-
-
Notifications
You must be signed in to change notification settings - Fork 400
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ailtyposquatting #2341
ailtyposquatting #2341
Conversation
api_app/playbooks_manager/migrations/0045_add_ailtyposquatting_free_to_use.py
Outdated
Show resolved
Hide resolved
api_app/playbooks_manager/migrations/0045_add_ailtyposquatting_free_to_use.py
Outdated
Show resolved
Hide resolved
api_app/analyzers_manager/migrations/0091_analyzer_config_ailtyposquatting.py
Outdated
Show resolved
Hide resolved
api_app/analyzers_manager/observable_analyzers/ailtyposquatting.py
Outdated
Show resolved
Hide resolved
…into AILTypoSquatting#1545
is there a way to avoid writing into the disk? I mean, you already get the results back from the functions you call, right? If you set the path to the written to file to None what happens? |
tried that. works now :p |
formatoutput="yara", | ||
pathOutput=None, | ||
) | ||
if self._job.tlp == "CLEAR" and self.dns_resolving: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can you use the enum for the compare? self._job.TLP.CLEAR.value
and dns resolving {self.dns_resolving}""" | ||
) | ||
resultList = [] | ||
response["algorithms"] = runAll( |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
can you please show the results from this? cause "formatoutput"="yara" I don't think it is the right option
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
yeah I mean it does not make sense to me cause I should have expected "Yara" code output. But ok, nevermind, the important thing is that it works. Maybe Yara would be used in the file written to the disk be but we are not generating it.
So, it could make sense to set it as None too to avoid confusion to the next reader
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
says : known format: None. Will use text format instead
committing with text
only.
pathOutput=None, | ||
) | ||
if self._job.tlp == "CLEAR" and self.dns_resolving: | ||
response["dnsResolving"] = dnsResolving( |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
also results from this plz
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
that's a problem cause I would have expected a populated answer. For instance, xx.com
does exist.
The output should be like this: https://github.com/typosquatter/ail-typo-squatting?tab=readme-ov-file#dns-output Can you check the library closely pls?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Figuring out the problem took quite some time. seems to work fine now. It just takes awfully lot of time.
attching a part of the output
{'k-com.xn--ogbpf8fl': {'NotExist': True}, 'k-com.xn--otu796d': {'NotExist': True}, 'k-com.xn--p1acf': {'NotExist': True}, 'k-com.xn--p1ai': {'NotExist': True}, 'k-com.xn--pgbs0dh': {'NotExist': True}, 'k-com.xn--pssy2u': {'NotExist': True}, 'k-com.xn--q7ce6a': {'NotExist': True}, 'k-com.xn--q9jyb4c': {'NotExist': True}, 'k-com.xn--qcka1pmc': {'NotExist': True}, 'k-com.xn--qxa6a': {'NotExist': True}, 'k-com.xn--qxam': {'NotExist': True}, 'k-com.xn--rhqv96g': {'NotExist': True}, 'k-com.xn--rovu88b': {'NotExist': True}, 'k-com.xn--rvc1e0am3e': {'NotExist': True}, 'k-com.xn--s9brj9c': {'NotExist': True}, 'k-com.xn--ses554g': {'NotExist': True}, 'k-com.xn--t60b56a': {'NotExist': True}, 'k-com.xn--tckwe': {'NotExist': True}, 'k-com.xn--tiq49xqyj': {'NotExist': True}, 'k-com.xn--unup4y': {'NotExist': True}, 'k-com.xn--vermgensberater-ctb': {'NotExist': True}, 'k-com.xn--vermgensberatung-pwb': {'NotExist': True}, 'k-com.xn--vhquv': {'NotExist': True}, 'k-com.xn--vuq861b': {'NotExist': True}, 'k-com.xn--w4r85el8fhu5dnra': {'NotExist': True}, 'k-com.xn--w4rs40l': {'NotExist': True}, 'k-com.xn--wgbh1c': {'NotExist': True}, 'k-com.xn--wgbl6a': {'NotExist': True}, 'k-com.xn--xhq521b': {'NotExist': True}, 'k-com.xn--xkc2al3hye2a': {'NotExist': True}, 'k-com.xn--xkc2dl3a5ee0h': {'NotExist': True}, 'k-com.xn--y9a3aq': {'NotExist': True}, 'k-com.xn--yfro4i67o': {'NotExist': True}, 'k-com.xn--ygbi2ammx': {'NotExist': True}, 'k-com.xn--zfr164b': {'NotExist': True}, 'k-com.xxx': {'NotExist': True}, 'k-com.xyz': {'NotExist': True}, 'k-com.yachts': {'NotExist': True}, 'k-com.yahoo': {'NotExist': True}, 'k-com.yamaxun': {'NotExist': True}, 'k-com.yandex': {'NotExist': True}, 'k-com.ye': {'NotExist': True}, 'k-com.yodobashi': {'NotExist': True}, 'k-com.yoga': {'NotExist': True}, 'k-com.yokohama': {'NotExist': True}, 'k-com.you': {'NotExist': True}, 'k-com.youtube': {'NotExist': True}, 'k-com.yt': {'NotExist': True}, 'k-com.yun': {'NotExist': True}, 'k-com.za': {'NotExist': True}, 'k-com.zappos': {'NotExist': True}, 'k-com.zara': {'NotExist': True}, 'k-com.zero': {'NotExist': True}, 'k-com.zip': {'NotExist': True}, 'k-com.zm': {'NotExist': True}, 'k-com.zone': {'NotExist': True}, 'k-com.zuerich': {'NotExist': True}, 'k-com.zw': {'NotExist': True}, 'k-com': {'NotExist': True}}
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
cool man! :)
…into AILTypoSquatting#1545
great! |
closes #1545
Description
Please include a summary of the change and link to the related issue.
Type of change
Please delete options that are not relevant.
Checklist
develop
dumpplugin
command and added it in the project as a data migration. ("How to share a plugin with the community")test_files.zip
and you added the default tests for that mimetype in test_classes.py.FREE_TO_USE_ANALYZERS
playbook by following this guide.url
that contains this information. This is required for Health Checks._monkeypatch()
was used in its class to apply the necessary decorators.MockUpResponse
of the_monkeypatch()
method. This serves us to provide a valid sample for testing.Black
,Flake
,Isort
) gave 0 errors. If you have correctly installed pre-commit, it does these checks and adjustments on your behalf.tests
folder). All the tests (new and old ones) gave 0 errors.DeepSource
,Django Doctors
or other third-party linters have triggered any alerts during the CI checks, I have solved those alerts.Important Rules
"report": {
"addDash": [
"g-oogle.com",
"go-ogle.com",
"goo-gle.com",
"goog-le.com",
"googl-e.com"
],
"omission": [
"oogle.com",
"gogle.com",
"goole.com",
"googe.com",
"googl.com"
],
"subdomain": [
"g.oogle.com",
"go.ogle.com",
"goo.gle.com",
"goog.le.com",
"googl.e.com"
]
},}