-
Notifications
You must be signed in to change notification settings - Fork 3
CLI
The command line has a help command who describe all commands available and theirs associated flags (global or command specific).
Global flags can configure where to find the components configuration with the flag : --config my/path/to/config
or where to find the database with the flag : --database my/path/to/sqlite.db
NAME:
Vulnerobot - Index CVE related to a list of progs
USAGE:
vulnerobot [global options] command [command options] [arguments...]
VERSION:
testing
COMMANDS:
collect, c Collect CVE from modules and add them to database
list, l List known CVE in database from a application list
info, i Display global info like the of list plugins availables
web, w Start a web server to display result.
help, h Shows a list of commands or help for one command
GLOBAL OPTIONS:
--debug, -d Turns on verbose logging [$DEBUG]
--config value, -c value Application list to monitor (default: "data/configuration")
--database value, --db value Application database to use (default: "data/sqlite.db")
--help, -h show help
--version, -v print the version
Permit to view and report information on the current application capabilities (plugins) and configuration (components)
The easiest command would be ./vulnerobot info
The output is a json format object in stdout and log information on stderr. This permit to view log and redirect the payload to a pipe/file like this ./vulnerobot info > output.json.
NAME:
vulnerobot info - Display global info like the of list plugins availables
USAGE:
vulnerobot info [arguments...]
DESCRIPTION:
Ask each modules to describe itself.
{"Plugins":["DUMMY","NVD","ANSSI"],"Components":[{"CPE":"cpe:/o:canonical:ubuntu_linux:12.04","Function":"FP1,FP3","Name":"Ubuntu","Version":"12.04"},{"CPE":"cpe:/o:canonical:ubuntu_linux:16.10","Function":"FP1,FP2","Name":"Ubuntu","Version":"16.10"},{"CPE":"cpe:/o:microsoft:windows_7","Function":"FP2,FP3","Name":"Microsoft Windows","Version":"7"},{"CPE":"cpe:/o:microsoft:windows_8.1","Function":"FP2","Name":"Microsoft Windows","Version":"8.1"},{"CPE":"cpe:/a:mozilla:firefox:48","Function":"FP2","Name":"Mozilla Firefox","Version":"48"},{"CPE":"cpe:/a:adobe:acrobat_dc:15.006.30173","Function":"FP1,FP2","Name":"Adobe Acrobat DC","Version":"15.006.30173"},{"CPE":"cpe:/a:adobe:acrobat_reader:11.0.04","Function":"FP1,FP3","Name":"Adobe Reader","Version":"11.0.04"}]}
In order to detect impacted components first we need to update the local database with information.
The easiest command would be ./vulnerobot collect
But you can limit the started plugins with the flag : --plugins plugin1,plugin2
, force plugins to reload their data : --force
NAME:
vulnerobot collect - Collect CVE from modules and add them to database
USAGE:
vulnerobot collect [command options] [arguments...]
DESCRIPTION:
Ask each modules to update their database of known vulnerability based on application list.
OPTIONS:
--plugins value, -p value Plugins to load (all or separated by comma) (default: "all")
--force, -f Force reload of data
--no-progress Don't display progress bar
List all matched components and related vulnerabilities in the database (previously collected)
The easiest command would be ./vulnerobot list
But you can also limit the started plugins with the flag : --plugins plugin1,plugin2
Flags --functions and --components permit to limit to a specific set of components.
The output, depending of the value of flag --format, is a json (default) or csv format object in stdout and log information on stderr. This permit to view log and redirect the payload to a pipe/file like this ./vulnerobot list > output.json.
A other format "csv-short" permit to export a csv containing only vulnerabilities sources, id and url
NAME:
vulnerobot list - List known CVE in database from a application list
USAGE:
vulnerobot list [command options] [arguments...]
DESCRIPTION:
Ask each modules to list known vulnerability in database based on application list.
OPTIONS:
--plugins value, -p value Plugins to load (all or separated by comma) (default: "all")
--format value, -f value Format to output (ex : csv, csv-short or json) (default: "json")
--functions value Functions to match from configuration (ex : f1,f5,...) (default: "all")
--components value Components to match from configuration (ex : c1,c5,...) (default: "all")
{"NVD":[{"Component":{"CPE":"cpe:/o:canonical:ubuntu_linux:16.10","Function":"FP1,FP2","Name":"Ubuntu","Version":"16.10"},"Matchs":[{"Type":"Component","Value":"ubuntu:16.10"}],"Vulns":[{"Source":"NVD","Value":{"CPE":"cpe:/o:canonical:ubuntu_linux:16.10","ID":"CVE-2016-1575","Summary":"The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.","URL":"https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1575"}},{"Source":"NVD","Value":{"CPE":"cpe:/o:canonical:ubuntu_linux:16.10","ID":"CVE-2016-1576","Summary":"The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.","URL":"https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1576"}},{"Source":"NVD","Value":{"CPE":"cpe:/o:canonical:ubuntu_linux:16.10","ID":"CVE-2016-9013","Summary":"Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.","URL":"https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9013"}},{"Source":"NVD","Value":{"CPE":"cpe:/o:canonical:ubuntu_linux:16.10","ID":"CVE-2016-9014","Summary":"Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.","URL":"https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9014"}}]}]}
Starting a web server that expose a web interface and api of the cli commands.
The easiest command would be ./vulnerobot web
But you can also configure the IP and port where the server listen with the flag : --listen ":4242"
NAME:
vulnerobot web - Start a web server to display result.
USAGE:
vulnerobot web [command options] [arguments...]
OPTIONS:
--listen value, -l value Address and port to listen (ex: 127.0.0.1:8080 or 127.0.0.1:4242 or :8080) (default: "127.0.0.1:8080")