prithvee07/WebDockerpentest

★ 0Forks 0PythonGitHub ↗Compare

README

WebPentest v1 MVP - Containerized Penetration Testing Framework

Status: Phase 1 (Reconnaissance) - Development
Version: 1.0.0-alpha
Target Users: Penetration Testers, Security Engineers, Security Researchers


Overview

WebPentest is a containerized web application penetration testing orchestration platform. v1 MVP focuses on Phase 1: Reconnaissance using Nmap for network discovery and port scanning.

Key Features

  • ✅ Self-contained Docker Compose deployment
  • ✅ Multi-interface access (CLI, REST API)
  • ✅ Secure authentication (API keys + simple login)
  • ✅ Full audit logging (immutable)
  • ✅ PostgreSQL persistence with backups
  • ✅ Zero-vulnerability hardening

Future Phases

  • 🔄 Phase 2: Scanning (Burp Suite, OWASP ZAP)
  • 🔄 Phase 3: Exploitation (Metasploit, SQLMap)
  • 🔄 Phase 4: Reporting (Advanced reports, integrations)

Quick Start

Prerequisites

  • Docker & Docker Compose (v3.8+)
  • Linux/macOS (or WSL on Windows)
  • 2GB+ RAM available

Setup (5 minutes)

# 1. Clone repository
git clone <repo> webpentest
cd webpentest

# 2. Generate secrets
make setup

# 3. Build images
make build

# 4. Start services
make up

# 5. Verify health
curl http://localhost:8000/health

First Pentest

# Create admin user (via orchestrator container)
docker-compose exec orchestrator python scripts/create_user.py admin yourpassword

# Start a pentest
curl -X POST http://localhost:8000/pentest/start \
  -H "Content-Type: application/json" \
  -H "X-API-Key: your-api-key" \
  -d '{"target": "example.com"}'

# Check status
curl http://localhost:8000/pentest/1/status \
  -H "X-API-Key: your-api-key"

# Get results
curl http://localhost:8000/pentest/1/results \
  -H "X-API-Key: your-api-key"

Architecture

Components

  1. Orchestrator Service — Central coordinator (Python + FastAPI)
  2. API Server — REST endpoints for users
  3. PostgreSQL — Data persistence
  4. Tool Containers — Isolated Nmap (v1), future tools

Data Flow

User (CLI/API)
    ↓
REST API Server
    ↓
Orchestrator Service
    ↓
Tool Container (Nmap)
    ↓
PostgreSQL Database
    ↓
Results (JSON, HTML, Reports)

Usage

Docker Compose Commands

make up              # Start all services
make down            # Stop all services
make logs            # View orchestrator logs
make test            # Run test suite
make lint            # Run security checks
make clean           # Clean everything
make setup           # Generate secrets
make shell           # Open shell in orchestrator
make health          # Check service health

API Endpoints (v1 MVP)

Method Endpoint Description
POST /auth/login Authenticate user (TODO)
POST /pentest/start Start reconnaissance scan
GET /pentest/{id}/status Get job status
GET /pentest/{id}/results Retrieve results (JSON)
GET /pentest/{id}/report Generate report (HTML)
GET /audit-logs View audit trail
GET /health Health check

Configuration

Environment Variables (.env)

# Database
DB_PASSWORD=<strong-password>

# API
API_KEY_SECRET=<strong-secret>

# Logging
LOG_LEVEL=INFO

# Nmap
NMAP_TIMEOUT=3600

# Python
PYTHONUNBUFFERED=1

Generate Secrets

# Option 1: Using make
make setup

# Option 2: Manual
DB_PASSWORD=$(openssl rand -base64 32)
API_KEY_SECRET=$(openssl rand -base64 32)
echo "DB_PASSWORD=$DB_PASSWORD" > .env
echo "API_KEY_SECRET=$API_KEY_SECRET" >> .env

Security

Zero-Tolerance Hardening

  • ✅ No hardcoded secrets
  • ✅ All SQL queries parameterized
  • ✅ All command arguments escaped
  • ✅ Containers run as non-root
  • ✅ API keys hashed (bcrypt)
  • ✅ Audit logs immutable
  • ✅ Security scanning (Bandit, pip-audit)

Security Checklist

# Run security checks
make security

# Specific checks
bandit -r orchestrator/app/
pip-audit

Development

Project Structure

webpentest/
├── orchestrator/          # Main service
│   ├── app/
│   │   ├── models.py
│   │   ├── database.py    # (TODO)
│   │   ├── api.py         # (TODO)
│   │   └── ...
│   ├── tests/
│   ├── scripts/
│   ├── Dockerfile
│   └── requirements.txt
├── cli/                   # Command-line interface (TODO)
├── .claude/
│   ├── DESIGN.md          # Architecture & design
│   ├── TASKS.md           # Implementation tasks
│   └── CHECKLIST.md       # Pre-launch verification
├── docker-compose.yml
├── init.sql
├── .env.example
└── Makefile

Testing

# Run all tests
make test

# Run specific test
pytest orchestrator/tests/test_health.py -v

# Coverage report
pytest --cov=orchestrator/app orchestrator/tests/

Code Quality

# Format code
make format

# Lint
make lint

# Security scan
make security

Troubleshooting

Services Won't Start

# Check logs
make logs
make logs-db

# Verify health
make health

# Rebuild images
make build

Database Issues

# Reset database
docker-compose down -v
make up

# Connect to database
make shell-db

# Backup database
make backup-db

# Restore database
make restore-db

Port Already in Use

Change port in docker-compose.yml:

orchestrator:
  ports:
    - "9000:8000"  # Changed from 8000:8000

Documentation


Roadmap

v1 (Current)

  • ✅ Phase 1: Reconnaissance (Nmap)
  • ✅ CLI + API interfaces
  • ✅ PostgreSQL persistence
  • ✅ Audit logging
  • ✅ Security hardening

v2 (Planned)

  • 🔄 Phase 2: Scanning (Burp, ZAP)
  • 🔄 Phase 3: Exploitation (Metasploit, SQLMap)
  • 🔄 Web dashboard (React)
  • 🔄 DefectDojo integration

v3+ (Future)

  • 🔄 Phase 4: Reporting (Advanced)
  • 🔄 Cloud deployment (AWS, GCP, Azure)
  • 🔄 Horizontal scaling
  • 🔄 Multi-tenant support

Contributing

See .claude/TASKS.md for implementation tasks and contribution guidelines.


Security Considerations

⚠️ v1 is designed for internal use only.

  • Keep .env file secure (never commit to git)
  • Use strong passwords (32+ chars)
  • Run on trusted networks
  • Regularly update Docker images
  • Monitor audit logs

License

[To be determined]


Support

For issues, questions, or contributions:


Version: 1.0.0-alpha
Last Updated: 2026-06-18
Status: Phase 1 Foundation (In Development)

Contributors

prithvee07

Issues