Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PRP: Dolibarr ERP fingerprint db and update scripts #333 #390

Open
wants to merge 3 commits into
base: master
Choose a base branch
from

Conversation

vishwaraj101
Copy link

This will detect the dolibarr version from 6-18.0.0 #333

This will detect the dolibarr version from 6-18.0.0
google#333
@vishwaraj101
Copy link
Author

@tooryx i made my first commit do let me know if something is not fine!

@tooryx tooryx linked an issue Feb 22, 2024 that may be closed by this pull request
@tooryx tooryx added Contributor main The main issue a contributor is working on (top of the contribution queue). fingerprints labels Feb 22, 2024
@tooryx
Copy link
Member

tooryx commented Feb 22, 2024

Hi @vishwaraj101,

I will add it to our backlog, but we are slowly processing the backlog, so it might take a while.

~tooryx

@vishwaraj101
Copy link
Author

Hi @vishwaraj101,

I will add it to our backlog, but we are slowly processing the backlog, so it might take a while.

~tooryx

well i can join you guys if you need help from back side i am available that way.

@vishwaraj101
Copy link
Author

Hi @tooryx any update on the progress ?

@tooryx
Copy link
Member

tooryx commented Feb 26, 2024

Hi @vishwaraj101,

Please be patient. As I mentioned, we are slowly processing the backlog. It might take a while.

~tooryx

@leonardo-doyensec
Copy link
Collaborator

Hi @vishwaraj101.
Thank you for your contribution, i'm noticing that you haven't committed the .binproto file.
You can find an example of an already merged fingerprint here

Feel free to reach out
~ Leonardo (Doyensec)

@leonardo-doyensec
Copy link
Collaborator

Hello @vishwaraj101. Friendly ping

@vishwaraj101
Copy link
Author

vishwaraj101 commented Oct 4, 2024 via email

@tooryx
Copy link
Member

tooryx commented Oct 22, 2024

Hi @vishwaraj101,

Sorry that it feels so complicated. What would be your suggestions to make it simpler and still integrate fully with Tsunami?
Does that mean that you do not wish to continue with this PR?

~tooryx

@vishwaraj101
Copy link
Author

vishwaraj101 commented Oct 22, 2024 via email

@tooryx
Copy link
Member

tooryx commented Oct 22, 2024

Could you point me to an example plugin from nuclei that performs fingerprinting (and not vulnerability detection) and that would be an example of what you have in mind?

~tooryx

@vishwaraj101
Copy link
Author

vishwaraj101 commented Oct 22, 2024 via email

@tooryx
Copy link
Member

tooryx commented Oct 22, 2024

But in that example, the server is advertising its version and is located at the base of the rootdir. How would that work for fingerprinting an app that is not at the rootdir or does not advertising its version? In Tsunami, we want to be able to identify (at least, as best as possible) the running version.

This would represent a massive overall of the fingerprinting system. I am going to bring this to the rest of the team, but this seems unlikely, at the moment, that we prioritize this over other work we are doing to improve Tsunami.

In the case of that specific PR, you already did 80% of the work and you need to run your update.sh script in the right environment. If it happens to be complicated, please let me know what is blocking you and I can update the documentation so that it is more straightforward or guided.

~tooryx

@vishwaraj101
Copy link
Author

vishwaraj101 commented Oct 22, 2024 via email

@vishwaraj101
Copy link
Author

vishwaraj101 commented Oct 23, 2024 via email

@tooryx
Copy link
Member

tooryx commented Oct 23, 2024

Hi @vishwaraj101,

I will not do a video, but I will try to update the documentation. That being said, it will take a while.

~tooryx

@vishwaraj101
Copy link
Author

vishwaraj101 commented Oct 24, 2024 via email

@vishwaraj101
Copy link
Author

vishwaraj101 commented Oct 26, 2024 via email

@tooryx
Copy link
Member

tooryx commented Oct 28, 2024

Hi @vishwaraj101,

It will probably take some time before I can write the documentation.

~tooryx

@vishwaraj101
Copy link
Author

vishwaraj101 commented Nov 20, 2024 via email

@tooryx
Copy link
Member

tooryx commented Nov 21, 2024

Hi @vishwaraj101,

As long as the quality of the plugin that we receive for review does not decline, you can use whichever tool you have at your disposal.

~tooryx

@vishwaraj101
Copy link
Author

vishwaraj101 commented Nov 21, 2024 via email

@tooryx
Copy link
Member

tooryx commented Nov 21, 2024

This is currently not planned, no.

~tooryx

@vishwaraj101
Copy link
Author

vishwaraj101 commented Nov 21, 2024 via email

@tooryx
Copy link
Member

tooryx commented Nov 21, 2024

I still did not have time to work on this, sorry.
I'll let you know.

~tooryx

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor main The main issue a contributor is working on (top of the contribution queue). fingerprints
Projects
None yet
Development

Successfully merging this pull request may close these issues.

PRP: Dolibarr ERP fingerprint db and update scripts
3 participants