} -
- {% endif %} -
-
- {% endfor %} -
- {% endif %} -
-
-
-

Reconnaissance Findings

- {% for subdomain in subdomains %} - - - - - {% if subdomain.http_status == 200 %} - - {% elif subdomain.http_status >= 300 and subdomain.http_status < 400 %} - - {% elif subdomain.http_status >= 400 %} - - {% elif subdomain.http_status == 0 %} - - {% else %} - - {% endif %} - - {% if subdomain.page_title %} - - - - {% endif %} - {% if subdomain.ip_addresses.all %} - - - - {% endif %} - {% if subdomain.get_vulnerabilities %} - - - - {% endif %} -
{{ forloop.counter }}.{{subdomain.name}}{{subdomain.http_status}}{{subdomain.http_status}}{{subdomain.http_status}}N/A{{subdomain.http_status}}
Page Title: {{subdomain.page_title}}
- IP Address: -
    - {% for ip in subdomain.ip_addresses.all %} -
  • {{ip.address}} - {% if ip.ports.all %} -
      -
    • Open Ports:   - {% for port in ip.ports.all %} - {{port.number}}/{{port.service_name}}{% if not forloop.last %},{% endif %} - {% endfor %} -
    • -
    - {% endif %} -
  • - {% endfor %} -
-
- Vulnerabilities - {% regroup subdomain.get_vulnerabilities by name as vuln_list %} -
    - {% for vulnerability in vuln_list %} -
  • - {{ vulnerability.grouper }} - {% regroup vulnerability.list by http_url as vuln_http_url_list %} -
      - {% for vuln_urls in vuln_http_url_list %} -
    • - {{vuln_urls.grouper}} -
      - {% for vuln_url in vuln_urls.list %} - - {% if vuln_url.extracted_results %} - {% if not forloop.first %}•{% endif %} {{vuln_url.exextracted_results}} -
      - {% endif %} - {% if vuln_url.matcher_name %} - {% if not forloop.first %} • {% endif %} {{vuln_url.matcher_name}} - {% endif %} -
      - {% endfor %} -
    • - {% endfor %} -
    -
  • - {% endfor %} -
-
- {% endfor %} -
- {% if all_vulnerabilities.count > 0 %} -
-

Vulnerabilities Discovered

-

- This section reports the security issues found during the audit. -
- A Total of {{scan_object.get_vulnerability_count}} were discovered in {{scan_object.domain.name}}, - {{scan_object.get_critical_vulnerability_count}} of them were Critical, - {{scan_object.get_high_vulnerability_count}} of them were High Severity, - {{scan_object.get_medium_vulnerability_count}} of them were Medium severity, - {{scan_object.get_low_vulnerability_count}} of them were Low severity, and - {{scan_object.get_info_vulnerability_count}} of them were Informational. -

-

Vulnerability Breakdown by Severity

-
-
-

Critical -
- - {{scan_object.get_critical_vulnerability_count}} - -

-
-
-

High -
- - {{scan_object.get_high_vulnerability_count}} - -

-
-
-

Medium -
- - {{scan_object.get_medium_vulnerability_count}} - -

-
-
-

Low -
- - {{scan_object.get_low_vulnerability_count}} - -

-
-
- * {{scan_object.get_info_vulnerability_count}} Informational Vulnerabilities Identified -
- {# start vulnerability #} -
- {% regroup all_vulnerabilities by name as grouped_vulnerabilities %} - {% for vulnerability in grouped_vulnerabilities %} -
-

- {{vulnerability.grouper}} - {% if vulnerability.list.0.severity == 0 %} - Informational -
- {% elif vulnerability.list.0.severity == 1 %} - Low -
- {% elif vulnerability.list.0.severity == 2 %} - Medium -
- {% elif vulnerability.list.0.severity == 3 %} - High -
- {% elif vulnerability.list.0.severity == 4 %} - Critical -
- {% endif %} -

- {% if vulnerability.list.0.description %} -
Description
- {{vulnerability.list.0.description}} - {% endif %} -
Vulnerable URL(s)
- {% regroup vulnerability.list by http_url as vuln_http_url_list %} - - {% if vulnerability.list.0.reference %} -
Reference
- {{vulnerability.list.0.reference}} - {% endif %} -
-
-
- {% endfor %} -
- {% endif %} -
-

END OF REPORT

-
- - -