Giter Club home page Giter Club logo

insight2's People

Contributors

cesrc-creditease avatar xxwsy avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

insight2's Issues

资产到底指的什么?

image
请问资产到底指的什么,指的IP或域名?那设置选项(公网/https)有啥用?应用类型指的什么,与应用的类型(APP/WEB应用)有啥关系?

[bug]后台-单个漏洞查询接口ACL配置错误

作者您好!
发现在 /action/vul.py 第173行代码中,@url(r"/vul/get", needcheck = False, category = "漏洞") ,
其中needcheck=False 因此并没有加入ACL策略中,导致开发可以越权查看不属于他/组的漏洞详情。

修复方法:
设置needcheck=True 这样可以在后台-编辑角色-权限列表中进行按需勾选,防御权限绕过,提升安全性。

image

修改needcheck=True 后可以按需配置,避免默认就被所有登录用户可访问。
image

批量导入漏洞接口问题

大佬好
1、想问_id是做什么用的,是什么算法生成的。
2、调试api/vul/add 接口的时候一直报错nonetype object has no attribute 'id',这里传的id ,是appid还是_id,传的时候怎么生成_id

邮件发出发给了录入漏洞的人,而不是漏洞相关的系统负责人。

邮件发出收不到。 action vul.py

@url(r"/vul/send_notification_email", category = "漏洞")
class VulSendNotificationEmail(LoginedRequestHandler):
"""
漏洞手动发送邮件

    id: 漏洞id
    title: 标题
    content: 内容
"""
def get(self):
    self.post(self)

def post(self):
    _id = self.get_argument("id")
    title = self.get_argument("title", "")
    content = self.get_argument("content", "")
    users = get_vul_relate_users2(_id)
    user_ids = [user.get("id") for user in users]
    settings = SystemSettings.get_or_none()
    global_setting = json.loads(settings.global_setting)

    vul = Vul.get_or_none(Vul._id == _id)

users = get_vul_relate_users2(_id)
这里的代码只拿到了发布或修改漏洞的人的信息,没有拿到应用系统的所有者的信息。 调试的结果是 我发布了一个漏洞,是别的系统的,但是发个邮件或短信发给了自己(短信是我自己加的。)

用户组管理无法添加AD账户

在【用户组】——【管理成员】——【从LADP职工新建用户】的输入框中,输入AD用户,不管是用户名还是中文名字,均无法匹配到用户,请问是LDAP哪里配置的不对导致的吗?

关于邮件下发问题以及漏洞下发关联

请问在哪将漏洞和业务负责人关联起来?应用资产关联的安全管用户,为啥登录该用户不能看到相应的漏洞,还有就是邮件下发配置在哪,怎么给业务负责人账号下发邮件提醒?

关于邮件下发问题以及漏洞下发关联

请问在哪将漏洞和业务负责人关联起来?应用资产关联的安全管用户,为啥登录该用户不能看到相应的漏洞,还有就是邮件下发配置在哪,怎么给业务负责人账号下发邮件提醒?

无法进行升级到2.03

当前版本 2.0.1
2.0.3
New features
报告生成扩展 生成每日风险处理报告,发送邮件
计划任务管理
计划任务数据备份
唯一用户在线
URL加入过滤参数,保证刷新后页面不变

有centos源码安装吗

有centos源码安装吗,有出现peewee.OperationalError: (2003, "Can't connect to MySQL server on 'web_mysql' ([Errno -2] Name or service not knwn)")这个问题吗

回执问题

下发漏洞给厂商后,厂商处置回复,漏洞发布人查看消息不显示对方名字。。。。

反馈bug

image
导入的数据库是一致的,登陆就显示账户密码错误,这种是什么问题?
我用docker也是这个问题,能拉入群吗?公众号没有人拉。

反馈个小问题:数据库配置文件缺少USE insight2;

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.