Ghostwriter v3.0.3
·
3807 commits
to master
since this release
Summary
This release includes changes from the unreleased v3.0.1 and v3.0.2 hotfix releases. Changes address some small issues reported by users, improvements to the GraphQL API to support mythic_sync v2 and other external projects, and quality of life improvements.
CHANGELOG
[3.0.3] - 5 August 2022
Added
- Added the
CSRF_TRUSTED_ORIGINSto the base configuration to make it easier to add trusted origins for accessing Ghostwriter via a web proxy - Oplog ID now appears at the top of the log entries view for easier identification
- Committed Ghostwriter CLI binaries (v0.2.2) for Windows, macOS, and Linux
- Added project notes to the serialized report data as a list under
project.notes(Closes #210)
Fixed
- Fixed "Stand by" message appearing for all users viewing a report when one user generates a report
- Fixed domain expiration dates not sorting properly in the domain table when date format is changed
- Fixed operation log entries not loading if null values were present from GraphQL submissions
- Fixed
completefield being required for reported findings but unavailable in the GraphQL schema (Fixes #226) - Fixed log entry tables not showing "No entries to display" row when no entries are available
- Fixed an issue that could cause an error when making a new activity log with a name longer than 50 characters
- Fixed minor issue that could prevent PowerPoint generation if multiple evidence images were stacked on top of each other inside a list
- Removed duplicate toast message displayed after the successful creation of a new oplog
- Fixed GraphQL configuration that could cause webhook authentication to fail
- Fixed server error when trying to view entries for an oplog that does not exist
Changed
- Set defaults on some fields to make it easier to insert new domains, objectives, and findings via GraphQL
- New domains will now default to WHOIS enabled, healthy, and available
- Objectives will now default to primary priority and position one (top of the list)
- Reported findings will now insert into position one (top of the list for its severity category)
- Log entry fields can now be null to make it easier to insert new entries via GraphQL
- Improved log entry view to make it easier to view logs
- Users with the
managerrole can now update and delete protected report templates - User accounts can now be filtered by role in the admin panel
- Removed GraphQL
operatorNamefield preset to allow this value to be set by the user - Groups are now hidden on the user profile unless a user is part of a group
- Adjusted client and project dashboards for better display of information and controls
- Display of client's timezone has been changed to display the client's current date and time with the abbreviated timezone name
- API keys now start with an initial expiry date that is +1 day from the current date
- Project descriptions are now truncated after 35 words to make lengthy descriptions more readable in some sections of the UI
- Infrastructure notes under the project dashboard are now inside collapsible sections for easier reading
- Upgraded Ghostwriter CLI binaries to v0.2.3