-
Notifications
You must be signed in to change notification settings - Fork 206
Comparing changes
Open a pull request
base repository: wapiti-scanner/wapiti
base: master
head repository: Cyberwatch/wapiti
compare: master
Commits on Sep 20, 2024
-
Bump aiohttp from 3.9.4 to 3.10.2
Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.9.4 to 3.10.2. - [Release notes](https://github.com/aio-libs/aiohttp/releases) - [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst) - [Commits](aio-libs/aiohttp@v3.9.4...v3.10.2) --- updated-dependencies: - dependency-name: aiohttp dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Configuration menu - View commit details
-
Copy full SHA for 087dcda - Browse repository at this point
Copy the full SHA 087dcdaView commit details -
apply changes in wp_enum module from cms/wp_enum to fix false positives
Signed-off-by: bretfourbe <gwendal@cyberwatch.fr>
Configuration menu - View commit details
-
Copy full SHA for 25764d3 - Browse repository at this point
Copy the full SHA 25764d3View commit details -
Configuration menu - View commit details
-
Copy full SHA for 28fd24c - Browse repository at this point
Copy the full SHA 28fd24cView commit details -
Corriger les warnings dans le Dockerfile de tests
Warning: LegacyKeyValueFormat
Configuration menu - View commit details
-
Copy full SHA for 0487dfa - Browse repository at this point
Copy the full SHA 0487dfaView commit details -
Add a script to update CMS hash files from a given database
Configuration menu - View commit details
-
Copy full SHA for f69d80e - Browse repository at this point
Copy the full SHA f69d80eView commit details -
Fix le problème des requetes PUT dans le module swagger en mode headless
Configuration menu - View commit details
-
Copy full SHA for 3188ef9 - Browse repository at this point
Copy the full SHA 3188ef9View commit details -
Configuration menu - View commit details
-
Copy full SHA for a7643a7 - Browse repository at this point
Copy the full SHA a7643a7View commit details -
Ajout d'une option d'authentification
Ajout d'une option pour faire l'authentification à partir d'un fichier .side
Configuration menu - View commit details
-
Copy full SHA for 22b2371 - Browse repository at this point
Copy the full SHA 22b2371View commit details -
Configuration menu - View commit details
-
Copy full SHA for 7dd1e73 - Browse repository at this point
Copy the full SHA 7dd1e73View commit details
Commits on Sep 24, 2024
-
Passer le module wp_enum en DEPRECATED
Mentionner dans la doc que le module wp_enum a été remplacé par le module cms.
Configuration menu - View commit details
-
Copy full SHA for 6d56b3d - Browse repository at this point
Copy the full SHA 6d56b3dView commit details
Commits on Sep 27, 2024
-
Ajout d'autres chemins au dictionnaire de module Buster
Ajout de quelques chemins pour détecter la présence de fichiers .env
Configuration menu - View commit details
-
Copy full SHA for 3e1e280 - Browse repository at this point
Copy the full SHA 3e1e280View commit details -
Add an option to set the JWT token on headers
Configuration menu - View commit details
-
Copy full SHA for 5c17758 - Browse repository at this point
Copy the full SHA 5c17758View commit details
Commits on Sep 30, 2024
-
Configuration menu - View commit details
-
Copy full SHA for bd2b3c7 - Browse repository at this point
Copy the full SHA bd2b3c7View commit details -
Configuration menu - View commit details
-
Copy full SHA for 9dfba09 - Browse repository at this point
Copy the full SHA 9dfba09View commit details
Commits on Oct 2, 2024
-
Correction des petites remarques remontées sur l'option --side-file
Corriger la description de l'option. Remplacer "-sf" par "--sf".
Configuration menu - View commit details
-
Copy full SHA for 56e2ff7 - Browse repository at this point
Copy the full SHA 56e2ff7View commit details
Commits on Oct 7, 2024
-
Configuration menu - View commit details
-
Copy full SHA for f7df7f5 - Browse repository at this point
Copy the full SHA f7df7f5View commit details
Commits on Oct 9, 2024
-
Configuration menu - View commit details
-
Copy full SHA for f80e225 - Browse repository at this point
Copy the full SHA f80e225View commit details
Commits on Oct 23, 2024
-
Supression du fonction isfile de fichier main/wapiti.py, et gérer le cas de fichier inexistant au niveau de fichier auth.py.
Configuration menu - View commit details
-
Copy full SHA for 230ac6a - Browse repository at this point
Copy the full SHA 230ac6aView commit details
Commits on Nov 21, 2024
-
Ajout d’une fonction de vérification : Cette fonction calcule le taux de similarité entre la réponse originale et la réponse obtenue après une requête modifiée. Il n’est pas possible de comparer directement le contenu brut des deux réponses car certaines variables dynamiques, comme les tokens (ex. authenticity_token, csrf-token), changent d’une réponse à l’autre.
Configuration menu - View commit details
-
Copy full SHA for 26b9bea - Browse repository at this point
Copy the full SHA 26b9beaView commit details
Commits on Nov 22, 2024
-
L'issue est causé par les fichiers .js contenant des chaines de caractères comme "uid=", ce qui considéré comme une injection réussie de la commande "id". J'ai ajouté 2 fonctions, la première vérifie le content-type des pages, afin de vérifier qu'il est acceptable (en prenant juste les content-type text/html, text/plain, application/json, et application/javascript). La deuxième fonction vérifie l'extension du fichier concerné, ça filtre les fichiers qui peuvent provoquer des faux positifs, comme les .js et .css par exemple. Le module ne détecte aucune vulnérabilités sur les pages qui causent des faux positifs. Fix issue #17.
Configuration menu - View commit details
-
Copy full SHA for 2939e4e - Browse repository at this point
Copy the full SHA 2939e4eView commit details
Commits on Jan 10, 2025
-
Configuration menu - View commit details
-
Copy full SHA for e8ba7eb - Browse repository at this point
Copy the full SHA e8ba7ebView commit details
Commits on Jan 16, 2025
-
Configuration menu - View commit details
-
Copy full SHA for 9e06391 - Browse repository at this point
Copy the full SHA 9e06391View commit details
Commits on Jan 17, 2025
-
Configuration menu - View commit details
-
Copy full SHA for 7f1eb81 - Browse repository at this point
Copy the full SHA 7f1eb81View commit details
Commits on Feb 3, 2025
-
Ajout d'une vérification permettant d'exclure les fichiers images lors du scan, ce qui permet d'éliminer les faux positifs causés par les paramètres des requêtes GET sur les fichiers images
Configuration menu - View commit details
-
Copy full SHA for 73fe568 - Browse repository at this point
Copy the full SHA 73fe568View commit details
Commits on Feb 4, 2025
-
Ajout d'un scan de la vulnérabilité CVE-2024-55591
Modification de module network_devices afin de pouvoir scanner la vulnérabilité CVE-2024-55591
Configuration menu - View commit details
-
Copy full SHA for 07cf26a - Browse repository at this point
Copy the full SHA 07cf26aView commit details
Commits on Feb 13, 2025
-
Amélioration de payloads de module exec
Remplacement de quelques règles par des regex.; Ajout d'une fonction de vérification plus précise.
Configuration menu - View commit details
-
Copy full SHA for c02bd4c - Browse repository at this point
Copy the full SHA c02bd4cView commit details
Commits on Feb 19, 2025
-
Configuration menu - View commit details
-
Copy full SHA for b5150ec - Browse repository at this point
Copy the full SHA b5150ecView commit details -
Remove the need for the asyncio stop Event on attacks, refactor attac…
…k module to a single function that can be cancelled on ctrl+c, use a finally block to persist attacked_ids in case of interruption
Configuration menu - View commit details
-
Copy full SHA for 16ed3cf - Browse repository at this point
Copy the full SHA 16ed3cfView commit details -
Configuration menu - View commit details
-
Copy full SHA for ef8dbd4 - Browse repository at this point
Copy the full SHA ef8dbd4View commit details -
Configuration menu - View commit details
-
Copy full SHA for 9a8dc9c - Browse repository at this point
Copy the full SHA 9a8dc9cView commit details
Commits on Mar 10, 2025
-
Configuration menu - View commit details
-
Copy full SHA for fc3af57 - Browse repository at this point
Copy the full SHA fc3af57View commit details -
Configuration menu - View commit details
-
Copy full SHA for d12d0e2 - Browse repository at this point
Copy the full SHA d12d0e2View commit details
There are no files selected for viewing
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.