diff --git a/CHANGELOG/3.6/Fix_encoding.md b/CHANGELOG/3.6/Fix_encoding.md deleted file mode 100644 index 057ca206856..00000000000 --- a/CHANGELOG/3.6/Fix_encoding.md +++ /dev/null @@ -1 +0,0 @@ -Faraday's database will be created using UTF -8 encoding diff --git a/CHANGELOG/3.6/active_and_readonly.md b/CHANGELOG/3.6/active_and_readonly.md deleted file mode 100644 index ed57ed707e1..00000000000 --- a/CHANGELOG/3.6/active_and_readonly.md +++ /dev/null @@ -1 +0,0 @@ -Readonly and disabled workspaces \ No newline at end of file diff --git a/CHANGELOG/3.6/acunetix_plugin_bug.md b/CHANGELOG/3.6/acunetix_plugin_bug.md deleted file mode 100644 index c3fdd5a84eb..00000000000 --- a/CHANGELOG/3.6/acunetix_plugin_bug.md +++ /dev/null @@ -1 +0,0 @@ -Fix bug when parsing URLs in Acunetix reports \ No newline at end of file diff --git a/CHANGELOG/3.6/add_dashboard_pagination.md b/CHANGELOG/3.6/add_dashboard_pagination.md deleted file mode 100644 index 9900819ad54..00000000000 --- a/CHANGELOG/3.6/add_dashboard_pagination.md +++ /dev/null @@ -1 +0,0 @@ -Add pagination in 'Command history', 'Last Vulnerabilities', 'Activity logs' into dashboard \ No newline at end of file diff --git a/CHANGELOG/3.6/add_fields_to_vuln_template.md b/CHANGELOG/3.6/add_fields_to_vuln_template.md deleted file mode 100644 index 4ef56a24a68..00000000000 --- a/CHANGELOG/3.6/add_fields_to_vuln_template.md +++ /dev/null @@ -1 +0,0 @@ -Add fields 'impact', 'easeofresolution' and 'policyviolations' to vulnerability_template \ No newline at end of file diff --git a/CHANGELOG/3.6/add_gitlab_ci_yml.md b/CHANGELOG/3.6/add_gitlab_ci_yml.md deleted file mode 100644 index 02a803c1e8a..00000000000 --- a/CHANGELOG/3.6/add_gitlab_ci_yml.md +++ /dev/null @@ -1 +0,0 @@ -Add gitlab-ci.yml file to execute test and pylint on gitlab runner diff --git a/CHANGELOG/3.6/add_status_code.md b/CHANGELOG/3.6/add_status_code.md deleted file mode 100644 index 3a35e35b6e2..00000000000 --- a/CHANGELOG/3.6/add_status_code.md +++ /dev/null @@ -1 +0,0 @@ -Added status_code field to web vulnerability \ No newline at end of file diff --git a/CHANGELOG/3.6/attachment_api_invalid_vuln_id.md b/CHANGELOG/3.6/attachment_api_invalid_vuln_id.md deleted file mode 100644 index 63b6215e7f6..00000000000 --- a/CHANGELOG/3.6/attachment_api_invalid_vuln_id.md +++ /dev/null @@ -1 +0,0 @@ -Fix bug when non-numeric vulnerability IDs were passes to the attachments API diff --git a/CHANGELOG/3.6/attachments_csrf_vuln.md b/CHANGELOG/3.6/attachments_csrf_vuln.md deleted file mode 100644 index a5352dc0557..00000000000 --- a/CHANGELOG/3.6/attachments_csrf_vuln.md +++ /dev/null @@ -1,4 +0,0 @@ -Fix CSRF (Cross-Site Request Forgery) vulnerability in vulnerability attachments API. -This allowed an attacker to upload evidence to vulns. He/she required to know the -desired workspace name and vulnerability id so it complicated the things a bit. We -classified this vuln as a low impact one. diff --git a/CHANGELOG/3.6/bug_lynis_plugin.md b/CHANGELOG/3.6/bug_lynis_plugin.md deleted file mode 100644 index b0c5ac4e9f4..00000000000 --- a/CHANGELOG/3.6/bug_lynis_plugin.md +++ /dev/null @@ -1 +0,0 @@ -Improve service's parser for Lynis plugin diff --git a/CHANGELOG/3.6/date.md b/CHANGELOG/3.6/date.md new file mode 100644 index 00000000000..239037a7164 --- /dev/null +++ b/CHANGELOG/3.6/date.md @@ -0,0 +1 @@ +Feb 21th, 2019 diff --git a/CHANGELOG/3.6/delete_ipdb.md b/CHANGELOG/3.6/delete_ipdb.md deleted file mode 100644 index 756baf8849e..00000000000 --- a/CHANGELOG/3.6/delete_ipdb.md +++ /dev/null @@ -1 +0,0 @@ -Deleted ipdb in bin/import_csv.py diff --git a/CHANGELOG/3.6/dynamic_vars_in_searcher.md b/CHANGELOG/3.6/dynamic_vars_in_searcher.md deleted file mode 100644 index c8f33fbb787..00000000000 --- a/CHANGELOG/3.6/dynamic_vars_in_searcher.md +++ /dev/null @@ -1 +0,0 @@ -Added ability to 'Searcher' to execute rules in loop with dynamic variables \ No newline at end of file diff --git a/CHANGELOG/3.6/extra_config_in_server_ini.md b/CHANGELOG/3.6/extra_config_in_server_ini.md deleted file mode 100644 index afe54f6d73a..00000000000 --- a/CHANGELOG/3.6/extra_config_in_server_ini.md +++ /dev/null @@ -1 +0,0 @@ -Fix loading in server.ini with extra configs diff --git a/CHANGELOG/3.6/fix_bug_initdb.md b/CHANGELOG/3.6/fix_bug_initdb.md deleted file mode 100644 index 25293f61d96..00000000000 --- a/CHANGELOG/3.6/fix_bug_initdb.md +++ /dev/null @@ -1 +0,0 @@ -bug fix on initdb. Added missing column in insert statement when the admin user is created. diff --git a/CHANGELOG/3.6/fix_duplicate_custom_fields.md b/CHANGELOG/3.6/fix_duplicate_custom_fields.md deleted file mode 100644 index 7f67a17e301..00000000000 --- a/CHANGELOG/3.6/fix_duplicate_custom_fields.md +++ /dev/null @@ -1 +0,0 @@ -Fix duplicate custom fields creation diff --git a/CHANGELOG/3.6/fix_nessus_plugin_host_issue.md b/CHANGELOG/3.6/fix_nessus_plugin_host_issue.md deleted file mode 100644 index 84fc0088ddd..00000000000 --- a/CHANGELOG/3.6/fix_nessus_plugin_host_issue.md +++ /dev/null @@ -1 +0,0 @@ -Fix bug in nessus plugin. It was trying to create a host without IP. Enabled logs on the server for plugin processing (use --debug) diff --git a/CHANGELOG/3.6/fix_search_exploits_logic.md b/CHANGELOG/3.6/fix_search_exploits_logic.md deleted file mode 100644 index 037b59551c7..00000000000 --- a/CHANGELOG/3.6/fix_search_exploits_logic.md +++ /dev/null @@ -1 +0,0 @@ -Fix logic in search exploits diff --git a/CHANGELOG/3.6/fix_sqlmap.md b/CHANGELOG/3.6/fix_sqlmap.md deleted file mode 100644 index 05c5556bea1..00000000000 --- a/CHANGELOG/3.6/fix_sqlmap.md +++ /dev/null @@ -1 +0,0 @@ -Fix SQLMap plugin to support newer versions of the tool diff --git a/CHANGELOG/3.6/fix_ws_loop.md b/CHANGELOG/3.6/fix_ws_loop.md deleted file mode 100644 index 3def0838185..00000000000 --- a/CHANGELOG/3.6/fix_ws_loop.md +++ /dev/null @@ -1 +0,0 @@ -Fix bug of "selec a different workspace" from an empty list loop. diff --git a/CHANGELOG/3.6/keep_selected_vulns.md b/CHANGELOG/3.6/keep_selected_vulns.md deleted file mode 100644 index b7d0748c107..00000000000 --- a/CHANGELOG/3.6/keep_selected_vulns.md +++ /dev/null @@ -1 +0,0 @@ -Preserve selection after bulk edition of vulnerabilities in the Web UI diff --git a/CHANGELOG/3.6/name_not_consistent.md b/CHANGELOG/3.6/name_not_consistent.md deleted file mode 100644 index d25a6715401..00000000000 --- a/CHANGELOG/3.6/name_not_consistent.md +++ /dev/null @@ -1 +0,0 @@ -The command createsupersuper of the manage.py was not consistent wiht the other commands, name changed to create-superuser \ No newline at end of file diff --git a/CHANGELOG/3.6/nessus_hostnames_bug.md b/CHANGELOG/3.6/nessus_hostnames_bug.md deleted file mode 100644 index 193c1b949fd..00000000000 --- a/CHANGELOG/3.6/nessus_hostnames_bug.md +++ /dev/null @@ -1 +0,0 @@ -Fixed Nessus hostnames bug diff --git a/CHANGELOG/3.6/send_searcher_alert_with_custom_mail.md b/CHANGELOG/3.6/send_searcher_alert_with_custom_mail.md deleted file mode 100644 index 34b5e7c198b..00000000000 --- a/CHANGELOG/3.6/send_searcher_alert_with_custom_mail.md +++ /dev/null @@ -1 +0,0 @@ -Send searcher alert with custom mail \ No newline at end of file diff --git a/CHANGELOG/3.6/sslyze_automatic_detection.md b/CHANGELOG/3.6/sslyze_automatic_detection.md deleted file mode 100644 index ee943963421..00000000000 --- a/CHANGELOG/3.6/sslyze_automatic_detection.md +++ /dev/null @@ -1 +0,0 @@ -Add SSLyze automatic detection for the WebUI diff --git a/CHANGELOG/3.6/summary_issuetracker_readonly.md b/CHANGELOG/3.6/summary_issuetracker_readonly.md deleted file mode 100644 index fa27c55f90e..00000000000 --- a/CHANGELOG/3.6/summary_issuetracker_readonly.md +++ /dev/null @@ -1 +0,0 @@ -Fix 500 error when updating services and vulns with specific read-only parameters set diff --git a/CHANGELOG/3.6/update_dnsmap_plugin.md b/CHANGELOG/3.6/update_dnsmap_plugin.md deleted file mode 100644 index 5ed3f224281..00000000000 --- a/CHANGELOG/3.6/update_dnsmap_plugin.md +++ /dev/null @@ -1 +0,0 @@ -Update Dnsmap Plugin diff --git a/CHANGELOG/3.6/updated_NetSparker.md b/CHANGELOG/3.6/updated_NetSparker.md deleted file mode 100644 index 1e8fb26624e..00000000000 --- a/CHANGELOG/3.6/updated_NetSparker.md +++ /dev/null @@ -1 +0,0 @@ -Fix and updated NetSparker Plugin diff --git a/CHANGELOG/3.6/white.md b/CHANGELOG/3.6/white.md new file mode 100644 index 00000000000..b9fa74047c6 --- /dev/null +++ b/CHANGELOG/3.6/white.md @@ -0,0 +1,30 @@ + * Fix CSRF (Cross-Site Request Forgery) vulnerability in vulnerability attachments API. + This allowed an attacker to upload evidence to vulns. He/she required to know the + desired workspace name and vulnerability id so it complicated the things a bit. We + classified this vuln as a low impact one. + * Readonly and disabled workspaces + * Add fields 'impact', 'easeofresolution' and 'policyviolations' to vulnerability_template + * Add pagination in 'Command history', 'Last Vulnerabilities', 'Activity logs' into dashboard + * Add status_code field to web vulnerability + * Preserve selection after bulk edition of vulnerabilities in the Web UI + * Faraday's database will be created using UTF-8 encoding + * Fix bug of "select a different workspace" from an empty list loop. + * Fix bug when creating duplicate custom fields + * Fix bug when loading in server.ini with extra configs + * Fix `./manage.py command`. It wasn't working since the last schema migration + * `./manage.py createsuperuser` command renamed to `./manage.py create-superuser` + * Fix bug when non-numeric vulnerability IDs were passed to the attachments API + * Fix logic in search exploits + * Add ability to 'Searcher' to execute rules in loop with dynamic variables + * Send searcher alert with custom mail + * Add gitlab-ci.yml file to execute test and pylint on gitlab runner + * Fix 500 error when updating services and vulns with specific read-only parameters set + + * Fix SQLMap plugin to support newer versions of the tool + * Improve service's parser for Lynis plugin + * Fix bug when parsing URLs in Acunetix reports + * Fix and update NetSparker Plugin + * Fix bug in nessus plugin. It was trying to create a host without IP. Enabled logs on the server for plugin processing (use --debug) + * Fix bug when parsing hostnames in Nessus reports + * Fix SSLyze report automatic detection, so reports can be imported from the web ui + * Update Dnsmap Plugin diff --git a/CHANGELOG/RELEASE.md b/CHANGELOG/RELEASE.md index ca1814557d7..b40909c745f 100644 --- a/CHANGELOG/RELEASE.md +++ b/CHANGELOG/RELEASE.md @@ -9,6 +9,39 @@ New features in the latest update ===================================== +3.6 [Feb 21th, 2019]: +--- + * Fix CSRF (Cross-Site Request Forgery) vulnerability in vulnerability attachments API. + This allowed an attacker to upload evidence to vulns. He/she required to know the + desired workspace name and vulnerability id so it complicated the things a bit. We + classified this vuln as a low impact one. + * Readonly and disabled workspaces + * Add fields 'impact', 'easeofresolution' and 'policyviolations' to vulnerability_template + * Add pagination in 'Command history', 'Last Vulnerabilities', 'Activity logs' into dashboard + * Add status_code field to web vulnerability + * Preserve selection after bulk edition of vulnerabilities in the Web UI + * Faraday's database will be created using UTF-8 encoding + * Fix bug of "select a different workspace" from an empty list loop. + * Fix bug when creating duplicate custom fields + * Fix bug when loading in server.ini with extra configs + * Fix `./manage.py command`. It wasn't working since the last schema migration + * `./manage.py createsuperuser` command renamed to `./manage.py create-superuser` + * Fix bug when non-numeric vulnerability IDs were passed to the attachments API + * Fix logic in search exploits + * Add ability to 'Searcher' to execute rules in loop with dynamic variables + * Send searcher alert with custom mail + * Add gitlab-ci.yml file to execute test and pylint on gitlab runner + * Fix 500 error when updating services and vulns with specific read-only parameters set + + * Fix SQLMap plugin to support newer versions of the tool + * Improve service's parser for Lynis plugin + * Fix bug when parsing URLs in Acunetix reports + * Fix and update NetSparker Plugin + * Fix bug in nessus plugin. It was trying to create a host without IP. Enabled logs on the server for plugin processing (use --debug) + * Fix bug when parsing hostnames in Nessus reports + * Fix SSLyze report automatic detection, so reports can be imported from the web ui + * Update Dnsmap Plugin + 3.5 [Jan 16th, 2019]: --- * Redesgin of new/edit vulnerability forms diff --git a/RELEASE.md b/RELEASE.md index ca1814557d7..b40909c745f 100644 --- a/RELEASE.md +++ b/RELEASE.md @@ -9,6 +9,39 @@ New features in the latest update ===================================== +3.6 [Feb 21th, 2019]: +--- + * Fix CSRF (Cross-Site Request Forgery) vulnerability in vulnerability attachments API. + This allowed an attacker to upload evidence to vulns. He/she required to know the + desired workspace name and vulnerability id so it complicated the things a bit. We + classified this vuln as a low impact one. + * Readonly and disabled workspaces + * Add fields 'impact', 'easeofresolution' and 'policyviolations' to vulnerability_template + * Add pagination in 'Command history', 'Last Vulnerabilities', 'Activity logs' into dashboard + * Add status_code field to web vulnerability + * Preserve selection after bulk edition of vulnerabilities in the Web UI + * Faraday's database will be created using UTF-8 encoding + * Fix bug of "select a different workspace" from an empty list loop. + * Fix bug when creating duplicate custom fields + * Fix bug when loading in server.ini with extra configs + * Fix `./manage.py command`. It wasn't working since the last schema migration + * `./manage.py createsuperuser` command renamed to `./manage.py create-superuser` + * Fix bug when non-numeric vulnerability IDs were passed to the attachments API + * Fix logic in search exploits + * Add ability to 'Searcher' to execute rules in loop with dynamic variables + * Send searcher alert with custom mail + * Add gitlab-ci.yml file to execute test and pylint on gitlab runner + * Fix 500 error when updating services and vulns with specific read-only parameters set + + * Fix SQLMap plugin to support newer versions of the tool + * Improve service's parser for Lynis plugin + * Fix bug when parsing URLs in Acunetix reports + * Fix and update NetSparker Plugin + * Fix bug in nessus plugin. It was trying to create a host without IP. Enabled logs on the server for plugin processing (use --debug) + * Fix bug when parsing hostnames in Nessus reports + * Fix SSLyze report automatic detection, so reports can be imported from the web ui + * Update Dnsmap Plugin + 3.5 [Jan 16th, 2019]: --- * Redesgin of new/edit vulnerability forms