GithubHelp home page GithubHelp logo

w-digital-scanner / w12scan Goto Github PK

View Code? Open in Web Editor NEW
1.3K 1.3K 359.0 14.7 MB

🚀 A simple asset discovery engine for cybersecurity. (网络资产发现引擎)

License: MIT License

Python 6.23% HTML 8.32% CSS 83.90% JavaScript 1.41% Dockerfile 0.10% Shell 0.04%

w12scan's People

Contributors

boy-hack avatar hack2012 avatar oliverklee avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

w12scan's Issues

搜索不到

docker下安装成功了,为何搜索不到?

docker运行错误

ERROR: Service 'web' failed to build: OCI runtime create failed: container_linux.go:344: starting container process caused "process_linux.go:293: copying bootstrap data to pipe caused "write init-p: broken pipe"": unknown

添加多个目标,http连接就会报错

报错:
Max retries exceeded with url: / (Caused by ConnectTimeoutError(<urllib3.connection.HTTPConnection object at 0x7f702037e7f0>, 'Connection to timed out. (connect timeout=30)'))"
这不是因为http连接太多没有关闭导致的吗、

用户登录与搜索API

  • 用户登录界面
  • 结构化:新建user app
    • dockerfile自动添加任务
  • 用户设置、退出 路由,功能,模板
  • 搜索API
  • 搜索API与用户token对接

怎么实现分布式部署?

大牛你好,请问下分布式部署要怎么配置?我想要多部署几个client节点,在web端运行节点那一栏一直是空的,看不到运行节点的状态。

初始化es表失败

想自己改下代码,再本地搭建了环境

到这一步的时候,失败了
image
image
一直这样子
这是啥原因

在win10使用docker部署启动失败

我按照文档中描述的启动失败了
`λ docker-compose up -d
Building web
Step 1/10 : FROM alpine:edge
---> 70997d35b3ed
Step 2/10 : MAINTAINER [email protected]
---> Using cache
---> b19d99808266
Step 3/10 : RUN sed -i 's/dl-cdn.alpinelinux.org/mirrors.ustc.edu.cn/g' /etc/apk/repositories
---> Using cache
---> 2c58dec142e6
Step 4/10 : RUN set -x && apk update && apk add python3-dev && apk add bash && apk add tzdata && apk add gcc && apk add gettext
&& apk add libc-dev && apk add linux-headers && apk add nginx && cp -r -f /usr/share/zoneinfo/Hongkong /etc/localtime && mkdir -p /opt/w12scan && mkdir -p /run/nginx
---> Running in d567f0b1a838

帮忙解决一下,谢谢啦

django DEBUG模式

目前使用的是django debug模式,实际线上部署发现此模式问题很多。

  1. nginx gunicorn 部署 ok
  2. 精简web端 js的大小 ok
  3. 漏洞统计优化 ok
  4. 资产管理关联页面优化 ok

没办法运行

按照github文档 启动后:
image
但是访问8000端口直接拒绝连接!不知道是哪里的问题!

语言切换是不是没有开发好?

昨天测试还是中文的,今天重新装了一下,就是英文了。
兄弟,能不能先服务好**用户再考虑国外的?
先把bug处理处理再说嘛。。比如说资产ip过大的时候报错的bug

docker启动,8000端口拒绝访问日志

docker启动,8000端口拒绝访问日志如下:

processing file django.po in /opt/w12scan/locale/zh_Hans/LC_MESSAGES
processing file django.po in /opt/w12scan/locale/en/LC_MESSAGES
[2019-08-15 18:26:19 +0800] [15] [INFO] Starting gunicorn 19.9.0
[2019-08-15 18:26:19 +0800] [15] [INFO] Listening at: http://127.0.0.1:8080 (15)
[2019-08-15 18:26:19 +0800] [15] [INFO] Using worker: sync
[2019-08-15 18:26:19 +0800] [18] [INFO] Booting worker with pid: 18
add user boyhack faild UNIQUE constraint failed: user_userinfo.name
nginx: [emerg] socket() [::]:80 failed (97: Address family not supported by protocol)

创建任务后没有反应

创建任务后从上午9点到下午3点没有扫描的迹象 一直保持图中的状态 这是为什么?
QQ截图20190321143905

扫描结果

扫描结果域名+IP的和实际大于255的话, 只显示255个(域名和IP的和),是否有这个限制?

关于搜索总是0的问题

大佬你好 关于搜索总是0的问题 直接搜索总是为0
image
创建资产后搜索还为0 不知什么原因 elastic运行正常 我的内存16G的
image
第二个问题就是 拜读了您的在线部署 但我修改配置文件后 站点就无法访问了 求您解答 谢谢
image

docker 启动 static文件 403 无权访问

该项目根目录 static 文件在 docker 容器中默认权限为 700,python 无权访问 static,导致 css 等静态资源无法访问。

临时解决方案:

docker exec -ti w12scan-master_web_1 bash    # 进入容器
chmod -R 777 ./static/    # 修改 static 权限

部署docker报错

ERROR: Service 'web' failed to build: The command '/bin/sh -c set -x && apk update && apk add python3-dev && apk add bash && apk add tzdata && apk add gcc && apk add libc-dev && apk add linux-headers && apk add nginx && cp -r -f /usr/share/zoneinfo/Hongkong /etc/localtime && mkdir -p /opt/w12scan && mkdir -p /run/nginx' returned a non-zero code: 137

reids 内存占用问题

因为redis是内存数据库,数据大多存入了内存,当扫描数据多了之后数据内存就被塞满了,需要程序自动判断释放数据

资产过多,在查看时会报错

像这样:
图片

删除重新部署了几次仍然存在同样的问题。
经过测试,在新建资产那里添加过多域名(1400+)会出现这样的问题,域名少的时候正常。

关于启动失败的问题

git clone https://github.com/boy-hack/w12scan
cd w12scan
docker-compose up -d

根据以上命令部署时,docker启动的时候爆下面的错误

ERROR: Version in "./docker-compose.yml" is unsupported. You might be seeing this error because you're using the wrong Compose file version. Either specify a version of "2" (or "2.0") and place your service definitions under the `services` key, or omit the `version` key and place your service definitions at the root of the file to use version 1.

将docker-compose.yml中的dockerversion改为2之后可以正常启动,但是访问访问为503.

同毕业设计哈哈哈


好开心
跟大佬想到了一起··
不过我的还不晓得咋写,
感谢大佬开源,让我有个参考!

漏洞扫描怎么实现?

请问怎么实现漏洞扫描?我看仓库中展示里有漏洞情况,我在本地搭建好的,找不到能做漏洞扫描的地方呀。

自己搭建的es

w12scan-master/pipeline/elastic.py
PUT http://127.0.0.1:9200/w12scan/_mapping/domains [status:400 request:0.006s]
elasticsearch.exceptions.RequestError: RequestError(400, 'illegal_argument_exception', 'Rejecting mapping update to [w12scan] as the final mapping would have more than 1 type: [domains, ips]')

用户自定义打tag支持

将漏洞威胁,相关组件转化为tag的方式,支持通过tag进行搜索,支持用户自定义tag(标记IP)

关于部署环境的问题

我在本地可以正常搭建这个系统框架,但是在vps是无法搭建成功的。Why? 难道只支持本地搭建的吗?

部署docker错误

我用的centos7.5安装docker,安装上之后,无法运行docker-compose up -d命令,这个是版本的问题还是我安装的问题????
第二次成功执行docker-compose up -d命令之后
卡在如下页面
image
image

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.