Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PRP: Dolibarr ERP fingerprint db and update scripts #333

Open
vishwaraj101 opened this issue Jul 27, 2023 · 12 comments · May be fixed by #390
Open

PRP: Dolibarr ERP fingerprint db and update scripts #333

vishwaraj101 opened this issue Jul 27, 2023 · 12 comments · May be fixed by #390
Assignees
Labels
Contributor main The main issue a contributor is working on (top of the contribution queue). fingerprints PRP:Accepted

Comments

@vishwaraj101
Copy link

This will detect the instances of Dolibarr
Dolibarr is an Open Source ERP & CRM for business for SMEs, Large Companies, Freelancers, Foundations)
It is currently used by 5000+ instances as per shodan query

This will detect the dolibarr version from 6-18.0.0

@vishwaraj101 vishwaraj101 changed the title PRP: Dolibarr fingerprint db and update scripts PRP: Dolibarr ERP fingerprint db and update scripts Jul 27, 2023
@tooryx tooryx added Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. fingerprints PRP:Accepted Contributor main The main issue a contributor is working on (top of the contribution queue). and removed Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. labels Feb 1, 2024
@tooryx
Copy link
Member

tooryx commented Feb 6, 2024

Hi @vishwaraj101,

Thanks for your request! This vulnerability is in scope for the reward program. Please submit our participation form and you can start working on the development.

Please keep in mind that the Tsunami Scanner Team will only be able to work at one issue at a time for each participant so please hold on the implementation work for any other requests you might have.

Thanks!

@vishwaraj101
Copy link
Author

Thanks

@tooryx
Copy link
Member

tooryx commented Feb 13, 2024

Hi @vishwaraj101,

Did you push your changes? I do not see a PR associated with this request.

~tooryx

@vishwaraj101
Copy link
Author

Hi @tooryx I am new to this could you please guide me where to get started to start changing the files ?

@vishwaraj101
Copy link
Author

Hi @tooryx you can point me toward appropriate resource and i will begin implementing this. Let me know

@tooryx
Copy link
Member

tooryx commented Feb 15, 2024

Hi @vishwaraj101,

Please see #134 (comment)

~tooryx

@vishwaraj101
Copy link
Author

hi @tooryx checked 134 comment sorry to bother you again i am still not getting how to properly contribute to the tsunami plugin i mean what i read i understood partially but would appreciate something like step by step process to contribute to

@tooryx
Copy link
Member

tooryx commented Feb 15, 2024

I will try to provide more details when I have a bit more time

@vishwaraj101
Copy link
Author

Hi @tooryx could you please help me unblock on this after this i will be on my own since this is my first time but i do feel tsunami contribution could have been made less complex!

@tooryx
Copy link
Member

tooryx commented Feb 19, 2024

Hi @vishwaraj101,

Here is an example of a fingerprint PR: https://github.com/google/tsunami-security-scanner-plugins/pull/326/files
The most important one if the update.sh that will pull the docker images for the application and generate the fingerprints for it. The .binproto file should be generated by the update.sh for every version in versions.txt

~tooryx

@vishwaraj101
Copy link
Author

vishwaraj101 commented Feb 19, 2024

hi @tooryx the person has customised the update.sh file according to the drupal case it's not straight forward ctrl +c ctrl +v what if the project don't have the docker image then ?

vishwaraj101 added a commit to vishwaraj101/tsunami-security-scanner-plugins that referenced this issue Feb 19, 2024
This will detect the dolibarr version from 6-18.0.0
google#333
@tooryx tooryx linked a pull request Feb 22, 2024 that will close this issue
@tooryx
Copy link
Member

tooryx commented Feb 22, 2024

In case you still have questions on the fingerprint development process, you can also refer to the documentation we have for it: https://github.com/google/tsunami-security-scanner-plugins/blob/master/google/fingerprinters/web/README.md

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor main The main issue a contributor is working on (top of the contribution queue). fingerprints PRP:Accepted
Projects
None yet
2 participants