From cdaa7a52c09a6fd85eefb82ee721d6e92afa4fca Mon Sep 17 00:00:00 2001 From: Yogesh Ojha Date: Mon, 2 Aug 2021 10:58:43 +0530 Subject: [PATCH] Out of scope added in start scan ui --- web/reNgine/tasks.py | 17 ++++++++--------- .../templates/startScan/start_scan_ui.html | 9 ++++++++- web/startScan/views.py | 12 +++++++++++- 3 files changed, 27 insertions(+), 11 deletions(-) diff --git a/web/reNgine/tasks.py b/web/reNgine/tasks.py index ef0e5a15..a838bc49 100644 --- a/web/reNgine/tasks.py +++ b/web/reNgine/tasks.py @@ -53,7 +53,9 @@ def initiate_scan( scan_history_id, scan_type, engine_type, - imported_subdomains=None): + imported_subdomains=None, + out_of_scope_subdomains=None + ): ''' scan_type = 0 -> immediate scan, need not create scan object scan_type = 1 -> scheduled scan @@ -149,7 +151,9 @@ def initiate_scan( domain, yaml_configuration, results_dir, - activity_id) + activity_id, + out_of_scope_subdomains + ) else: skip_subdomain_scan(task, domain, results_dir) @@ -330,7 +334,7 @@ def extract_imported_subdomain(imported_subdomains, task, domain, results_dir): file.close() -def subdomain_scan(task, domain, yaml_configuration, results_dir, activity_id): +def subdomain_scan(task, domain, yaml_configuration, results_dir, activity_id, out_of_scope_subdomains=None): ''' This function is responsible for performing subdomain enumeration ''' @@ -339,10 +343,6 @@ def subdomain_scan(task, domain, yaml_configuration, results_dir, activity_id): send_notification('Subdomain Gathering for target {} has been started'.format(domain.name)) subdomain_scan_results_file = results_dir + '/sorted_subdomain_collection.txt' - # Excluded subdomains - excluded_subdomains = '' - if EXCLUDED_SUBDOMAINS in yaml_configuration: - excluded_subdomains = yaml_configuration[EXCLUDED_SUBDOMAINS] # check for all the tools and add them into string # if tool selected is all then make string, no need for loop @@ -478,7 +478,7 @@ def subdomain_scan(task, domain, yaml_configuration, results_dir, activity_id): for _subdomain in subdomain_list: __subdomain = _subdomain.rstrip('\n') if not Subdomain.objects.filter(scan_history=task, name=__subdomain).exists( - ) and validators.domain(__subdomain) and __subdomain not in excluded_subdomains: + ) and validators.domain(__subdomain) and __subdomain not in out_of_scope_subdomains: subdomain_dict = DottedDict({ 'scan_history': task, 'target_domain': domain, @@ -663,7 +663,6 @@ def http_crawler(task, domain, results_dir, activity_id): endpoint.save() except Exception as exception: logging.error(exception) - update_last_activity(activity_id, 0) alive_file.close() if notification and notification[0].send_scan_status_notif: diff --git a/web/startScan/templates/startScan/start_scan_ui.html b/web/startScan/templates/startScan/start_scan_ui.html index 701245e7..9b038f32 100644 --- a/web/startScan/templates/startScan/start_scan_ui.html +++ b/web/startScan/templates/startScan/start_scan_ui.html @@ -58,7 +58,7 @@ Start Scan for {{domain.name}} -

Import Subdomains

+

Import/Ignore Subdomains

@@ -66,6 +66,13 @@ Start Scan for {{domain.name}}
+
+
+ +
+ + +
diff --git a/web/startScan/views.py b/web/startScan/views.py index aa15c389..b8b6b3a2 100644 --- a/web/startScan/views.py +++ b/web/startScan/views.py @@ -120,12 +120,22 @@ def start_scan_ui(request, domain_id): # get imported subdomains imported_subdomains = [subdomain.rstrip() for subdomain in request.POST['importSubdomainTextArea'].split('\n')] imported_subdomains = [subdomain for subdomain in imported_subdomains if subdomain] + + out_of_scope_subdomains = [subdomain.rstrip() for subdomain in request.POST['outOfScopeSubdomainTextarea'].split('\n')] + out_of_scope_subdomains = [subdomain for subdomain in out_of_scope_subdomains if subdomain] # get engine type engine_type = request.POST['scan_mode'] scan_history_id = create_scan_object(domain_id, engine_type) # start the celery task celery_task = initiate_scan.apply_async( - args=(domain_id, scan_history_id, 0, engine_type, imported_subdomains)) + args=( + domain_id, + scan_history_id, + 0, + engine_type, + imported_subdomains, + out_of_scope_subdomains + )) ScanHistory.objects.filter( id=scan_history_id).update( celery_id=celery_task.id)