Skip to content
Antoine GIRARD edited this page Feb 1, 2017 · 12 revisions

The Command Line Interface

Description

The command line has a help command who describe all commands available and theirs associated flags (global or command specific).

Global flags can configure where to find the components configuration with the flag : --config my/path/to/config or where to find the database with the flag : --database my/path/to/sqlite.db

Example of default output

NAME:
   Vulnerobot - Index CVE related to a list of progs

USAGE:
   vulnerobot [global options] command [command options] [arguments...]

VERSION:
   testing

COMMANDS:
     collect, c  Collect CVE from modules and add them to database
     list, l     List known CVE in database from a application list
     info, i     Display global info like the of list plugins availables
     web, w      Start a web server to display result.
     help, h     Shows a list of commands or help for one command

GLOBAL OPTIONS:
   --debug, -d                   Turns on verbose logging [$DEBUG]
   --config value, -c value      Application list to monitor (default: "data/configuration")
   --database value, --db value  Application database to use (default: "data/sqlite.db")
   --help, -h                    show help
   --version, -v                 print the version

Display app information (info)

Permit to view and report information on the current application capabilities (plugins) and configuration (components)

The easiest command would be ./vulnerobot info

The output is a json format object in stdout and log information on stderr. This permit to view log and redirect the payload to a pipe/file like this ./vulnerobot info > output.json.

Full command detail :

NAME:
   vulnerobot info - Display global info like the of list plugins availables

USAGE:
   vulnerobot info [arguments...]

DESCRIPTION:
   Ask each modules to describe itself.

Example of output (stdout) :

{"Plugins":["DUMMY","NVD","ANSSI"],"Components":[{"CPE":"cpe:/o:canonical:ubuntu_linux:12.04","Function":"FP1,FP3","Name":"Ubuntu","Version":"12.04"},{"CPE":"cpe:/o:canonical:ubuntu_linux:16.10","Function":"FP1,FP2","Name":"Ubuntu","Version":"16.10"},{"CPE":"cpe:/o:microsoft:windows_7","Function":"FP2,FP3","Name":"Microsoft Windows","Version":"7"},{"CPE":"cpe:/o:microsoft:windows_8.1","Function":"FP2","Name":"Microsoft Windows","Version":"8.1"},{"CPE":"cpe:/a:mozilla:firefox:48","Function":"FP2","Name":"Mozilla Firefox","Version":"48"},{"CPE":"cpe:/a:adobe:acrobat_dc:15.006.30173","Function":"FP1,FP2","Name":"Adobe Acrobat DC","Version":"15.006.30173"},{"CPE":"cpe:/a:adobe:acrobat_reader:11.0.04","Function":"FP1,FP3","Name":"Adobe Reader","Version":"11.0.04"}]}

Collecting data (collect)

In order to detect impacted components first we need to update the local database with information.

The easiest command would be ./vulnerobot collect

But you can limit the started plugins with the flag : --plugins plugin1,plugin2 , force plugins to reload their data : --force

Full command detail :

NAME:
   vulnerobot collect - Collect CVE from modules and add them to database

USAGE:
   vulnerobot collect [command options] [arguments...]

DESCRIPTION:
   Ask each modules to update their database of known vulnerability based on application list.

OPTIONS:
   --plugins value, -p value  Plugins to load (all or separated by comma) (default: "all")
   --force, -f                Force reload of data
   --no-progress              Don't display progress bar

Display matching vulnerabilities (list)

List all matched components and related vulnerabilities in the database (previously collected)

The easiest command would be ./vulnerobot list

But you can also limit the started plugins with the flag : --plugins plugin1,plugin2

Flags --functions and --components permit to limit to a specific set of components.

The output, depending of the value of flag --format, is a json (default) or csv format object in stdout and log information on stderr. This permit to view log and redirect the payload to a pipe/file like this ./vulnerobot list > output.json.

A other format "csv-short" permit to export a csv containing only vulnerabilities sources, id and url

Full command detail :

NAME:
   vulnerobot list - List known CVE in database from a application list

USAGE:
   vulnerobot list [command options] [arguments...]

DESCRIPTION:
   Ask each modules to list known vulnerability in database based on application list.

OPTIONS:
   --plugins value, -p value  Plugins to load (all or separated by comma) (default: "all")
   --format value, -f value   Format to output (ex : csv, csv-short or json) (default: "json")
   --functions value          Functions to match from configuration (ex : f1,f5,...) (default: "all")
   --components value         Components to match from configuration (ex : c1,c5,...) (default: "all")

Example of output (stdout) :

{"NVD":[{"Component":{"CPE":"cpe:/o:canonical:ubuntu_linux:16.10","Function":"FP1,FP2","Name":"Ubuntu","Version":"16.10"},"Matchs":[{"Type":"Component","Value":"ubuntu:16.10"}],"Vulns":[{"Source":"NVD","Value":{"CPE":"cpe:/o:canonical:ubuntu_linux:16.10","ID":"CVE-2016-1575","Summary":"The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.","URL":"https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1575"}},{"Source":"NVD","Value":{"CPE":"cpe:/o:canonical:ubuntu_linux:16.10","ID":"CVE-2016-1576","Summary":"The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.","URL":"https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1576"}},{"Source":"NVD","Value":{"CPE":"cpe:/o:canonical:ubuntu_linux:16.10","ID":"CVE-2016-9013","Summary":"Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.","URL":"https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9013"}},{"Source":"NVD","Value":{"CPE":"cpe:/o:canonical:ubuntu_linux:16.10","ID":"CVE-2016-9014","Summary":"Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.","URL":"https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9014"}}]}]}

Starting web interface (web)

Starting a web server that expose a web interface and api of the cli commands.

The easiest command would be ./vulnerobot web

But you can also configure the IP and port where the server listen with the flag : --listen ":4242"

Full command detail :

NAME:
   vulnerobot web - Start a web server to display result.

USAGE:
   vulnerobot web [command options] [arguments...]

OPTIONS:
   --listen value, -l value  Address and port to listen (ex: 127.0.0.1:8080 or 127.0.0.1:4242 or :8080) (default: "127.0.0.1:8080")

Clone this wiki locally