-
Notifications
You must be signed in to change notification settings - Fork 178
New Scanner: HTTPLoot #1247
Copy link
Copy link
Closed
Labels
scannerImplement or update a security scannerImplement or update a security scanner
Description
🚓 New Scanner implementation request
HTTPLoot is a new
automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.
This seems like a good fit to the scb.
Steps to implement a new scanner
Hint: A general guide how to implement a new SCB scanner is documented here
- Create a new folder with the name of the scanner here
- Add a
README.gotmpland give a brief overview of the scanner and its configuration options. - Add a HelmChart and document all configuration options.
- Implement a new scanner specific
scan-type.yaml - Implement a new scanner specific
parse-definition.yaml - Add (optional) some
cascading-rules.yamllike documented here - Add (optional) a
Dockerfilefor the scanner if there is no existing one publicly available on dockerHub - Use the parser-SDK to implement a new findings parser (currently based on NodeJS)
- Add unit tests with at minimum 80% test coverage
- Add some example
scan.yamlandfinding.yamlfiles in the example folder - Implement a new integration or E2E test for the hook here
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
scannerImplement or update a security scannerImplement or update a security scanner