diff --git a/startScan/api/serializers.py b/startScan/api/serializers.py index 124f571d..101199fa 100644 --- a/startScan/api/serializers.py +++ b/startScan/api/serializers.py @@ -54,6 +54,7 @@ class TechnologyCountSerializer(serializers.Serializer): count = serializers.CharField() name = serializers.CharField() + class TechnologySerializer(serializers.ModelSerializer): class Meta: model = Technology diff --git a/startScan/api/urls.py b/startScan/api/urls.py index 1637d068..f1a77669 100644 --- a/startScan/api/urls.py +++ b/startScan/api/urls.py @@ -26,7 +26,9 @@ router.register(r'listIps', IpAddressViewSet) urlpatterns = [ url('^', include(router.urls)), - path('listTechnologies', ListTechnologies.as_view(), name='listTechnologies'), + path('listTechnologies/', ListTechnology.as_view(), name='listTechnologies'), + path('listPorts/', ListPorts.as_view(), name='listPorts'), + path('listIPs/', ListIPs.as_view(), name='listIPs'), ] urlpatterns += router.urls diff --git a/startScan/api/views.py b/startScan/api/views.py index b1ab2e48..4f96cb4b 100644 --- a/startScan/api/views.py +++ b/startScan/api/views.py @@ -17,20 +17,49 @@ from rest_framework.response import Response from rest_framework import status from rest_framework.decorators import api_view, action -class ListTechnologies(APIView): + +class ListTechnology(APIView): def get(self, request, format=None): req = self.request scan_id = req.query_params.get('scan_id') if scan_id: - tech = Technology.objects.filter(technologies__in=Subdomain.objects.filter(scan_history__id=scan_id)).annotate(count=Count('name')) + tech = Technology.objects.filter(technologies__in=Subdomain.objects.filter(scan_history__id=scan_id)).annotate(count=Count('name')).order_by('-count') serializer = TechnologyCountSerializer(tech, many=True) return Response({"technologies": serializer.data}) else: - all_tech = Technology.objects.all() - serializer = TechnologySerializer(all_tech, many=True) + tech = Technology.objects.filter(technologies__in=Subdomain.objects.all()).annotate(count=Count('name')).order_by('-count') + serializer = TechnologyCountSerializer(tech, many=True) return Response({"technologies": serializer.data}) +class ListPorts(APIView): + def get(self, request, format=None): + req = self.request + scan_id = req.query_params.get('scan_id') + if scan_id: + port = Port.objects.filter(ports__in=IpAddress.objects.filter(ip_addresses__in=Subdomain.objects.filter(scan_history__id=scan_id))).distinct() + serializer = PortSerializer(port, many=True) + return Response({"ports": serializer.data}) + else: + port = Port.objects.filter(ports__in=IpAddress.objects.filter(ip_addresses__in=Subdomain.objects.all())).distinct() + serializer = PortSerializer(port, many=True) + return Response({"ports": serializer.data}) + + +class ListIPs(APIView): + def get(self, request, format=None): + req = self.request + scan_id = req.query_params.get('scan_id') + if scan_id: + ips = IpAddress.objects.filter(ip_addresses__in=Subdomain.objects.filter(scan_history__id=scan_id)).distinct() + serializer = IpSerializer(ips, many=True) + return Response({"ips": serializer.data}) + else: + ips = IpAddress.objects.filter(ip_addresses__in=Subdomain.objects.all()).distinct() + serializer = IpSerializer(ips, many=True) + return Response({"ips": serializer.data}) + + class IpAddressViewSet(viewsets.ModelViewSet): queryset = Subdomain.objects.none() serializer_class = IpSubdomainSerializer diff --git a/startScan/migrations/0035_auto_20210609_1847.py b/startScan/migrations/0035_auto_20210609_1847.py new file mode 100644 index 00000000..495ab5dd --- /dev/null +++ b/startScan/migrations/0035_auto_20210609_1847.py @@ -0,0 +1,18 @@ +# Generated by Django 3.1.6 on 2021-06-09 18:47 + +from django.db import migrations, models + + +class Migration(migrations.Migration): + + dependencies = [ + ('startScan', '0034_auto_20210609_0406'), + ] + + operations = [ + migrations.AlterField( + model_name='ipaddress', + name='ports', + field=models.ManyToManyField(related_name='ports', to='startScan.Port'), + ), + ] diff --git a/startScan/models.py b/startScan/models.py index 8048a063..657b4422 100644 --- a/startScan/models.py +++ b/startScan/models.py @@ -231,7 +231,7 @@ class Technology(models.Model): class IpAddress(models.Model): address = models.CharField(max_length=100, blank=True, null=True) is_cdn = models.BooleanField(default=False) - ports = models.ManyToManyField('Port', related_name='port') + ports = models.ManyToManyField('Port', related_name='ports') def __str__(self): return str(self.address) diff --git a/startScan/templates/startScan/detail_scan.html b/startScan/templates/startScan/detail_scan.html index 866166c7..1ef0a457 100644 --- a/startScan/templates/startScan/detail_scan.html +++ b/startScan/templates/startScan/detail_scan.html @@ -261,18 +261,13 @@ Detailed Scan Results for {{history.domain.name}}
-
{{ports.count}} Unique Discovered Ports
+
Discovered Ports
*Ports highlighted with red are uncommon Ports.
- {% if not history.port_scan %} - Port Scan has not been initiated, please initiate port scan to discover unique and uncommon ports. - {% else %} - {% for port in ports %} - {{port.0}}/{{port.1}} - {% endfor %} - {% endif %} +
+
@@ -280,11 +275,12 @@ Detailed Scan Results for {{history.domain.name}}
-
{{technology|length}} Discovered Unique Technologies
+
Discovered Technologies
- {{technologies}} +
+
@@ -1290,7 +1286,11 @@ get_endpoint_changes_values({{scan_history_id}}); get_interesting_count({{scan_history_id}}); -get_ip_and_port({{scan_history_id}}); +get_ips({{scan_history_id}}); + +get_technologies({{scan_history_id}}); + +get_ports({{scan_history_id}}); {% if history.fetch_url and history.used_gf_patterns %} // gf patterns diff --git a/static/custom/custom.js b/static/custom/custom.js index 2df2c8a4..196d05bd 100644 --- a/static/custom/custom.js +++ b/static/custom/custom.js @@ -749,32 +749,40 @@ function get_endpoint_changes_values(scan_id){ }); } -function get_ip_and_port(scan_id){ - $.getJSON(`../api/listIps/?scan_id=${scan_id}&no_page`, function(data) { - var ip_array = Array() - var cdn_ip_array = Array() +function get_ips(scan_id){ + $.getJSON(`../api/listIPs/?scan_id=${scan_id}&format=json`, function(data) { $('#ip-address-count').empty(); - for (var val in data){ - // gather ip - for(var ip in data[val]['ip_addresses']){ - if ($.inArray(data[val]['ip_addresses'][ip]['address'], ip_array) == -1 && $.inArray(data[val]['ip_addresses'][ip]['address'], cdn_ip_array) == -1) { - var ip_addr = data[val]['ip_addresses'][ip]['address']; - if (data[val]['ip_addresses'][ip]['is_cdn']) { - badge_color = 'warning' - cdn_ip_array.push(ip_addr); - } - else{ - badge_color = 'info' - ip_array.push(ip_addr); - } - $("#ip-address").append(`${ip_addr}`); - } - } - - + for (var val in data['ips']){ + ip = data['ips'][val] + badge_color = ip['is_cdn'] ? 'warning' : 'info'; + $("#ip-address").append(`${ip['address']}`); } - $('#ip-address-count').html(`${ip_array.length+cdn_ip_array.length}`); - $('#ip-address-summary').html(`(${cdn_ip_array.length} CDN IPs)`); + $('#ip-address-count').html(`${data['ips'].length}`); + $("body").tooltip({ selector: '[data-toggle=tooltip]' }); + }); +} + +function get_technologies(scan_id){ + $.getJSON(`../api/listTechnologies/?scan_id=${scan_id}&format=json`, function(data) { + $('#technologies-count').empty(); + for (var val in data['technologies']){ + tech = data['technologies'][val] + $("#technologies").append(`${tech['name']}`); + } + $('#technologies-count').html(`${data['technologies'].length}`); + $("body").tooltip({ selector: '[data-toggle=tooltip]' }); + }); +} + +function get_ports(scan_id){ + $.getJSON(`../api/listPorts/?scan_id=${scan_id}&format=json`, function(data) { + $('#ports-count').empty(); + for (var val in data['ports']){ + port = data['ports'][val] + badge_color = port['is_uncommon'] ? 'danger' : 'info'; + $("#ports").append(`${port['number']}/${port['service_name']}`); + } + $('#ports-count').html(`${data['ports'].length}`); $("body").tooltip({ selector: '[data-toggle=tooltip]' }); }); }